Is ESCB-PKI user certificate enrollment safe?
ESCB-PKI bridges certificate enrollment pages on ESCB and BDE sites to a native messaging host that loads PKCS11 DLLs supplied by the page.
The extension injects a JavaScript API (IndraToken.js) into specific paths on *.bde.es and *.escb.eu. When a page calls that API, the extension relays the request through a content-script port to a background service worker, which forwards it verbatim to the native messaging host indra.minsait.indratokennativewrapper. The native host is then expected to load a PKCS11 library by the name the page provided, with no path validation performed in the extension layer.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itBANCO DE ESPAÑA - 1 other listing from the same operator, none carrying a finding
BANCO DE ESPAÑA - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same operator - 1 listing
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging