2014-04-02 UTC
gRegor` The most secure scenario is that you've signed your h-note with a PGP key and the reader has verified your key out of band. Or via a secure channel that is linked from your site, but not able to be updated via your site. Like ben_thatmustbeme said, if they can compromise your site, all bets are off.