3 ms·
> Even if it asks for your vault key each time, since they control the JavaScript delivered to the webapp How is that any different from a malicious app you ha
by codemusings 8y ago
> Even if it asks for your vault key each time, since they control the JavaScript delivered to the webapp
How is that any different from a malicious app you have on your phone or desktop? Assuming that the web client is served entirely over HTTPS MITM attacks shouldn't be possible and the project maintainer is the only remaining bad actor. Which is where trust comes in.