Dismissing one of the leading penetration tester's essays with it mainly just boils down to watch-out for XSS attacks. seems unwise.
I'll submit that because it's in-browser it's additionally difficult - very difficult - to get right, but I don't see that it's impossible.