Disclaimer: I avoid Chrome browser exactly because I don't have enough information to know if they really "aren't evil." I don't claim there isn't such information somewhere, just that I don't know about it. My worries are exactly because their installers install more like a malware than like clean projects ("no we aren't going to let you to simply download executables, just click here, give us administrative privileges and enjoy when we download what we want and change on your machine what we like").
Anybody who knows more?
Apps without source-code cannot be trusted by default, unless you have a contract with the company providing it that stipulates a relief agreement that's reasonable for you in case anything goes wrong. And only enterprise software does that, depending on how you negotiate nonetheless, otherwise for consumers the EULAs are doing the exact opposite. And even with enterprise software guarded by good contracts, even then you need the source-code.
For more abstract take on this topic, I direct to Gödel, Escher, Bach; Hofstadter elaborates there on the fact that the distinction between what is data storage (e.g. music CD) and reading device (e.g. music player) is somewhat arbitrary, and in fact the information itself is "stored" in the combination of "data storage" and "data reader".
* - or at least most, IANAB.
https://code.google.com/p/chromium/wiki/ChromiumBrowserVsGoo...
http://git.chromium.org/gitweb/?p=chromiumos/platform/assets...
In the same press release they said they fixed the problem and would be deleting the logs, but many governments quickly stopped them from deleting the logs so they could investigate.
That's probably why they announced they would delete them before they actually did. And the investigations found that Google was not at fault for accidentally recording unencrypted publicly transmitted data. ;)
I don't troll interwebz from my terminal/putty, so I'd say there's a smaller risk of that happening there.
On a side note, add passwords to private keys :)
Granted this is equally a problem with any terminal emulator that you didn't compile yourself after examining the source code, but I have quite a bit more faith in Apple and the various Linux repo maintainers than some random guy publishing to the chrome app store. I don't know if Google even claims to vet its contents, but if they do I know they do a terrible job because I've ripped open some extensions to confirm they're doing some sketchy stuff (nothing insecure or worrying, more like adding affiliate links to your entire browsing experience)
The source for the extension is available at http://git.chromium.org/gitweb/?p=chromiumos/platform/assets...
Also, handing it private keys is completely optional.
So no, private key is still private.