Earlier quoted context omitted.
Do you want to reinforce established monopolies? Because I can't think of a better way of doing that than having a technical difference between "trusted" and "untrusted" sites.
Well, I personally would be fine with the fair policy of disabling js everywhere but I'm sure most would not agree, so what's the alternative ? If anything, Spectre class attacks really showed how hard it is to properly sandbox arbitrary programs. Yes, the CPUs are complex, but the attacks happen on a high conceptual level, level at which the CPU is fairly simple. It's not like they rely on an obscure detail or bug.…
Turning it on for trusted websites is one click away, once per domain, and it could save me in the future.