> "AES-256 in CBC mode" is not a confidence-inspiring description of a cryptosystem
I'll second this, although knowing the author, my concurrence doesn't add much weight.
To wit:
* Encryption is not authentication. CBC mode in particular is vulnerable to
bit-flipping attacks.
* The password KDF is an important implementation detail that needs to be
considered.
* Browser extensions and node-webkit > browser JS
OP: Let me know if you'd like to know more about these details and/or advice on moving forward.