Is Softdreams công cụ ký điện tử safe?
Softdreams công cụ ký điện tử exposes a hardware-token signing bridge to any web page without enforcing an origin allowlist.
The extension injects a script into every page that makes cryptographic signing and certificate operations available to any JavaScript on the page. Messages relayed through the content script reach a native messaging host (com.tokensign) that performs signing with the user's hardware token; the background script contains an unfilled TODO where an origin allowlist check should be but is absent. As a result, any site the user visits can trigger signing operations or read certificate details without restriction.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itSoftdreams JSC - no other listings under this identity, 1 shared hostname
Softdreams JSC - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 0.1.6. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Schedule its own background tasks
alarms