So if I run arbitrary, potentially-malicious code from the Web, in the form of a browser extension, I'm "clueless"?
Yet if I don't run arbitrary, potentially-malicious code from the Web, in the form of JS, I'm a "luddite"?
Considering that many browser extensions are implemented in JS, the only difference is in control: users can pick and choose which browser extensions they want to use (I use a few; I've skimmed the source of a couple and written a couple myself), whereas enabling Javascript turns a machine into a third-party free-for-all.