This looks potentially nice. The initial assumption with these types of services is always that an attacker, having compromised their servers, could simply inject malicious code into the browser. From their docs: > Normally, when hackers get access to your server, they can change the code that gets sent to customers. For example, they could make the code say "send your password to us". Then, even though they can't re…
But how would you know an app developer wasn't compromised and signed the next version with a backdoor also?