I think it's important to decouple Javascript the language, Javascript the runtime, and the browser security model from each other. Javascript --- the language and the runtime --- aren't ideal environments in which to do crypto, but they're not untenable. It's the browser --- not the browser shell, running as a standalone application as in Electron, but the actual Chrome browser that fetches things from URLs --- that makes crypto untenable.
Tangentially related (and this conversation might have moved on already) but I'd be curious to hear your view on 1password's sync service. I know you like and use 1password standalone. Do you have a recommendation for how to sync across devices? Thanks!