I don't think Keybase is glossing over security at all.
First of all, you don't have to use the browser app at all. I personally don't trust Javascript crypto and hence don't do anything in the web app.
They're also acutely aware of the dangers of centralization and all the Keybase crypto is based on minimal trust. Check the documentation: https://keybase.io/docs/server_security
Personally, I don't want someone else storing my private keys; which is a pre-condition for doing anything you'd have to worry about in the browser anyway.
So do I - that was my point to parent: I don't use the browser tools not because of JS (which is a concern) but because of not wanting private keys stored online which would be required to do so.
First of all, you don't have to use the browser app at all. I personally don't trust Javascript crypto and hence don't do anything in the web app.
They're also acutely aware of the dangers of centralization and all the Keybase crypto is based on minimal trust. Check the documentation: https://keybase.io/docs/server_security