Edit:
> If you execute untrusted JavaScript and WebAssembly code in a separate process from any sensitive data, the potential impact of SSCA is greatly reduced. Through process isolation, SSCA attacks are only able to observe data that is sandboxed inside the same process along with the executing code, and not data from other processes.
I do run isolates in separate processes to prevent security issues, even if that may not be enough. Still an early prototype for now.