Can the applet be probed?
Though measures are taken to keep passwords within the applet classes private from outside of the instance, whereas data pertaining to passwords and initialization vectors goes in but are not coming back out, a hacked browser with a corrupted Document Object Model (DOM) (which are mainly software rules) could possibly infiltrate the applet. One measure against this is to make sure there are no other applets or controls within the DOM, and keep the machine virus/trojan free. Hardware-based encryption (such as with CodeMeter or Securikey) is not resident inside of the browser and much more secure.