@muvlon There'd also need to be an equivalent something (maybe js is allowed but no network access or communication with anything outside the encrypted block element?) on the sending side where the browser UI makes it clear that you're typing in a secure context and what key(s) it's going to be encrypted to.