Item logo image for Secret Question Helper

Secret Question Helper

ExtensionPrivacy & Security2 users
Item media 1 (screenshot) for Secret Question Helper

Overview

Replace guessable security answers with deterministic security answers generated via local crypto.

Secret Question Helper replaces guessable “security answers” with deterministic cryptographic signatures derived from the exact question text and your private key. This yields stable, site‑agnostic answers without storing personal facts—improving consistency and security across account recovery flows. How it works: - Deterministic signing: ECDSA P‑256 (RFC6979) over the selected question text, returning a Base64 DER signature. - Seamless filling: The content script finds question/answer pairs and fills the signature into the answer field. - Encrypted at rest: Your private key is stored only as a flattened JWE (RFC 7516) using PBES2-HS256+A256KW with AES-256-GCM; the key-encrypting key derives from your passphrase via PBKDF2-SHA256 with salt and 600k iterations. - Session unlock: Passphrase is kept only in session memory; unlock via the popup, lock manually or via optional auto‑lock timeout. - Zero trust: No external network calls; all signing occurs locally in the background service worker. Why use it: - Avoid weak, guessable answers based on personal data. - Ensure consistency across sites: same question text → same signature. - Keep control: Export/import the flattened JWE encrypted key; passphrase never persisted. Privacy and security: - No data collection or transmission. The extension does not send your page content, signatures, keys, or passphrases anywhere. - Private key remains encrypted at rest; the passphrase resides only in session storage when unlocked. - Sensitive buffers are zeroized after signing as good hygiene. Getting started: - Open Options to generate and export an encrypted key (requires passphrase ≥16 chars). - Unlock in the popup and click “Sign & Fill Page” on forms with security questions. - Configure an optional auto‑lock timeout in minutes. Limitations: - While unlocked, a compromised browser could request signatures. Lock after use. - Some pages may structure question/answer fields unusually; heuristics aim to cover common layouts.

Details

  • Version
    1.1.0
  • Updated
    January 1, 2026
  • Offered by
    Yevgeniy Kononovich
  • Size
    1.31MiB
  • Languages
    English
  • Developer
    Email
    secretquestionhelper@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, please open this page on your desktop browser

Google apps