Congrats on your accomplishment! However, I will never use it because a browser is one of those really important information gateways that I want to be very sure is not compromised.
The implication here is "not compromised by independent actors that wouldn't already be capable", right? You're delegating trust to closed source megacorp products or open-but-insanely-complex megacorp dependents (firefox/chromium babies?), all of which will naturally create a strong incentive to find or hide exploits, once they have some traction. Discussion on HN makes me think it's impossible to really trust a browser to be secure atm. The alternative is to hope there are no wide-sweeping exploits, and to try to remain anonymous.
I guess the real additional issue added by something like this is this introduction of another actor which you need to be inherently suspicious of since they're attempting to funnel you towards their system, which they have some control over. Just like other corps, but you've given them your trust already. It's not crazy, I don't know if it's even wrong.
But I'd say maybe we can reframe your issues adopting something like this. Would it be something you would trust to use daily if the following become true? :
- The team at Impervious, develop a sufficient reputation for being stewards of open software with healthy communities over the coming years. (I'm implying that's a good approach to get security researchers giving time to your project, maybe it'd be sufficient to have a really good bugbounty program, or just develop a sufficient security team)
- A large audience adopts this browser, so you're not one of the hundred beacon users that's easily picked out throughout the web (I assume fingerprinting techniques make this an issue though I admit I've little knowledge on the topic)
I'd love to hear what I'm missing, and if this conflicts with your approach to assessing security maybe you can help me see your perspective :)