Though, this particular interpretation does make Google Chrome illegal; it has dev tools that can be used for manually sending HTTPS POST requests with forged headers. (It also has XMLHttpRequest, which can be instructed to do what nmap does with relative ease.)