It is, however, ridiculous that DigitalOcean (a quite popular VPS provider) advises innocent webmasters to generate it in the browser with no mention of how insecure this is.
https://www.digitalocean.com/community/tutorials/how-to-set-...
https://www.digitalocean.com/community/tutorials/how-to-set-...
And you're more likely to screw up key safety yourself than for that narrow window to be exploited.
I don't think it's ridiculous.