They implemented end-to-end crypto in this web client as well. Since it's JS served on each request, it's vulnerable to compromise on the server side. I also don't know how key material is securely provisioned to your browser by scanning the QR code.
That being said, they are in a good position to roll out a Chrome extension or plug-in that can keep the crypto implementation on the browser. That would be a nice solution.