Is Directors Desk SecureView safe?
Directors Desk SecureView bridges document links on directorsdesk.com to a local native viewer, forwarding a hardcoded key seed bundled in the extension.
When a user clicks a document link on a directorsdesk.com page, the extension fetches a one-time token from the site and assembles an XML payload that includes a static string 'Hello Machine Key Seed!' hardcoded in the distributed bundle. That payload is sent to a local native messaging host (com.google.chrome.nasdaq) which handles the secure document viewing. Because the key seed is static and publicly readable from the Chrome Web Store bundle, it provides no per-install secrecy.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 2.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed Directors Desk SecureView contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.google.chrome.nasdaq (local native messaging host)
Directors Desk SecureView sends data to com.google.chrome.nasdaq (local native messaging host). Named as a recipient in this extension's own analysis.