But mitigations=on doesn't even give full protection from ZombieLoad attacks.. if you want full coverage you need to disable hyper-threading, which kills performance. This caused a big debate among linux devs, but keep-HT won out.
So, disabling mitigations is not a good idea for work or critical workloads. But the chance someone compromises the average computer with one of these hardware bugs is probably the same probability that two equal UUIDs are ever generated.
PC overclockers move mountains trying to eek out half-percentage perf gains. Why not flip a flag for 12%?
But they usually do not have to compromise on security for that, not even stability unless they are aiming to set some new world record.
IIRC OpenBSD disabled SMT by default, which took away from performance, but overall secured the OS from several CPU-related vulnerabilities.
If you don't do this simple action you are not vulnerable.