Web-based cryptography is always snake oil
Nowadays, there is an epidemic of web applications purporting to offer βend-to-endβ encryption. Examples might range from a file upload service, which allows you to upload and share files of arbitrary size and promises βend-to-end encryptionβ; or a web-based password safe service which claims that it can't see your passwords because they're encrypted; or a web-based cryptocurrency wallet.
The cryptographic claims made by these services are invariably nonsense. Indeed they necessarily must be, because the web as a platform does not possess the necessary functionality which would allow otherwise.
Fundamentally, all web-based cryptosystems are incoherent because they suffer from an incoherent threat model.
Let me start by coining a law, which is both obvious and yet, to my knowledge, novel and overdue:
It is inherent to the model of the web platform that the code which implements a client-side web application is distributed by the given website. Thus the client-side code is always distributed by the operator of the web server.
In other words, web-based βE2Eβ applications claim to secure against malice on the part of the server operator using encryption implemented in client-side JavaScript, but this is obviously not true, since if the server operator was malicious, they could just push different client-side JavaScript. (Conversely, entities other than the server operator are secured against via use of TLS, so there is no additional benefit to βE2Eβ if you trust the server operator.)