We don’t have a choice yet, but yeah, you shouldn’t be pasting your private key on random clients just cause they are native either.
Discussion
The choice is :
- Use open source apps
- Verify the code or trust an independent source
- For developers add key safety informations
Quick look at the login page of #[4]