The security concern is remote code execution via JS, and sharing processor time with other people you don't trust, right?
It should be up to the VM-as-a-service and browser vendors to flush the cache properly.
It should be up to the VM-as-a-service and browser vendors to flush the cache properly.
“Microarchitectural Data Sampling (MDS) is a group of vulnerabilities that allow an attacker to potentially read sensitive data.”
That is way more serious than stealing cycles.
Still it's fine with no JS and no shared processor time, right?