with simple XSS, anyone viewing my account has their cookies stolen