I contacted their support: Me: I wanted to know more about your certificate key matcher isn't the private key always meant to remain... private? Emanuele: Yes, it should. We offer the tool to help verify the correspondence SSL certificate it is lost. Me: But it would be sent over HTTP and viewable to anyone along the network. Emanuele: The page can also be accessed through HTTPS. Me: I think it should be enforced. Al…
So leaking my private key to somebody is OK if I do so over HTTPS, and even better if I encrypt it with a javascript crypto library beforehand? I don't think you've thought this through.
I haven't been able to access the site though, so I may be way off in my understanding of what it does.