For the advanced option, what if we took the same approach that Hushmail uses, where encryption is done in either client side javascript or a full java/flash app (although I dislike having to run plugins just to access your wallet)? That would probably be a better option for the truly paranoid (which I admit I am one myself)...

No Java or flash on the iPhone/iPad's (which is really your target market), that and the Android (which has java and flash). Not that Java/Adobe are known for great security. There are just so many reports on CERT (
http://search.us-cert.gov/) of Java and Adobe vulnerabilities.