23 ms·
Microsoft Authenticator Chrome Extention is not from MS and is phishing
- judge2020 5y agoLooks like it's been taken down - either enough HN people reported it, or a Googler raised an issue internally and got it taken care of.
- cheph 5y agoPutting this here because Google won't remove it even though it has been reported multiple times.
- judge2020 5y agoI’m sure that, if enough people report it, it’ll be delisted. It only has 500 users so I doubt it’s in any priority queue for a human reviewer to look into it.
- novium 5y agoSadly, the most efficient way is probably to report it to the abuse contact of the host. In this case - Scaleway / Online.net.
- qw 5y agoIt is surprising that they apparently haven't added a more strict check when an extension claims to be from a known company. I would have thought they would have a list of names like "Microsoft", "Facebook" etc. that would trigger a more thorough check. In this case it should be clear that they tried to pose as Microsoft, and it is coming from an account that has no association with Microsoft.
- mrweasel 5y agoYou'd think they'd have a vetting process on their ads as well, but they don't. Not a good one at least. Either Google doesn't care, or they aren't able to do any form of sensible checking of stuff uploaded to they various platforms. Well, either that or they don't see it as a massive issue.
- tasogare 5y agoThey don’t care. A company that can soft-censor (by placing specific warning messages) videos about a virus a few weeks after it became a hot topic in the West could easily detect big corpo brand appropriation if they wanted.
- cheph 5y agoEither Google doesn't care < this one IMO Caring removes money from them, at least in add case, so better to shift the bullshit to their "users", who are really the product being sold to advertisers, so who cares. Customer is always right, its just we are not the customer.
- dt3ft 5y agoThese reports are usually handled by a single person with a dozen other responsibilities. Chances are, nobody will ever read majority of user generated reports. Also, the person may have already left the company and a replacement was deemed by management to not be necessary.
- ableal 5y agoThanks for the heads up. Just when MS started offering login form filling from MS Authenticator ... (At least for me that popped up a couple of days ago, when I used the real Authenticator app for some MS authorization in my phone.)
- pcf 5y agoIf you get this information to a tech journalist who makes a story about it, it'll probably be delisted much quicker.
- davidjgraph 5y agoThe chrome web store is overrun with phishing apps like these, I think it's safe to say Google have given up.
- jarcane 5y agoJust like they have with Play Store.
- emteycz 5y agoPerhaps if the store made more money, they would have motivation to do something about it...
- rebuilder 5y agoIf the store made more money, why would they do anything? If it ain't broke, don't fix it. Now, if the store started making less money because of scams...
- emteycz 5y agoBecause of the prospect of losing that income stream. Their ad services are very well managed. AFAIK they're not making much/any money from the stores now so it makes sense they're not fixing it, or am I wrong?
- swiley 5y agoIt's Google. It doesn't matter how profitable something is, if it's incompatible with their org chart they'll let anything rot.
- robjan 5y agoChicken and egg. They would probably make more money if the store was more curated. At the moment it's hard to discover apps in the sea of spam and fake apps. As an example, there are literally hundreds of QR code readers, most of which are probably based on the same library but with very different levels of security. In fact, one of the top QR readers asks for very invasive permissions without any justification
- Deradon 5y agoImo, it's not a good idea to directly link to the extension as one might accidentally hit the "Add to chrome" button. (e.g. when coming from the homepage and not peeking into the thread here)
- bellyfullofbac 5y agoUnless someone changed the submission title within the 2 minutes of your comment and this reply... you really have a high expectation of catastrophe. Edit: well, don't complain about the downvotes, but here I am after a few downvotes thinking "Wow, who are these baby-coddling users who think HN readers are idiots who don't read the headline and just accidentally click 'Add to Chrome'?".
- Deradon 5y agoSo maybe to explain myself: I'm used to scan through the homepage and open link and comment side by side for a few things that I think are interesting to me. While reading through it, I might get interrupted. So I might come back to a link a few hours later. So lets say, I open up the extension page and forgot the initial context. So for me, it could theoretically happen that I install this extension cuz I assume links posted at HN to be safe.
- breakfastduck 5y agoSolved easily but not making rash assumptions and reading what you're clicking.
