Comment Re:Browser keeps the private key? (Score 1) 179
I don't think the browser would ever need to transmit the private key in this scenario. However, yes: if the user or browser was some how tricked into uploading it -- you are compromised. This is still better than passwords, which are easy to attack with dictionaries and rainbow tables.