You can serve different JS to "special" users once. If you're smart, you run checks "for the security of the browser environment" first to make sure it's something unlikely to contain debugging capabilities, e.g. an unmodified iOS device.
The site even helpfully asks you to identify yourself with ANOTHER username and passphrase first, making it even safer for the attacker.