That holds true only until the next Web browser bug is found (or pick your own remote user-level exploit -- web browsers are merely the most common attack vector, not the only one).
Posted Nov 19, 2009 6:49 UTC (Thu) by bojan (subscriber, #14302)
[Link]
Exactly. This is madness. If someone is brave enough to _enable_ this kind of stuff on their machine, that's OK. But shipping this as a default is nuts.