Microsoft Authenticator Chrome Extention is not from MS and is phishing
chrome.google.com
chrome.google.com
https://chrome.google.com/webstore/detail/microsoft-autofill...
I literally can’t tell real from fake on these shitty platforms.
Edit: Or this using msandapp.chrome@gmail.com:
https://chrome.google.com/webstore/detail/microsoft-news-new...
The average person has no chance :-(
Maybe extensions and apps should be signed by domain ownership?
Google doesn't require a gmail adresse to publish.
There’s no way even for technical people to make a proper assessment of the trustworthiness of the publisher.
Google has ruined the internet because they want Google Search to be the only “trustworthy” source online. Too bad they suck at it and Google search is a steaming pile of shit now.
https://blogs.windows.com/windowsexperience/2021/02/05/simpl...
First arcane password rules so it takes 5 minutes and half a dozen attempts to come up with a password that is accepted. Then force the user to change it often. Then add email verification. Then SMS/phone verification. Still not good enough, now we all need to have a hardware token to buy the counterfeit garbage for sale on Amazon. Fuck that. It's just not worth the trouble. Honestly the world was a lot easier (if a bit slower) when you dealt with businesses in person or via mail. Fraud and identity theft just doesn't scale in meatspace, so it was never a big problem.
For some context, I grew up very much "OMG wire my brain in, let's get this future shit going!" Years of watching that future develop, and some reflection, have almost entirely reversed that sentiment, for me.
For example: are streaming services convenient? Yeah, of course. Am I actually happier with them than I was with the library, rentals, and the occasional purchased movie? Marginally, if at all. (but I have Internet service for the handful of things it actually is highly beneficial for, so, may as well use streaming, too)
Is shopping online convenient? Yes. Am I happier than when I just had way less idea what was available to buy, and there was more friction to indulging every little purchase-whim? I really wonder. This one may not just be marginally better, but net-harmful.
I think you're remembering what it was like pre-internet with rose-colored glasses.
The internet is great.
[EDIT] specifically, I think some of our "satisfaction" from this sort of consumption is itch-scratching generated by the possibility of doing it, in the same way that pre-Internet one rarely felt bothered by not knowing some piece of trivia, if no-one around happened to know either. Now it itches until someone looks it up, because you know you can find out quickly. Now if I'm not watching the best possible thing, for example, it itches, but I don't think it would have before. I think to some extent the level of choice available, aside from famously causing analysis-paralysis ("browsing Netflix" is famously an activity all its own, that may or may not end up in ever actually watching anything) also generates the very desire that it's satiating. I'm not sure I was actually less happy watching the best thing I could find at the video store, versus the best thing I can find on streaming services.
These sorts of things improve my life immeasurably and definitely give me a sense of 'satisfaction' that I would not otherwise have been able to achieve paying someone to fix my car, watching a reality show on TLC, or going to the library and reading a book about ducks for the 50th time.
With online shopping, I think the biggest wins are for anyone not being in the "common" category (be it the 5-95% size, fashion, usefulness etc): if what you generally need is suitably common, you might miss the physical shopping (try-ons/try-outs for wearables/tools are very useful).
This also means that there is more incentive for non-common products to be produced because the market is larger.
Generally the suggested rules are: be at least 12 characters long, check the password against lists of known passwords.
Evernote has a normal Gmail account listed. So maybe this goes hand in hand with having a bad product.
[0] https://chrome.google.com/webstore/detail/cackey/lpimdiknnpi...
Google apps/Gsuite/Google for work (or whatever it’s called now) accounts all work fine.
There’s no requirement to use a gmail.com account.
Source: have published extensions on my own and for my company.
Perhaps it's like YouTube? You cannot buy or use a Youtube Premium subscription with a Google Workspace account. I tried inviting a family member to my Youtube Premium subscription, using her Google Workspace email. It doesn't work, because Youtube doesn't see it as a Gmail account.
All you'd need to actually work would be email, so some MX records on a subdomain. Is it ideal? No. Is it better than all of your users having no way to verify that a Chrome extension is actually you? Infinitely better.
vs. months of emails and meetings for something that more or less achieves the same result
ever wondered why these large companies end up running things on random domains?
this is why
How... how can you tell?
edit: it's actually legit
Links on this site to the extension: https://browserprotection.microsoft.com/learn.html
chmod 444 ~/Library/Application\ Support/Google/Chrome/Default/ExtensionsBack in 2008 Chrome was the breath of fresh air, with absolutely spartan look, total lack of extensions and amazing speed, while IE was the opposite. There was good reason for its initial popularity.