- ddmma 5y agoWho approved this in the listing? Should Microsoft sue them.. that would be a start
- f6v 5y agoThe developer's address is harperrodriguez31@gmail.com Good luck figuring out who that is.
- mrweasel 5y agoIt's clearly a mr. Harper Rodriguez, age 31. How many could there possibly be with than name and age? We have his email address, so maybe write to him and ask that he stop pretending to be Microsoft.
- yrro 5y agoI find it rather surprising that anyone with a gmail address can publish an extension that appears to be from Microsoft.
- helsinkiandrew 5y agoVery surprising - I assume that there is absolutely no human check before an extension can be made available.
- majewsky 5y agoI'm surprised that you're surprised. "Absolutely no human check" may as well be Google's tagline.
- rjmunro 5y agoThis extension does not "appear to be from Microsoft". It merely mentions Microsoft in its title. But the fact that the developer was allowed to call themselves "Extensions" is worrying.
- mrweasel 5y agoI love that it's made by: "Extensions"
- donmcronald 5y agoYeah. That’s a clever move by the author. That will trick a lot of people.
- Inhibit 5y agoI'm still amazed that people install (outside of very specific development or page manipulation use cases) Chrome extensions. Are these more common on Chromebooks or some other platform I don't regularly use?
- tasogare 5y agoEven development ones are dangerous, even more so because of the broad permissions they often requires. I’m pretty sure that’s how I got my credit card number stolen once.
- richardstephens 5y agoWithout Dark Reader, uBlock Origin, and JSONView, the web feels broken to me.
- markwillis82 5y agoThank you for Dark Reader... this has made a world of difference
- gpvos 5y agoThose, plus Multi-account containers, and Violentmonkey for a small number of corrections to websites.
- e3bc54b2 5y agoOh the amount of extensions that do one thing that can be much easier and cleaner to be integrated via userscripts is staggering! Its all the little things that add up, and I hate that mobile Firefox update disabled Tampermonkey. Talk about planned regressions. Pardon my French, but fuck Mozilla and their recommended extensions program.
- detaro 5y agoWhy are you amazed about that?
- chaozznl 5y agoIf everyone that reads this simply takes the time to report it, the HN community should be able to get this extension down fairly quicly, right? https://chrome.google.com/webstore/report/mabdjppmcjpjploliggpbonahnjjlgkf https://chrome.google.com/webstore/report/mabdjppmcjpjplolig...
- denysvitali 5y agoIt's Google, so, no?
- dijit 5y agoGoogle’s automated systems do have anomaly detection that would flag it if there were many reports though.
- Cthulhu_ 5y agoThat's exactly it, dogpiling can be discarded as anti-competitive behaviour.
- formerly_proven 5y agoIt works on other, bigger and more important Google properties what makes you think the Chrome store handles it properly?
- carschno 5y agoWhile I appreciate the approach of making "the world" a bit better once you see a chance to do so, I also don't think a company like Google should (be able to) leave it to random internet users to clean up their mess.
- geocar 5y agoThey could offer a bounty.
- bilekas 5y agoReally surprising that something so blatant would get past the playstore checks..If i remember correctly, there was a vetting process on the first updload of an app anyway, not sure about extensions. Brand/Company names could easily be flagged as a 'needs review' for example.
- JPKab 5y agoThis is just an extension and whoever is supposed to be vetting things at Google is completely asleep at the wheel. Think about the fact that this extension has been up for over 2 weeks but if I upload a YouTube video where somebody says the wrong thing it's down in minutes. They have armies of highly paid employees and none of them can take care of this?
- e3bc54b2 5y agoI doubt bots can sleep.. That is, if Google have a bit for this at all. But I like your sense of humor if you say there is actual human in charge of this.
- JPKab 5y agoLol. Yes you are, of course, correct. What I should have said is the Product Manager at Google in charge of the extensions for Chrome is asleep at the wheel.
- soulchild37 5y agoMicrosoft lawyer should file a DMCA for abusing trademark, then it should be resolved quickly
- kube-system 5y agoYou cannot legally file a DMCA notice for trademarks. The DMCA is for copyrights only.
- zyx321 5y agoMicrosoft could file a DMCA claim for violating their copyright. Google usually does not verify claims before executing them, and there's no penalty for false claims.
