JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.
To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again.
I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.