pah was convinced by crown to support no-limit server-command-client browsing on the condition that pah can figure out how to prevent downloading files, last time i asked him. he probably should keep us updated through here though
Turns out I was wrong, files won't download as far as I know.
If you consider where the vast majority of exploits come from, javascript is easily the worst offender. Perhaps you could take the noscript approach and instead just have a whitelist of sites which are allowed to use javascript (and certain other html5 objects).
I might consider doing this, should be as simple as changing a value in the preference.
is there a......... mac......... version...........
No, and there probably will never be.
Just use Wine to run Blockland instead.