- kevingadd 5y agoCan confirm that's how it works. Google does not verify that claims are fully filled out (a nearly blank claim form is sufficient), they don't respond to counter-notices in a timely matter (1+ month processing time), and they don't provide information on the claimant that you can use to pursue them for a false claim.
- kube-system 5y agoFalse DMCA claims are penalized under section F of the DMCA. > (f)Misrepresentations.—Any person who knowingly materially misrepresents under this section— > (1)that material or activity is infringing, or > (2)that material or activity was removed or disabled by mistake or misidentification, > shall be liable for any damages, including costs and attorneys’ fees, incurred by the alleged infringer, by any copyright owner or copyright owner’s authorized licensee, or by a service provider, who is injured by such misrepresentation, as the result of the service provider relying upon such misrepresentation in removing or disabling access to the material or activity claimed to be infringing, or in replacing the removed material or ceasing to disable access to it. Now, in this instance we're talking about a fraudulent listing, so I can't imagine there's much civil liability to worry about, but the suggestion that there is "no penalty for false claims" is not true. And also, DMCA claims are made with a statement that they are accurate "under penalty of perjury". I haven't seen anyone convicted under this, but I wouldn't imagine that MS legal would find this to be an acceptable way to solve the issue.
- samsaga2 5y agoDeveloper's email harperrodriguez31@gmail.com I don't think Microsoft engineers uses gmail. It could be their real name?
- Hallucinaut 5y agoCan we also take a moment to assign partial blame to Microsoft for this situation? Their authentication is a shambles, they try to force you to use their app rather than other 2FA providers and heavily steer you towards having to install Microsoft apps. And that's if you're lucky and they arbitrarily don't mandate a phone number and an email address for a corporate account. Oh and the email address can't be the primary corporate domain that owns the account because of course what we need is personal emails to authenticate business accounts. Lord help you if you were ever an early adopter of an onmicrosoft.com domain. You will remain in purgatory until you wipe your accounts and start again.
- reallyManSrs 5y agoIf the 100M iPhone breach wasn't Apples Fault, this couldn't possibly be MS fault. Both were due to deficiency of a service.
- mavhc 5y agoNeeds to be a standard for push notification 2FA. Does Google still require a phone number for enabling 2FA?
- sundvor 5y agoI'm using my standard TOTP 2FA app with my Microsoft account, fwiw.
- sdflhasjd 5y agoDoes anyone have the .crx file to inspect?
- yread 5y agohttps://clients2.google.com/service/update2/crx?response=redirect&os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromiumcrx&prodchannel=beta&prodversion=79.0.3945.53&lang=ru&acceptformat=crx3&x=id%3Dmabdjppmcjpjploliggpbonahnjjlgkf%26installsource%3Dondemand%26uc https://clients2.google.com/service/update2/crx?response=red...
- pingec 5y agoSlightly offtopic but I think the problem of rogue addons applies to firefox as well. I wish it were possible in firefox to limit which addons can be loaded on a per-container basis. The extensions I want loaded on banking websites, social media and youtube are completely different. And limiting them per-container makes it a relatively simple mental model to reason about.
- ajdude 5y agoI was just thinking about this the other day. I would love to keep google/gststic blocked in noscript on most containers except the Google container.
- njsubedi 5y agoIn that case you can use multiple profiles.
- Kye 5y agoThe point of containers is to not have to juggle a bunch of profiles.
- capableweb 5y agoHm, not really, they have different use cases, and Containers was never meant to 100% replace Profiles. Containers are for being able to keep separate identities in the same browser window, but on a per-tab basis. Profiles are for being able to separate different browser instances, with all their settings, extensions and so on. While Profiles was used before to do the same thing that Containers now allow you to do, there are things you cannot do with Containers that you'll need to use Profiles for. Having separate extensions for different sessions is one of those things.
- pingec 5y agoI was able to learn how to use containers quite quickly and some container addons make it very easy to use them. Not so much for profiles, setting up multiple profiles seems very tiresome and honestly whenever I look up how to create multiple profiles I lose interest. Would really love a solution that is as easy to manage and use as containers and allows to control which addons are allowed to load/run. Edit: Also IIRC multiple profiles cannot be synced across devices through the same firefox account while it is possible with containers
- lm741 5y agoCRXcavator is a pretty useful tool for scoping out Chrome extensions like this: https://crxcavator.io/report/mabdjppmcjpjploliggpbonahnjjlgkf/1.1.0?platform=Chrome https://crxcavator.io/report/mabdjppmcjpjploliggpbonahnjjlgk... Similarly, Urlscan.io is pretty useful for scoping out sketchy links like the one in the extension's html: https://urlscan.io/result/d95c1113-a446-4c94-8b1f-dd7d5305313c/ https://urlscan.io/result/d95c1113-a446-4c94-8b1f-dd7d530531...
