Now imagine someone malicious drawing a pixel perfect Chrome browser that someone thinks is a normal browser, browses to their "bank" site, and enters credentials. Oops. I'm not even sure how you could protect against an attack like that..
It was heavily railed against in JavaScript: The Good Parts which had a huge effect I suspect.