I am working on a EDIT: mobile web app which displays some sensitive information and requires a login which stores the members username and password in a HT
See this HTML5 Web DB Security
client-side encryption libraries aren't mature or tested well enough
...but it's been a year ago, so that could be false already