Let's say I create a wallet on an offline computer and move a watching-only wallet file by USB to my online computer and import it there. Armory will show it as watching-only/offline and won't allow me to spend any bitcoins, but in theory the private keys could have been transferred in the watching-only file and then sent to the Armory developer. Once thousands of wallets are funded by Armory users, the attacker might be tempted to move all bitcoins to an address of his own.
Is this a case of we just have to trust the good will of the developer or is it possible for a user to check that all private keys indeed stays on the offline computer?
I must say that I'm really impressed by the Armory software and since it's announced that Alan is a featured speaker at the Inside Bitcoin Conference in Vegas next week, I'm confident that Armory doesn't have any hidden "features". I've already made a donation
However all users might not agree...
Thanks