I'm thinking a few thoughts:
- Interpreted programs can carry out Spectre attacks
- Interpreted programs are un-analysable using a technique that does binary analysis
- This technique would insert fences "everywhere" in an interpreter, adding significant overhead
[edit]I'm thinking it matters a lot whether the analysis is done at run-time or static. If the analysis is static, and it was done on the Python interpreter for instance, it would have to be very pessimistic. But if it's done at run-time, it might not need to insert as many "fences".