Yes, performing CSRF attacks is easy. A more interesting question is whether you can find anybody who can quantify the actual risk created by an attack. In my experience, people don't understand the issue in any depth (and that would include me

) and just cargo-cult solutions. Javascript isn't browser-specific - it's an ECMA standard - it's just that some browsers are more broken than others in their implementations, and therein lies much of the potential for exploits.
I do agree javascript is here to stay. I use YUI for some AJAX stuff as well as some raw javascript. But all my pages continue to work if the browser does not run scripts. Again, wikipedia has a useful summary
http://en.wikipedia.org/wiki/Unobtrusive_Javascript