<feed xmlns='http://www.w3.org/2005/Atom'>
<title>1pass-analysis/.gitignore, branch main</title>
<subtitle>1Password Firefox Extension Security Review</subtitle>
<id>https://git.yuv.al/1pass-analysis/atom/.gitignore?h=main</id>
<link rel='self' href='https://git.yuv.al/1pass-analysis/atom/.gitignore?h=main'/>
<link rel='alternate' type='text/html' href='https://git.yuv.al/1pass-analysis/'/>
<updated>2026-02-26T07:58:17Z</updated>
<entry>
<title>Initial security review docs for 1Password Firefox extension v8.12.2.38</title>
<updated>2026-02-26T07:58:17Z</updated>
<author>
<name>Yuval Adam</name>
<email>_@yuv.al</email>
</author>
<published>2026-02-26T07:58:17Z</published>
<link rel='alternate' type='text/html' href='https://git.yuv.al/1pass-analysis/commit/?id=54adf11e1c8905c97512fcf29d8b3d75aa9eb0cb'/>
<id>urn:sha1:54adf11e1c8905c97512fcf29d8b3d75aa9eb0cb</id>
<content type='text'>
Static analysis of the extracted XPI covering:
- Architecture: runtime topology, WASM modules, boot sequence, permissions
- Message catalog: ~50 background handlers, per-file content script messages
- WebAuthn analysis: page-world monkey-patching, postMessage IPC protocol
- Trust boundaries: 8 zones, 7 crossings, data lifecycle, attack surfaces
- Telemetry: Snowplow, Sentry, DNS privacy proxy, opt-out controls
- TODO: prioritized future work plan
</content>
</entry>
</feed>
