Very interesting, especially in light of the recent claimed hacks to ProtonMail. I've just switched to PM recently and, while I'm no cryptography expert, it did seem unlikely that typing my password into a browser app could ever be considered very secure -- certainly not "invisible" to PM since, as the author points out, you can't see or validate the code running in the browser.