Zero ways to validate what random JavaScript was downloaded from what random server and immediately executed inside a browser that probably has multiple unknown zero day exploits
You cannot reliably do cryptography inside content DOM
Been true since forever
