Much of Artur Bergman's post Your browser is a tcp/ip relay goes quite high above my bald patch, but I get the gist: as users, we all need to worry a bit more about what the funky web apps appearing daily might be able to do, such as allow the website owner to grab hold of your machine via the browser. Wild! I guess we were lulled into a false sense of security by the assurances we've had for years that browsers would let us know if javascript was going to try anything iffy. In fact we did used to be a lot more cautious (and evidently Flash is a concern too; perhaps ActiveX and Silverlight too?) but since it's so hard to imagine a web now without AJAX we sort of laid the concerns aside.
Not a lot to do with my research, perhaps, but a little worrying