The Microsoft Authenticator extension in the Chrome store wasn't actually made by Microsoft. Oops, Google
- Reference: 1621407724
- News link: https://www.theregister.co.uk/2021/05/19/chrome_extension_microsoft_authenticator_fake/
- Source link:
The legit Microsoft Authenticator generates one-time codes for multi-factor authentication, and [1]lately gained password-manager-like features.
However, it’s only [2]available as a smartphone app, and not as a Chrome extension. When someone submitted a dodgy Chrome add-on called Microsoft Authenticator to the browser's store, one would hope Google would have given it more than a cursory glance and checked that it was legit. Instead, the bogus extension was accepted into the store.
[3]
[4]
[5]
The add-on looked fairly convincing; it had Microsoft's logo, at least hundreds of downloads, and a three-star rating. Rather than declare its developer as Microsoft Corporation, though, the software simply said it was offered by "Extension," [6]according to GHacks.
It would have been nice if Google had checks and systems in place to catch extensions masquerading with a company in its name – in this case, Microsoft – when it wasn't actually submitted by that company.
[7]FYI: There are thousands of Chrome extensions with so, so many fake installations to trick you into using them
[8]Fake crypto-wallet extensions appear in Chrome Web Store once again, siphoning off victims' passwords
[9]Google's clever-clogs are focused on many things, but not this: The Chrome Web Store. Devs complain of rip-offs, scams, wait times
[10]Chrome extensions are 'the new rootkit' say researchers linking surveillance campaign to Israeli registrar Galcomm
[11]Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store
[12]Google burns down more than 500 private-data-stealing, ad-defrauding Chrome extensions installed by 1.7m netizens
[13]Google's Chrome Web Store under fire for shoddy service and cryptic policies
[14]Google halts paid-for Chrome extension updates amid fraud surge: Web Store in lockdown 'due to the scale of abuse'
Further inspection using analysis tool CRXcavator revealed the add-on's code contained a [15]suspicious URL that took the browser to a website [16]hosted in Poland.
Indeed, it's said the extension tried to phish netizens by redirecting them to a fake login page and asking for account credentials. Some [17]reported the application sucked up high amounts of CPU resources and perhaps mined cryptocurrencies in the background.
Google declined to comment on the record about how this add-on slipped through the net. The extension has now been pulled. Users who installed the Chrome add-on will receive a warning that the software has been disabled at Google's end.
[18]
"Microsoft has never had a Chrome extension for Microsoft Authenticator," the Windows giant told The Register . "The company encourages users to report any suspicious extensions to the Chrome Web Store." ®
Get our [19]Tech Resources
[1] https://www.theregister.com/2020/12/16/authenticator_autofill/
[2] https://www.microsoft.com/en-us/account/authenticator
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YKThu@cV@iefDawMCclL6QAAAMY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKThu@cV@iefDawMCclL6QAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKThu@cV@iefDawMCclL6QAAAMY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.ghacks.net/2021/05/18/dont-download-this-microsoft-authenticator-extension-for-chrome-it-is-fake/
[7] https://www.theregister.com/2020/05/28/chrome_web_store_fraud/
[8] https://www.theregister.com/2020/05/06/chrome_malicious_extensions/
[9] https://www.theregister.com/2020/01/14/chrome_web_store_scam/
[10] https://www.theregister.com/2020/06/18/chrome_browser_extensions_new_rootkit/
[11] https://www.theregister.com/2020/04/15/google_malicious_chrome/
[12] https://www.theregister.com/2020/02/14/500_chrome_extensions_removed/
[13] https://www.theregister.com/2019/10/25/chrome_web_store_issues/
[14] https://www.theregister.com/2020/01/27/google_disables_web_store/
[15] https://crxcavator.io/source/mabdjppmcjpjploliggpbonahnjjlgkf/1.1.0?file=manifest.json&platform=Chrome
[16] https://www.dnsinspect.com/przekierowanie2-chrome.augustow.pl/10559359
[17] https://news.ycombinator.com/item?id=27194620
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKThu@cV@iefDawMCclL6QAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[19] https://whitepapers.theregister.com/
Re: Epic
Why? Were Google demanding a 30% cut of the Phishing profits?
qui authenticators et authenticas reddat?
An age old question.
You get what you pay for...
so they say
Certificates
Why not require that apps are signed by a certificate owned by the submitting party and make part of the checks before publishing a validation that the certificate is valid and lines up to the submitting party.
Back in the old days, we used to download applications direct from the vendors website, hence we could check if we trusted the vendor ourselves.
Looks like we have taken yet another step backwards in the race to dumb down technology with the inevitable outcome that security gets worse as users get less visibility on the source and trustworthiness of the code they use as other, better routes get gradually taken away for
websync, extensions, ease of use
Considering that 2fa is supposed to be "inaccessible" to an extent, that customers choose these kind of extensions in the first place makes this firmly the responsibility of the user.
"Google declined to comment [,,] about how this add-on slipped through the net"
It slipped through because the net has links that are a mile wide.
Let's be clear : Google is not there to curate the content of its Store, it's there to make money. Anything goes until someone complains. That's when Google reacts and goes fishing for a reason not to remove the app.
In this case, it didn't find any, so it removed the app.
But if you think Google is going to pre-emptively deprive itself of revenue when nobody has noticed anything, I have a bridge to sell you.
Epic
Coming to an iPhone near you if Epic wins its case against Apple.