- tester34 5y agoI wonder why there's no ONE employee who could read all names of extensions and just click "accept" "reject" whenever they apply I bet it'd reduce amount of scams significantly
- II2II 5y agoIt would be more complicated than that in the vast majority of cases. Sure, you would catch people trying to impersonate major corporations that everyone is familiar with. With well trained staff and clear polices you could also catch some more obscure cases, such as companies that serve businesses yet is relatively unknown outside corporate environments. It becomes much more difficult to verify authenticity otherwise since it would involve research, not just reading names. That research would also have to be conducted with care, since all but the most trivial of scams would factor that into their methodology.
- asddubs 5y agosure, it's easy to make demands like this in an internet comment, but this would cost google easily thousands of dollars a year, it would surely drive them out of business
- deleted 5y ago[deleted]
- sundvor 5y agoI laughed. (I'm also frustrated by just about everything they do, and the fact that I'm so reliant on it.)
- diogenesjunior 5y ago>it would surely drive them out of business LOL. Agreed
- majewsky 5y agoPlease recalibrate your irony detector.
- aritmo 5y agoIt is a very simple extension. No effort to hide the malicious URL. See the source: https://crxcavator.io/source/mabdjppmcjpjploliggpbonahnjjlgkf/1.1.0?file=popup.html&platform=Chrome https://crxcavator.io/source/mabdjppmcjpjploliggpbonahnjjlgk... The malware link: hxxp://przekierowanie2.chrome_augustow.pl/?123-Microsoft525896
- dividuum 5y agohttps://crxcavator.io https://crxcavator.io is nice. I always wondered by there is no direct way to easily peek into an extension's source code.
- diogenesjunior 5y agoThere is... you can do it yourself: https://clients2.google.com/service/update2/crx?response=redirect&prodversion=[VERSION]&acceptformat=crx2,crx3&x=id%3D[ID]%26uc https://clients2.google.com/service/update2/crx?response=red... Where [VERSION] is your chrome version and [ID] is the extensions ID. Hope this helps ;)
- jakub_g 5y agoThere's also an... extension to view the extensions: https://chrome.google.com/webstore/detail/chrome-extension-source-v/jifpbeccnghkjeaalbbjmodiffmgedin?hl=en https://chrome.google.com/webstore/detail/chrome-extension-s... If you trust it :)
- deleted 5y ago[deleted]
- Trung0246 5y agoInteresting... The domain did not considered to be malicious on VirusTotal: https://www.virustotal.com/gui/url/ab2a0f6d00de42ebf4ff8cb2c8db5db47661cccdb12e291c54c718ddab76be24/detection https://www.virustotal.com/gui/url/ab2a0f6d00de42ebf4ff8cb2c...
- lgats 5y agothe link is ://przekierowanie2-chrome.augustow.pl/?123-Microsoft525896 for those confused about the underscore in the tld
- donmcronald 5y agoHow about the related one that claims to be from Microsoft, but uses msftliveapps@gmail.com? https://chrome.google.com/webstore/detail/microsoft-autofill/fiedbfgcleddlbcmgdigjgdfcggjcion?hl=en-US https://chrome.google.com/webstore/detail/microsoft-autofill... I literally can’t tell real from fake on these shitty platforms. Edit: Or this using msandapp.chrome@gmail.com: https://chrome.google.com/webstore/detail/microsoft-news-new-tab/lklfbkdigihjaaeamncibechhgalldgl?hl=en-US https://chrome.google.com/webstore/detail/microsoft-news-new... The average person has no chance :-(
- koheripbal 5y agoHow on Earth is "Offered by: Microsoft Corporation" not verified in literally any way whatsoever. That's so poorly vetted it's negligent. Maybe extensions and apps should be signed by domain ownership?
