Is "SynthPass" on Chrome Web Store Safe to Install?

[email protected] · chrome · v0.2.9

SynthPass is a different kind of password manager: it is a password synthesizer. With SynthPass, there is no "vault" that has to be protected from hackers because your passwords are synthesized on the fly, just as you need them. SynthPass-made passwords are always high strength and comprise letters, numbers, and special characters. Passwords for different websites are guaranteed to be totally different. You never have to change your Master Password. When a website forces you to change its password, simply change the optional serial that is used to synthesize that password. SynthPass will remember the serial, as well as your user ID. Your Master Password will never be stored, and it disappears from memory after five minutes not using it. And, if you absolutely must use a certain password, SynthPass can use that too! It is encrypted for storage and synced with the browser's own files so no third parties need to be involved. Unlike conventional password managers, SynthPass - won't pop up and interrupt your flow; it is activated only when you click its icon on the browser toolbar - won't store anything secret, only user IDs and optional serials, if you allow it - is always available, because it does not have to connect to "the Cloud" - makes only strong passwords - won't ask you for money - won't show ads SynthPass is based on the WiseHash key-stretching algorithm, which evaluates the information entropy of your Master Password and subjects it to a variable number of rounds of SCRYPT key-stretching. The weaker the password, the more stretching. This forces would-be hackers to spend an inordinate amount of computer time testing weak passwords before they can get to yours. SynthPass displays an accurate measurement of your Master Password's entropy to help you come up with a strong one. This is the same algorithm stretching the user password in PassLok Privacy and PassLok for Email, also in this web store. When there is no password to be filled, SynthPass displays a box where you can store securely encrypted notes for that particular website. