True it is a scary web but how many of those exploits have relied on default settings and Javascript to run?
You are many times safer on the web if you have the discipline to use noscript properly.
You are many times safer on the web if you have the discipline to use noscript properly.
Layout (just to name one non-JS subsystem) has been responsible for a lot of vulnerabilities too.
This will probably seem quite shocking, but I almost exclusively used IE6 for a few years, with JS disabled - and despite frequently visiting the "darkest corners" of the Internet, was never exploited. On the sites that tried, I'd just see a blank page; view the source, and there was a blob of obfuscated JS.