- yrro 5y agoIn general this is a good idea. But in the case of Microsoft--good luck figuring out which of Microsoft's thousands of domains are legit! :)
- koheripbal 5y agoIt would seem to me that Microsoft would choose to link it to microsoft.com so that customers can easily recognize its authenticity.
- yrro 5y agoThey have already failed this test: they are already publishing extensions using msftliveapps@gmail.com and msandapp.bgcextn@gmail.com, doubtless many others!
- evilsnoopi3 5y agoI believe Google requires you publish Chrome extensions with an @gmail address, in which case MS doesn’t really have a choice.
- yrro 5y agoArchiving the extension author's email address before it's taken down: harperrodriguez31@gmail.com The same account has published another extension: https://chrome.google.com/webstore/detail/iartbook-digital-painting/pndkaoeigpfhjkjblpmneppaffijeoof?hl=en-US https://chrome.google.com/webstore/detail/iartbook-digital-p... [edit] both have now been nuked - about 2 hours since this was posted.
- rebuilder 5y agoI wonder if the account has been taken over by someone.
- grigarav 5y agoReport it for illegal activity instead of posting a negative review, will have a bigger impact.
- Zitrax 5y agoAlso writing a review requires you to install the extension first.
- swiley 5y agoSo glad Google has to vet the extensions... they seem to do a pretty good job of stopping scams that way. Do people like walled gardens just so they have someone to blame when this kind of thing happens? They obviously don't work.
- Geenirvana 5y agoNaive question. How does one know this is malicious before installing it? I think this would fool me if it wasn't for this thread. The only thing that seems off to me is the lack of information, and hovering over the contact developer shows a gmail address. I wouldn't have looked at the comments in the reviews as I know what the Microsoft Authenticator does, as I use it constantly on my mobile device. So in this instance, I could have seen myself finding this link, clicking Add to Chrome without much thought. I can surely see how an average user would fall for this and it's frightening.
- tjpnz 5y ago>Naive question. How does one know this is malicious before installing it? You can't, that's the problem.
- supergirl 5y agoyeah, the chrome marketplace is the wild west. probably the easiest way to get hacked is to install some extensions from there, like this one https://chrome.google.com/webstore/detail/microsoft-autofill/fiedbfgcleddlbcmgdigjgdfcggjcion?hl=en-US https://chrome.google.com/webstore/detail/microsoft-autofill... that is from "Microsoft Corporation" but has a gmail contact address. the android app store is probably not much better. google just doesn't care about the users. they invest in good tech and launch shiny products that get some market share and then leave the users to deal with the automated replies while engineers go to build the next shiny thing.
- novium 5y agoThat's an actual Microsoft extension though[0]. [0] https://blogs.windows.com/windowsexperience/2021/02/05/simplify-and-secure-your-life-with-microsofts-autofill-solution-for-passwords/ https://blogs.windows.com/windowsexperience/2021/02/05/simpl...
- tyingq 5y agoPretty low effort too. It's just a popup with a button that links to hxxp://przekierowanie2-chrome.augustow.pl/?123-Microsoft525896 , which then redirects to hxxps://extensions-install.com/?123-Microsoft525896 The form itself doesn't look particularly MS-like, and the grammar is pretty bad.
- ocdtrekkie 5y agoOne of the things that stuns me, is that for as effective as phishing and scam ads are today, they could be hundreds of times more effective if someone put the effort in to run them through a spell check in the target language. It sometimes seems like the saving grace to society is that criminals aren't actually all that smart.
- tyingq 5y agoThis one may have been run through a spell checker. The spelling is fine. It's the grammar/phrasing: "Complete the installation register an account." "How to register? Create an account and then verify, it is anti spam protection."
- Namidairo 5y agoIsn't this sometimes intentional, to act as a filter of sorts, for more prospectful targets?
- ocdtrekkie 5y agoIt can be, particularly for scams which require human interaction. But for an extension that collects phishing data, there's no point in it: If people enter data into it, they are a good target.
- rchaud 5y agoEmail scammers have been A/B testing their pitches for a long time now. The evidence is clear: dumbing down the pitch is far more effective than attempting to capture more sophisticated users.
