Also I remember that cryptographers consider any leaking of information about a secret to be a break. They call this "semantic security". Maybe there's something special about crypto that means people have to be maximally paranoid. I wonder what level of paranoia is appropriate for CPUs.
Actually, if NetSpectre can already leak information about a plaintext or secret key, then that already breaks all of cryptography from some cryptographers' point of view.
Another thing: Nation states may learn how to execute Spectre attacks faster than academia does. Then again, those same nation states would also want to switch to non-Spectre-prone computers, which would be visible enough for other people to start changing. Or maybe I'm putting too much faith in the IT skills of nation states.
Given all that, I don't know what safety margin is appropriate for CPUs. When do we consider all of our CPUs to be broken? Is it when Spectre attacks are being used to extract our financial info en masse? Is it soon? Or is it when governments start changing their computers (assuming governments are even that clever -- see the NHS and Wannacry)?
Run some scripts, check on it six months later...oh look, we have SSL private keys for the X domains now.