You can inspect the website and detect a backdoor. It is not easy, but nobody would risk to be caught doing that. On the server side, we have no possibility of knowing what happens.
If you are interested in checking a completely different approach, you can look at Secrez https://github.com/secrez/secrez. It is a CLI secret manager that supports git repo for distribution. Using other packages in the suite, Secrez allows direct communication between local desktop accounts using SSL tunneling.
Disclosure: I wrote it.
Sometimes I have the impression that some entrepreneurs like to say that there is a bubble because so they can say: "Yes, he raised all that money, or had that big exit, but not because he is better than me, only because there is the bubble".
I seem that this article contains a lot of good points about Javascript cryptography. The error of the author is that he is unable to see a reason to build a secure application based on Javascript because his prejudices are too strong.
I am the founder of Passpack. We use Javascript cryptography from 2006. We have 16,000 active users and nobody ever reported loss of data. I think that if you are conscious of all the issue connected with browsers and their problems, you can build a good system that is able to protect not only the security of the users but also their privacy.
And the privacy can not be protected with a server-based cryptography system.
Before that a developer, I am a song-writer. When you write a song, you start listening a lot of music. After, you put all that music in a side of your brain and forget it. After, you sing and sing untill you sing something totally different.
I agree. In fact, I specified that using the browser is good in some cases with the caveat that there is at least a master password protection. But a good password manager is always a better idea. Of course everyone chooses the one that best fits his needs, but the important thing is that you use one. 1password is a great product for consumer and individuals.