- kypro 5y agoNot entirely related, but is there a simple way to run an application like a web browser in a sandbox on Windows? Sometimes I find myself wanting to install a dodgy extension or software, but I don't know how to test it safely without using something like virtual box as a sandboxed enviroment. I kinda want something where I can just right-click an .exe and run it in a sandbox.
- paulz_ 5y agoThere is actually an app that I used to setup for people years and years ago that did this. Recently they went fully open source. Pretty neat little piece of software. https://github.com/sandboxie/sandboxie https://github.com/sandboxie/sandboxie
- kencausey 5y agoHave you tried Windows Sandbox (https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-sandbox/windows-sandbox-overview https://docs.microsoft.com/en-us/windows/security/threat-pro...)?
- SquareWheel 5y agoI really liked Windows Sandbox when I used it. My only complaint was I could no longer use VirtualBox (I guess because Windows was acting as a hypervisor). Do you know if this limitation has since been removed? I know there was work on it, but I don't know how that turned out.
- oauea 5y agoVirtualBox can perform under HyperV nowadays, although it performs less well.
- ocdtrekkie 5y agoThis has been my main limitation on using... about half a dozen neat Windows virtualization features. I wasn't willing to give up... every... other virtualization tech to have the Hyper-V feature installed. Hoping the other child comment is right and that there's been some improvement in this space.
- deleted 5y ago[deleted]
- mgol94 5y agoLink is dead, they removed it
- deleted 5y ago[deleted]
- 1cvmask 5y agoA simple solution would be to allow any domain to sign up and show he email extension like company.com or helloworld.co.uk etc…… I remember seeing this app when I had searched for the Saas Pass Authenticator & Password Manager in the past. (worked on the 2FA design of the saas pass browser extension). I naturally assumed it was an official Microsoft extension.
- minikites 5y agoThe pitch from companies offering "stores" like these (Apple, Google, Microsoft) is that they're for the protection of users. Apple can't stop scams, Google can't stop scams, Microsoft can't stop scams. It's time we saw these stores for their true purpose: platform control, vendor lock-in, and in the case of pay stores, recurring services revenue. They were never about protecting users.
- breakfastduck 5y agoYou would not get a fake Microsoft-impersonating app on the Apple App Store, though, because of the very checks you're writing off as nothing but a money grab.
- minikites 5y agoSo I submit my scam app as "MichaelSoft". Given how many scams remain on every app store, it's clear these companies don't actually want to address these problems because it's not actually a problem for them, it's just a cost center. Apple can tout their "numbers" (https://www.apple.com/newsroom/2021/05/app-store-stopped-over-1-5-billion-in-suspect-transactions-in-2020/ https://www.apple.com/newsroom/2021/05/app-store-stopped-ove...) all they want, but there's no way to verify them. They can make up any of these numbers and nobody can say otherwise. It's all smoke and mirrors.
- alpacaillama 5y agoI would pay you a $100 USD if you could consistently get a scam like this into the App Store. And by this I mean: - Low effort - Phishing for data - Pretending to be Microsoft.
- breakfastduck 5y ago'Given how many scams remain on every app store etc...' That's not what we're talking about. You will not be able to get an app onto the App Store using microsofts brand image, logos, pretending to be microsoft to phish data from people. It will not get through. You've obviously got a very strong informed opinion on the topic, but this is just fact.
- RockmanZero 5y agoclassic google app store: they never give a fxxk about their users
- bob1029 5y agoThe one thing I hate about the Apple store is also its best feature when dealing with crap like this. As a consumer, business entity verification & savagely-enforced PKI/codesigning does make for a much safer app ecosystem. As a developer and small business owner, Apple is a fucking nightmare to build apps for. I much rather build Android/Windows/Web platform because its so much easier to iterate in our shop. All of that said, could we at least consider requiring some basic domain verification process around these things so that it is possible in theory to determine who endorsed a specific app or extension? If a gmail account & some "reputation" is all it takes to trickle to the top of the store, I think we are missing several important security controls.
- bobbob1921 5y agoI’ve always been concerned with the chrome store in regard to chrome extensions. While I do know some level of scrutiny is applied to new brand new extensions uploaded to their store platform, my concern has always lied in a developers ability to update an existing extension, which is then almost universally updated on all clients upon which that extension as it’s installed. I have seen extension updates (updates not releases) get approved much too quickly to be properly vetted on the stores side.