User blog comment:Rappy 4187/Technical Update: August 31, 2015/@comment-5558012-20150901003221/@comment-5558012-20150901011132

I realized that after additional thought. I was initially thinking purely along the lines of if someone accessed your account without your knowledge.

"It is also easier for someone who compromises your account to put some javascript there then it is to go change the settings."

How so? If someone compromised an account, why would it be harder to change settings? There's no confirmation for changing settings.