JavaScript Zero: real JavaScript, and zero side-channel attacks
blog.acolyer.org
blog.acolyer.org
https://github.com/IAIK/ChromeZero
Note this closed issue from karthikbhargavan pointing out some of the ways a malicious page could get access to unprotected javascript features:
https://github.com/IAIK/ChromeZero/issues/2
misc0110 suggests those are implementation details, but I'm a little skeptical -- I bet it's pretty dang hard for a Chrome extension to close off every way to get access to a given function in javascript.
So I think it's probably best to look at this as a user interface testbed -- basically a test of how annoying or effective it would be if browsers asked users to opt into these things, and which set of policies would be least annoying for the maximum protection. I suppose it also sets a ceiling on the performance impact, but it's not obvious the impact would be the same if the same rules were set at the browser level.