Earlier quoted context omitted.
I don’t think the second paragraph is a logical extrapolation of the first. If this is using the WebCrypto API (which it appears to be doing), then trusting this browser-based solution isn’t fundamentally different from trusting an installed application that can update itself.
> trusting this browser-based solution isn’t fundamentally different from trusting an installed application that can update itself. Which is still a bad idea to trust, so I'd say that it is a logical extrapolation.
I mean, sure, you can never use an auto-updating application again and always manually review system updates before installing them. But realistically, I don't see anyone besides Richard Stellman adopting that lifestyle.