Is there a reasonable way to estimate how much performance could be gained if we operated in a hypothetical universe where we never ever had to worry about security?
Is there a reasonable way to estimate how much performance could be gained if we operated in a hypothetical universe where we never ever had to worry about security?
The mitigations for the various hardware sidechannel attacks discovered in the past year have a bit larger impact. But you don't need these at all on your local computer, only in shared environments.
As a rule of thumb each mitigation usually costs a single digit percentage, seldom double digit. Of course in a system multiple mitigations will be at play but the impact should be far below 100%.
The performance impact of scripting languages, interoperable web standards and bad implementations are far worse :)
Not really, no. In the limit of a theoretically perfect implementation, the performance overhead of security is zero (except to the extent that you count cryptography, but that's distinct from CFI/RCE/memory-corruption/etc-style security). The practical overhead basically comes from defence-in-depth to insure that imperfect implementation don't break security, and there's not in general any fundamental reason why imperfection A is common problem that needs to be mitigated, but imperfection B is a stupid corner case deserving of "well, don't do that then". Also we essensially -by-definition don't have a theoretically perfect implementation to compare against, so we can't even estimate the zero-overhead point with any confidence.
One place to look at would be TLS perf.
Network latency, encryption compute.