This applies at all levels of reading, really. We're mixing the trafficking of sensitive authentication information in the same process as code that executes instantly upon clicking on hyperlinks. We're mixing business and pleasure on the same filesystem, in the same OS and memory space. We're mixing mutually untrusting entities' private data and code on timesharing systems that we're renting in someone else's datacenter.
Process boundaries, both in terms of physical reality and design choices on what constitutes a system boundary, are critical, and will need additional thought. At the same time, a boundary that's more robust to side-channel attacks than most is having all the hardware exclusive to yourself.
Also, this entire issue neatly demonstrates the problems with executing untrusted code. Solving the issue of vetting code and evaluating trust, especially by average users, is extremely difficult; but the current culture of the Web largely consists of running untrusted code immediately from a single user-entered string, or through automatic or manual navigation thenceforth. This is a frightening proposition, and yet entirely mainstream today.