Some people have claimed narrow execution limits provide a defense, but we on the Workers team don't believe that's true and I don't think we've made that claim. Specifically, it's easy for an attacker to store state between requests and so continue an attack across many requests. In our current implementation, you can store that state in global variables, but even if we wiped the worker's state after every request, it would still be easy for an attacker to store their state remotely.
We'll be posting more about Spectre later this week.
> That was also how they prevented v8 from allocating tons of memory.
No, we explicitly limit V8 memory usage independent of CPU time.