Hacking protonmail - with a browser
http://vimeo.com/99599725/cc all those fancy HTML5-Javascript-wallets out there (blockchain.info, Ripple, etc)
I use a very simple heuristic that saved me from a lot of trouble: Scripted websites are unsuitable for security applications - don't use them for anything sensible.
These days every idiotic page requires scripting for useless effects - often you can't even view simple text without scripting enabled... i cannot express how much I hate this!
Scripting is a disease.
ya.ya.yo!