For all the furore, I think the best outcome happened here. Both browsers used their weight to get a memory-safe implementation out, and now we can all benefit from a new file format with a significantly reduced attack surface.
Imagine if the fanatics got what they wanted immediately and then major vulnerabilities were introduced and there was a huge backlash against JXL. It could have set things back way more
Has that ever stopped any of the previous unsafe stuff? Seems like this would be the same - we'd just see faster adoption of the better format without browser limits
I don't remember security being an issue with WebSQL. The big complaint was about getting locked too tightly to SQLite's implementation details.
I see the security issues with WebUSB as not wanting to step into a minefield, which is pretty different from adding one more C++ library.