3 ms·
I agree. I want these turned on for shared servers and on the consumer on OS processes that I don't trust. But I would want an option to turn it off for JavaScr
by ud_0 5y ago
I agree. I want these turned on for shared servers and on the consumer on OS processes that I don't trust. But I would want an option to turn it off for JavaScript-heavy sites that I do trust.
I'm frankly amazed that the mitigations so far have not already been disastrous to performance. Either we accept drastically less performance from now until basically forever, or we adopt a more fine-grained security model.
- qwerty456127 5y ago> turn it off for JavaScript-heavy sites that I do trust How can you trust any?
- speedgoose 5y agoDownloading a software trough http and executing it on your operating system is not very different than downloading a software through http, and executing it inside your web browser virtual machine.