No, it doesn't. The "attack surface" is a IP stack that looks in some hash tables whether there is anyone listening on the port, and then rejects the connection. Vs. a huge browser with a javascript interpreter and JIT and what have you that is accessible regardless of NAT or firewalls or whatever else you do on the network level. The fear of inbound connections is completely irrational.
No, it doesn't. The "attack surface" is a IP stack that looks in some hash tables whether there is anyone listening on the port, and then rejects the connection. Vs. a huge browser with a javascript interpreter and JIT and what have you that is accessible regardless of NAT or firewalls or whatever else you do on the network level. The fear of inbound connections is completely irrational.