<feed xmlns='http://www.w3.org/2005/Atom'>
<title>1pass-analysis/README.md, branch main</title>
<subtitle>1Password Firefox Extension Security Review</subtitle>
<id>https://git.yuv.al/1pass-analysis/atom/README.md?h=main</id>
<link rel='self' href='https://git.yuv.al/1pass-analysis/atom/README.md?h=main'/>
<link rel='alternate' type='text/html' href='https://git.yuv.al/1pass-analysis/'/>
<updated>2026-02-26T08:13:23Z</updated>
<entry>
<title>Add key hierarchy analysis, update all docs with WASM/auth/native messaging findings</title>
<updated>2026-02-26T08:13:23Z</updated>
<author>
<name>Yuval Adam</name>
<email>_@yuv.al</email>
</author>
<published>2026-02-26T08:13:23Z</published>
<link rel='alternate' type='text/html' href='https://git.yuv.al/1pass-analysis/commit/?id=7b609fffddf3ae138cdf301c97bad805fc508616'/>
<id>urn:sha1:7b609fffddf3ae138cdf301c97bad805fc508616</id>
<content type='text'>
New document:
- key-hierarchy.md: Full key derivation model, MUK lifecycle, SRP auth,
  biometric unlock, Duo MFA, dSecret bypass, delegated sessions, password
  timebox mechanism, crypto algorithm inventory

Major updates:
- architecture.md: Expanded WASM section with confirmed 80+ rA.* methods,
  clarified WASM is portability layer not security boundary
- trust-boundaries.md: Corrected Zone A (keys in JS heap not just WASM),
  Zone D (confirmed native messaging protocol with biometry messages),
  Zone F (WASM is NOT a privilege boundary), detailed sensitive data table
  with confirmed storage locations, new Critical attack surface category
- message-catalog.md: Added native messaging protocol (biometry save/unlock/
  remove, availability check), desktop connection messages, server notification
  events
- TODO.md: Marked completed items, added key material exposure assessment
  section, authentication &amp; session security section
</content>
</entry>
<entry>
<title>Initial security review docs for 1Password Firefox extension v8.12.2.38</title>
<updated>2026-02-26T07:58:17Z</updated>
<author>
<name>Yuval Adam</name>
<email>_@yuv.al</email>
</author>
<published>2026-02-26T07:58:17Z</published>
<link rel='alternate' type='text/html' href='https://git.yuv.al/1pass-analysis/commit/?id=54adf11e1c8905c97512fcf29d8b3d75aa9eb0cb'/>
<id>urn:sha1:54adf11e1c8905c97512fcf29d8b3d75aa9eb0cb</id>
<content type='text'>
Static analysis of the extracted XPI covering:
- Architecture: runtime topology, WASM modules, boot sequence, permissions
- Message catalog: ~50 background handlers, per-file content script messages
- WebAuthn analysis: page-world monkey-patching, postMessage IPC protocol
- Trust boundaries: 8 zones, 7 crossings, data lifecycle, attack surfaces
- Telemetry: Snowplow, Sentry, DNS privacy proxy, opt-out controls
- TODO: prioritized future work plan
</content>
</entry>
</feed>
