I understand that my data is safe with you guys at rest. I'm sure your security protocols are top notch. But it's all about attack surface. Things can and do go wrong on the internet all the time. Bits get flipped, certs expire, DNS cache gets poisoned, employees get phished, and MITM is an omnipresent threat. I'd just rather avoid all of that.
Would you mind elaborating on this?
Compromised algorithms are unlikely. But not impossible. Quantum computing enabling brute force attacks is unlikely in the immediate future, but not impossible. Certificate pinning compromise during transport is not implausible for state actors.
And in those scenarios and others, having the vault stored remotely on someone else's machines is inherently less secure than not.
The assumptions made in the paper are clumsy.