Sometimes it's just silly...

I understand the reason and thinking for the fact that you can’t use Javascript XMLHttpRequest to call scripts from remote servers…but the fact that all you have to do is use it to call a local script that in turn calls the remote server renders the whole thing a little moot no?

In the case of Chrome extensions, you just need to make sure you’ve set the proper permissions for any XMLHttpRequest calls…which also makes me question why do we have to do it at all (those that are going to be malicious are going to find it very easy to get around these ‘requirements’ and those of us that aren’t just find them a tad annoying to be in the way in the first place).

Anyway - just a little 'security’ gripe I’ve had for awhile now.

