I see WebGL people saying essentially the same thing: that there is a reasonable degree of security that can only be assured by obtaining cooperation from driver vendors; that, in other words, the security of WebGL is not entirely under their control.