Prevents cross-domain transaction phishing. Especially when we're injecting in every tab? It'd be too easy for a well-timed transaction to look correct right now.