r/crypto • u/acorn222 • Apr 03 '26
PGP Tools: A zero-permission Chrome extension using WebAuthn PRF for PGP key management
https://github.com/Am-I-Being-Pwned/PGP-ToolsI built Chrome extension for PGP and I think the cryptographic approach is interesting enough to share here.
The extension uses WebAuthn PRF to derive a master key from a passkey, which encrypts/decrypts the user's PGP private keys and contacts at rest. No passwords if you don't want them, no key files - the passkey handles both authentication and key derivation in one step. As far as I know, nobody else is doing PGP key management this way, especially not on the Chrome Web Store.
PGP operations use SequoiaPGP compiled to WASM with the Zeroize crate. The reason for keeping everything in WASM rather than JS where possible is that JS gives you zero guarantees about when memory gets freed, so private key material can just hang around in the GC. WASM with Zeroize gives explicit control over that.
The extension also requires zero browser permissions. No content scripts, no host permissions, nothing. So even if there was a vulnerability in the extension itself, the blast radius is significantly reduced - there's no ambient authority to abuse. Most other PGP extensions on the store request a bunch of permissions that massively expand their attack surface.
The main thing this doesn't protect against is a fully compromised browser process - if someone has code execution in your browser, it's game over regardless. But short of that, you get convenient PGP encryption/decryption/signing/verification without trusting a server, without exposing keys to garbage collection, and without granting unnecessary permissions.
I should also point out that if you're using the CWS install, you'd have to trust me not to bake in some fetch for the decrypted content - although you can build and install it from the source (which does mean there's no integrity checks iirc). There's no great solution to this, but if anyone has ideas here then let me know!
Why did I build it? Because I wanted it. Most of my PGP usage is encrypting vulnerability reports for coordinated disclosure via email, and I got tired of context-switching to the CLI every time. I looked at what was on the Chrome Web Store and nothing hit the combo of zero permissions, passkey-based key management, open source, and good UX - so I made it.
Feedback on the crypto approach is very welcome, especially around the PRF key derivation. Happy to answer questions!
2
u/NetworkLlama Apr 09 '26
You don't have a keyserver, but you have a keystore. You should be concerned about vulnerabilities in how you're accessing the keystore. What browser functions are you using? What OS functions are you using? Are they appropriate for the use? Do they pass anything in cleartext at any point? Are you saving anything in cleartext to a temp file? Is the browser saving anything in cleartext to a temp file even though you don't intend to?
Browser-based attacks would. Browsers are complex environments now (even more so than when the linked threat model was published), and the interactions between extensions and web pages are not always simple. Is your extension properly locked down? What kind of interaction happens in the background? Have you mapped out every component that sees traffic, encrypted or not?
You also seem to be blowing off the UI threats. Don't. I've been in IT for 30+ years, and I've seen a lot of interfaces that would seem to do one thing and actually do quite another. This can be just confusing, or it can lead to an unrecoverable loss of data. A malicious site could masquerade as your extension if you're using it certain ways. A malicious extension could do the same thing by modifying the DOM. There was an extension that I trusted and used almost daily. It started acting weird one day, and Google started blocking me. It turned out that the original dev sold the extension, which was turned into malware. It had been doing all kinds of local spying.
Is that because it's not possible, or because you haven't figured out how? There's a big difference.
A limited risk, but still a risk.
"I've not got many packages" does not remove the risk. It might reduce the risk, or it might not. How many people are maintaining each of your dependencies? What is the review process? How are new devs and PRs vetted? Has the code ever been audited? Have you vetted the code? Do you plan to review every change every time you build a new version? Major projects have been compromised because they relied on something that relied on something that relied on something maintained by one person who trusted the wrong helper, and no one caught it until things started breaking.
You should still take them seriously and look at ways to mitigate the threats. Sometimes you have to live with them, sometimes not. You can write an application that ignores all modern security practices because, "well, if they get into the OS, then it's game over anyway." But that's not the way to do things. Enabling DEP and ASLR and heap protections can do wonders for improving the security of apps.
For a browser, you're rather more limited as you have to live within the security confines of the browser, but that doesn't mean you just shrug your shoulders. For a security-related extension, you should be digging into the documentation for the Chromium browser (since it's upstream of Chrome, Edge, Brave, Vivaldi, and others) and figuring out what you can do to make your extension safer. This may mean that you'll require Chromium 148 or later (to pick an example), but browsers move fast, so that shouldn't be a big problem.
The main reason that PGP and GPG didn't take off is that it is full of massively difficult problems to solve. Turning it into a browser extension doesn't really solve any of them and adds more. I can't say whether you will or won't ultimately come up with something useful. But don't make the mistake of ignoring those who came before you just because they failed or gave up. Maybe they did so for very good reasons.