pull down to refresh

I agree, the goal is to not have priv keys on the server, but sign txs with remote signing only.
But there is an extra vector of attack when you send the transaction
reply