@Henry Cobb
It shouldn't make a difference if it's a GET or a POST. It's just as easy to fake either. The only difference is the field values are in the URL for the GET and in the request body for the POST.
And as Stephen Stagg points out, they're not trying to get around your security or logins or anything like that. Consider online shopping sites - now they can "browse" the catalogue if it's only available by form which is quite common these days.
On some sites, it's as simple as selecting a region before you get a customised site.


