@silverwizard @davidgarywood @evan well, you get to decide, right?
just so we’re clear, i wasn’t suggesting that your private key be protected by your account password, which your admin can easily capture. all signing and decryption should happen in the client, where they could get caught serving patched javascript