Hacker News new | ask | show | jobs
by ranger_danger 699 days ago
The key is in the part of the URL after the #, which currently is never sent to servers in any browser, but I suppose that could change.

The more secure method IMO to using the web client (which could have malicious JS pushed to it at any time), would be to use a standalone mega client that you control the source to and can verify yourself.