Secret Question Helper

Replace guessable security answers with deterministic security answers generated via local crypto.

As of June 2026, Secret Question Helper has 3 users in the Privacy & Security category.

Usersup 50.0 percent+50.0%
3
3
Ratingno change0%
— reviews
Reviewsno change0%
Version
1.1.0
Manifest V3

History

6 snapshots

Tracking since Apr 6, 2026.

3.082.51.92Apr 6, 2026Jun 5, 2026
View as table
DateUsersRatingReviewsVersion
Apr 6, 202621.1.0
Apr 20, 202631.1.0
Apr 30, 20261.1.0
May 9, 202621.1.0
May 17, 202631.1.0
Jun 5, 202621.1.0
Now31.1.0

Permissions & access

Permissions
storagealarmsactiveTabscripting
Host access
None declared

Screenshots

Secret Question Helper screenshot 1

About

Secret Question Helper replaces guessable “security answers” with deterministic cryptographic signatures derived from the exact question text and your private key. This yields stable, site‑agnostic answers without storing personal facts—improving consistency and security across account recovery flows.

How it works:
- Deterministic signing: ECDSA P‑256 (RFC6979) over the selected question text, returning a Base64 DER signature.
- Seamless filling: The content script finds question/answer pairs and fills the signature into the answer field.
- Encrypted at rest: Your private key is stored only as a flattened JWE (RFC 7516) using PBES2-HS256+A256KW with AES-256-GCM; the key-encrypting key derives from your passphrase via PBKDF2-SHA256 with salt and 600k iterations.
- Session unlock: Passphrase is kept only in session memory; unlock via the popup, lock manually or via optional auto‑lock timeout.
- Zero trust: No external network calls; all signing occurs locally in the background service worker.

Why use it:
- Avoid weak, guessable answers based on personal data.
- Ensure consistency across sites: same question text → same signature.
- Keep control: Export/import the flattened JWE encrypted key; passphrase never persisted.

Privacy and security:
- No data collection or transmission. The extension does not send your page content, signatures, keys, or passphrases anywhere.
- Private key remains encrypted at rest; the passphrase resides only in session storage when unlocked.
- Sensitive buffers are zeroized after signing as good hygiene.

Getting started:
- Open Options to generate and export an encrypted key (requires passphrase ≥16 chars).
- Unlock in the popup and click “Sign & Fill Page” on forms with security questions.
- Configure an optional auto‑lock timeout in minutes.

Limitations:
- While unlocked, a compromised browser could request signatures. Lock after use.
- Some pages may structure question/answer fields unusually; heuristics aim to cover common layouts.

Technical

Version
1.1.0
Manifest
V3
Size
1.31MiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
ndiobihemghddfffgcnobodjejhkoekk
Developer ID
u823b4606d6897293e2836e4f95c98d41
Developer Email
[email protected]
Created
Dec 23, 2025
Last Updated (Store)
Jan 1, 2026
Last Scraped
Jun 5, 2026
Website
Support URL
Privacy Policy

Similar extensions

Alternatives to Secret Question Helper, ranked by description similarity.

Data sourced from the Chrome Web Store · last verified Jun 5, 2026.