> JavaScript ... is a demonstrated attack vector
OMG, I didn't know that. Thanks.
OMG, I didn't know that. Thanks.
If you feel paranoid, you might also want to disable JS by default and only enable by whitelist on any machines that hold particularly sensitive or valuable data.
See the "Fantastic Timers" paper. Link to HN discussion: https://news.ycombinator.com/item?id=16080235
The attack is already pretty damn slow (1kB/s) in C, if you have to collect a statistically significant sample in JS it might well slow down enough to not really work properly.