Also, how do you expect that, for example, a videoconference site (let’s say, Jitsi Meet) will work if you don’t execute any client-side code?
I never said that you should never run client-side code. Even OP doesn’t say that (which is why they’re running some sites in Whonix, they just really don’t like it), and they’re way more extreme about not allowing JS than I am.
The fact that WASM is NOT a programmimg language, and that WASM is intrinsically sandboxed and has really granular permissions (through WASI).
Interesting. Are the actual implementations of it sufficiently secure so far?
I never said that you should never run client-side code. Even OP doesn’t say that (which is why they’re running some sites in Whonix, they just really don’t like it), and they’re way more extreme about not allowing JS than I am.
I have to admit that I may have exaggerated a bit, but I think the point is still clear.
Interesting. Are the actual implementations of it sufficiently secure so far?
Yeah, at this point it’s quite mature, and especially the implementations in languages like Rust, Zig, or Nim are particularly secure, although the classic ones in C or C++ are too, and there are great implementations for JS, TS, and other subsets of ECMAScript.
I never said that you should never run client-side code. Even OP doesn’t say that (which is why they’re running some sites in Whonix, they just really don’t like it), and they’re way more extreme about not allowing JS than I am.
Interesting. Are the actual implementations of it sufficiently secure so far?
I have to admit that I may have exaggerated a bit, but I think the point is still clear.
Yeah, at this point it’s quite mature, and especially the implementations in languages like Rust, Zig, or Nim are particularly secure, although the classic ones in C or C++ are too, and there are great implementations for JS, TS, and other subsets of ECMAScript.