If browser vendors really cared, they would disable javascript on non-https sites.
https://googleprojectzero.blogspot.com/2025/03/blasting-past...