We added this to protect against an attack where a third party site bypasses the content-type of the response by doing:
Google does something similar, except they use //... + \n (e.g. http://www.google.com/calendar/feeds/developer-calendar@google.com/public/full?alt=json&callback=foo)