Of course there is nothing intrinsic to forms to prevent someone from saving
your POST form, changing it, and submitting the altered one. It's always a
good idea to assume that you WILL receive values that you were not

When you think about security, the above makes sense. If GET encodes the
junk into the URL, and the junk messes with some data on the server in a
"gonna change you, poo poo kachoo" sort of way, then that's bad, since
anyone could modify the URL to give values you weren't expecting.

