Browser extension
Safety and privacy
What the extension can access, how it avoids filling a login on the wrong site, and where its limits are.
A password manager extension is powerful, so here is exactly what it does and does not do.
#Permissions it asks for
| Permission | Why |
|---|---|
| Read and change data on websites | So the key button and the save prompt can appear on the pages where you sign in. The extension looks only for sign-in boxes and never sends page content anywhere. |
| Talk to GrailVault | To load and save your encrypted vault. |
| Storage | To keep your sign-in in memory, and the list of sites you chose "Never for this site" for. |
| Active tab | So the toolbar popup can tell which site you are on and fill it. |
#It only offers logins for the right site
A login is offered only on the website it was saved for, or on a subdomain of that website. Look-alike addresses (for example github.com.evil.example or evilgithub.com for a login saved for github.com) never match. Logins saved for a hosting platform itself (such as github.io) are not offered on other people's sites hosted there.
It also refuses to fill on pages that are not secure (no https), apart from localhost addresses used for development.
#Nothing fills by itself
Passwords are filled only after you click the key button or Fill. A web page cannot trigger it: the extension ignores clicks that come from the page's own scripts and only responds to real clicks. The extension's on-page controls are hidden from the page, so a website cannot read or restyle them.
A web page you are filling into can of course see the values once they are in its boxes. That is true of any autofill, including your browser's own.
#Where your keys live
- When you sign in, your master password is turned into keys on your computer, as on the website. The password itself is not kept.
- The extension keeps your vault key and sign-in token in memory only. They are not written to disk, they are gone when the browser closes, and web pages cannot read them.
- Passwords are decrypted only when needed. Saved logins are encrypted before they leave the extension.
- The extension talks only to GrailVault. It does not contact any other site, and it has no analytics.
#Signing the extension out
The extension is listed under Settings, Where you're signed in. If you lose a computer, sign the extension out there and change your master password. Its sign-in then stops working immediately.
#Limits
- The extension runs in your browser. Malware on your computer, or a malicious browser extension you installed, could read what you see. Install only extensions you trust.
- Subdomain matching trusts the site. If a site's own subdomain is taken over by an attacker, a login saved for the main site could be offered there.
- No independent audit. The extension has been tested, but it has not been audited by a third party. See Limits and roadmap.
- Not every page works. Unusual sign-in forms, forms inside embedded frames and some single sign-on pages are not detected.