And now, looks like Chrome lived long enough to see itself become a villain...
https://support.google.com/chrome/a/answer/7517624?hl=en
https://chromeenterprise.google/policies/#ExtensionInstallAl...
This, unlike the "chmod 444," solution will let extensions update.
You can also allow safe extensions that aren't currently installed (but may be later) and the user can remove extensions in the Allow list if so desired (although there is a ExtensionInstallForcelist to stop that too).
Check this blog: https://blogs.windows.com/windowsexperience/2021/02/05/simpl...
Similarly, Urlscan.io is pretty useful for scoping out sketchy links like the one in the extension's html: https://urlscan.io/result/d95c1113-a446-4c94-8b1f-dd7d530531...
https://chrome.google.com/webstore/report/mabdjppmcjpjplolig...
EDIT: My guess is they delisted the extension right about as I was submitting, since the extension page loaded, but the report submission failed, and now the extension is also gone. Maybe a cache purge was in there somewhere.
Also I am pretty sure Google has a "karma" number for users (just like reddit) in the backend where they automatically take down if report is from a user with high karma.
See the source: https://crxcavator.io/source/mabdjppmcjpjploliggpbonahnjjlgk...
The malware link: hxxp://przekierowanie2.chrome_augustow.pl/?123-Microsoft525896
https://clients2.google.com/service/update2/crx?response=red...
Where [VERSION] is your chrome version and [ID] is the extensions ID. Hope this helps ;)
https://chrome.google.com/webstore/detail/chrome-extension-s...
If you trust it :)
for those confused about the underscore in the tld
Now, if the store started making less money because of scams...
I understand vetting everything manually would take unreasonable amounts of manpower but maybe you should check that literally the #1 grossing app in you store is not a scam?
As with sooo many of their underfunded departments. Google My Business is the worst, full of bugs and piss poor 3rd world country support staff.
This I simply don't understand. Google Maps would be nothing against their competition if it wasn't for almost every single business being on there. But then the support and UX for actually being a business on Google Maps is absolutely horrific, and I think they simply stopped caring about it. As you say, it's full of bugs and every upgrade to the UX seems to make it worse for us as well. Not sure what's going on in Google's brain, but I'm afraid they have run out of lamp oil.
Outside of some core products, Google software simply accumulates cruft and bugs and, I think, is rarely updated at all. They'd rather release a new product than make an existing one better.
This sounds painfully familiar.
Let's see.. Search these days seems to have given up on SEO blocking, Gmail has given up on any kind of UX improvements, and YouTube has given up on being a decent platform for either creators or viewers.
I think the CRU's of the issue is Search is so big, and despite getting progressively worse, brings in so much money, that eventually people at Google realised it doesn't matter whether their products improve or not. After that, its just path of least resistance.
Thanks, I'm aware of this...
> Whether it sucks is irrelevant as that does not affect the reason why you're there.
No, it is not at all irrelevant. I'm much less likely to use it well and maintain up-to-date information if the UI and UX is so terrible that it makes it easy to make mistakes and hard to find the thing I'm looking for. Not sure why it sucking would be irrelevant, I'm a user of it, of course I don't want it to suck...
> They'd rather release a new product than make an existing one better.
I don't think this is true either. Google updates old products all the time. The updates they do frequently makes the software worse though. The willingness to make things better is there, it's just that their execution of these updates is poor as fuck
I think it’s safe to say Google likes this sort of thing.
Containers are for being able to keep separate identities in the same browser window, but on a per-tab basis.
Profiles are for being able to separate different browser instances, with all their settings, extensions and so on.
While Profiles was used before to do the same thing that Containers now allow you to do, there are things you cannot do with Containers that you'll need to use Profiles for. Having separate extensions for different sessions is one of those things.
Edit: Also IIRC multiple profiles cannot be synced across devices through the same firefox account while it is possible with containers
The same account has published another extension: https://chrome.google.com/webstore/detail/iartbook-digital-p...
[edit] both have now been nuked - about 2 hours since this was posted.
But the fact that the developer was allowed to call themselves "Extensions" is worrying.
That Google allows this is clearly nothing other than gross negligence!
I bet it'd reduce amount of scams significantly
LOL. Agreed
And that's if you're lucky and they arbitrarily don't mandate a phone number and an email address for a corporate account. Oh and the email address can't be the primary corporate domain that owns the account because of course what we need is personal emails to authenticate business accounts.
Lord help you if you were ever an early adopter of an onmicrosoft.com domain. You will remain in purgatory until you wipe your accounts and start again.
Does Google still require a phone number for enabling 2FA?
Do you know if this limitation has since been removed? I know there was work on it, but I don't know how that turned out.
