Product / Browser extension

Filling passwords is the riskiest moment. We designed for it.

The KalderaShield extension is a Manifest V3 companion for Chromium and Firefox. It fills credentials only on sites it can bind to an existing record, talks to the desktop app over an encrypted loopback bridge, and collects nothing.

What it does

Autofill with a bouncer at the door

The extension injects a content script into http/https pages and offers to fill credentials for the site you are on. Domain matching is validated down to eTLD+1 — lookalike domains on different registrable domains do not receive another site's credentials, and a phishing-alert latch keeps warning once a mismatch is detected.

It has no broad page powers: the manifest requests nativeMessaging, activeTab and storage, the extension pages' CSP is script-src 'self', and the Firefox build declares data_collection_permissions: none. There is no analytics SDK and no telemetry in the bundle.

The pairing dialog on the desktop side must be accepted before the bridge works at all, credentials are leased to the bridge for five minutes at a time and zeroized on expiry, and a revoke action wipes the lease and rotates the pairing token immediately.

How a fill happens

The site asks, the extension checks

The content script finds a login form on the page you are on and asks the background worker. The worker validates the tab URL against the records it may offer — same eTLD+1 or an explicitly saved match.

The desktop decides

The request travels over the native messaging bridge to the desktop app, which returns only credentials bound to that site — broad queries return sanitized metadata with empty passwords.

The fill is bound to the tab

Filling is gated by tab-URL validation on the return path. The extension never accepts fill requests from web pages directly: pages cannot reach the extension's channel at all.

Security Architecture

What the extension does not do

The limits, written down

The extension stores no vault: it is a window into the desktop app, and without the paired desktop running it has nothing to give. It does not sync anything to any server, it does not read pages you have not activated it on, and malware with your OS privileges could reach the pairing token file — a residual risk documented in the threat model rather than denied.

Manifest V3

Minimal permissions

nativeMessaging, activeTab, storage. No broad host access, no scripts evaluated from remote sources, CSP locked to 'self'.

127.0.0.1

Loopback-only bridge

Native messaging talks to the desktop over loopback TCP only; every frame is XChaCha20-Poly1305-encrypted under an HKDF-derived session key.

Firefox 142+

Signed for release Firefox

The Firefox build ships as a Mozilla-signed XPI (AMO), so it installs persistently on Release and Beta; the Chromium build loads unpacked or through your organization's policy.

Frequently Asked Questions

Extension questions

Can the extension work without the desktop app?

No, by design. It holds no vault copy, so a stolen laptop with the extension installed still holds nothing. Everything it can offer comes live from the paired, locked-or-unlocked desktop session.

What stops a fake website from getting my credentials?

Domain validation at eTLD+1, a phishing-alert latch, and the fact that fill offers are bound to validated tab URLs. A different registrable domain is a different site, whatever it looks like.

Does the extension see what I type on every page?

No. The content script is active on http/https pages, but it only reacts to login forms and to your explicit requests through the popup or keyboard. There is no keystroke logging.

Related pages

Download Installer