Earlier quoted context omitted.
Many? Anything running a browser needs it because of js. Anything running connected to the internet at all would be well advised to have them because you can take advantage of the exploits via the network stack. Anything running on a vm has to have them since microcode is set by the hypervisor. So, we're talking about desktops not used to browse the internet, and bare metal servers whose network stacks aren't exposed…
> So, we're talking about desktops not used to browse the internet You can browse the internet without JS. Many people here seem to do so.
The number of people who do isn't statistically interesting though. If you are I still wouldn't advise doing so while turning off the mitigations since you're still parsing and displaying hostile ip/tcp/http/(html/CSS/image/video/...).
For example, http://www.misc0110.net/web/files/netspectre.pdf