Of course Keychain will ask for your credentials, but:
- the extension code runs locally on your browser. It does not rely on an internet connection or a 3rd party service.
- the provided keys are encrypted and stored locally. They never leave your computer. They are used locally to sign transactions.
- keychain code is auditable, either on github and even locally after you have installed the extension. It's clear text Javascript.
It's a like a password manager, except that not all password manager code are auditable.
Posted with