Also, I didn't say "just as dangerous", I said "just dangerous"
However, with proper CSRF protection your man in the middle argument is not the case is it?
Also, I didn't say "just as dangerous", I said "just dangerous"