What is the difference between this and working with a frame? I guess one could be the security policy (this being more flexible than a blank frame document which is automatically of different origin), but is there anything else?
It is using iframes, that can be sanboxed in many ways. The security policy apply for external domains, if declared in header. It is a way to create a whole valid DOM quickly, it is identical as creating it by hand. Then we can use window postMessage, or simply from the main document retrieve stuffs in the children DOM with like `frame007.contentDocument.documentElement...`