Hoping the other child comment is right and that there's been some improvement in this space.
Run it in a sandbox all you want manually, you'll still have no idea what it's really doing. It could be the safest looking thing ever, that's not really going to tell you much.
As a consumer, business entity verification & savagely-enforced PKI/codesigning does make for a much safer app ecosystem. As a developer and small business owner, Apple is a fucking nightmare to build apps for. I much rather build Android/Windows/Web platform because its so much easier to iterate in our shop.
All of that said, could we at least consider requiring some basic domain verification process around these things so that it is possible in theory to determine who endorsed a specific app or extension? If a gmail account & some "reputation" is all it takes to trickle to the top of the store, I think we are missing several important security controls.
Brand/Company names could easily be flagged as a 'needs review' for example.
Think about the fact that this extension has been up for over 2 weeks but if I upload a YouTube video where somebody says the wrong thing it's down in minutes.
They have armies of highly paid employees and none of them can take care of this?
That is, if Google have a bit for this at all. But I like your sense of humor if you say there is actual human in charge of this.
What I should have said is the Product Manager at Google in charge of the extensions for Chrome is asleep at the wheel.
The form itself doesn't look particularly MS-like, and the grammar is pretty bad.
It sometimes seems like the saving grace to society is that criminals aren't actually all that smart.
"Complete the installation register an account."
"How to register? Create an account and then verify, it is anti spam protection."
I think this would fool me if it wasn't for this thread. The only thing that seems off to me is the lack of information, and hovering over the contact developer shows a gmail address.
I wouldn't have looked at the comments in the reviews as I know what the Microsoft Authenticator does, as I use it constantly on my mobile device. So in this instance, I could have seen myself finding this link, clicking Add to Chrome without much thought.
I can surely see how an average user would fall for this and it's frightening.
You can't, that's the problem.
Are these more common on Chromebooks or some other platform I don't regularly use?
Its all the little things that add up, and I hate that mobile Firefox update disabled Tampermonkey.
Talk about planned regressions. Pardon my French, but fuck Mozilla and their recommended extensions program.
I trust gorhill much more than I trust random ad delivery networks trying to possibly exploit zero-day vulnerabilities.
And the suspicion that Google doesn't do even a cursory examination would put me off of using anything that isn't independently vetted.
I have seen extension updates (updates not releases) get approved much too quickly to be properly vetted on the stores side.
That's not what we're talking about.
You will not be able to get an app onto the App Store using microsofts brand image, logos, pretending to be microsoft to phish data from people.
It will not get through. You've obviously got a very strong informed opinion on the topic, but this is just fact.
It will not get through the checks you're suggesting are 'not really for security'.
[0] https://blogs.windows.com/windowsexperience/2021/02/05/simpl...
Do people like walled gardens just so they have someone to blame when this kind of thing happens? They obviously don't work.
I would have thought they would have a list of names like "Microsoft", "Facebook" etc. that would trigger a more thorough check. In this case it should be clear that they tried to pose as Microsoft, and it is coming from an account that has no association with Microsoft.
Either Google doesn't care, or they aren't able to do any form of sensible checking of stuff uploaded to they various platforms. Well, either that or they don't see it as a massive issue.
Caring removes money from them, at least in add case, so better to shift the bullshit to their "users", who are really the product being sold to advertisers, so who cares. Customer is always right, its just we are not the customer.
(At least for me that popped up a couple of days ago, when I used the real Authenticator app for some MS authorization in my phone.)
> (f)Misrepresentations.—Any person who knowingly materially misrepresents under this section—
> (1)that material or activity is infringing, or
> (2)that material or activity was removed or disabled by mistake or misidentification,
> shall be liable for any damages, including costs and attorneys’ fees, incurred by the alleged infringer, by any copyright owner or copyright owner’s authorized licensee, or by a service provider, who is injured by such misrepresentation, as the result of the service provider relying upon such misrepresentation in removing or disabling access to the material or activity claimed to be infringing, or in replacing the removed material or ceasing to disable access to it.
Now, in this instance we're talking about a fraudulent listing, so I can't imagine there's much civil liability to worry about, but the suggestion that there is "no penalty for false claims" is not true.
And also, DMCA claims are made with a statement that they are accurate "under penalty of perjury". I haven't seen anyone convicted under this, but I wouldn't imagine that MS legal would find this to be an acceptable way to solve the issue.
Edit: well, don't complain about the downvotes, but here I am after a few downvotes thinking "Wow, who are these baby-coddling users who think HN readers are idiots who don't read the headline and just accidentally click 'Add to Chrome'?".