And to be clear: norms in the browser engine world are moving towards multiple layers of protection: writing code in safer languages, aggressively fixing even potential vulnerabilities, tools for software auditing, sandboxing that prevents many APIs from being called, etc.