The AI Bookmark Manager uses AES-GCM encryption to protect your sensitive credentials (Notion API tokens and database IDs) stored in Chrome's local storage.
-
Key Generation: A unique encryption key is generated for each installation using:
- The Chrome extension ID (unique per installation)
- A salt value
- SHA-256 hashing
- The result is used to create an AES-256-GCM key
-
Encryption Process:
- When you save credentials, they are encrypted using AES-GCM
- A random 96-bit IV (Initialization Vector) is generated for each encryption
- The IV and encrypted data are combined and stored as Base64
-
Decryption Process:
- When retrieving credentials, the IV is extracted
- The data is decrypted using the same key
- Original plaintext is returned
-
Not Zero-Knowledge: The encryption key is derived from the extension ID, which means:
- Anyone with access to your Chrome profile can decrypt the data
- This is NOT end-to-end encryption
- This protects against casual browsing but not determined attackers with profile access
-
Physical Access: If someone has physical access to your computer and Chrome profile, they can potentially access your credentials.
-
Profile Sync: If you sync your Chrome profile, encrypted data may sync across devices, but the key derivation is per-installation.
✅ Recommended Actions:
-
Use Integration Tokens, Not Personal Tokens
- Create a dedicated Notion integration for this extension
- Don't use your personal Notion API token
-
Limit Integration Permissions
- Only grant the integration access to specific databases
- Use Notion's sharing settings to restrict access
-
Rotate Tokens Regularly
- Change your integration tokens periodically
- Revoke old tokens after updating
-
Lock Your Computer
- Always lock your computer when stepping away
- Use a strong user password
-
Don't Share Your Chrome Profile
- Keep your Chrome profile private
- Use separate Chrome profiles for different purposes
-
Clear Credentials When Not Needed
- Use the "Clear" button to remove stored credentials
- Re-enter them only when needed
Without Encryption (previous versions):
- Credentials stored as plain text
- Readable by any script or extension
- Visible in Chrome DevTools
- Easy to extract
With Encryption (current version):
- Credentials encrypted with AES-256-GCM
- Requires decryption key to read
- Not visible in DevTools
- Significantly harder to extract
// Encryption algorithm
Algorithm: AES-GCM
Key Length: 256 bits
IV Length: 96 bits (12 bytes)
Key Derivation: SHA-256 hash of (Extension ID + Salt)If you discover a security vulnerability, please email the maintainer or create a private security advisory on GitHub. Do not create public issues for security vulnerabilities.
- Encryption weaknesses
- Credential leakage
- XSS vulnerabilities
- Unauthorized data access
- Any security-related bugs
Security updates will be released as soon as possible after a vulnerability is confirmed. Always keep your extension updated to the latest version.
This security documentation is part of the AI Bookmark Manager project and is subject to the same license terms.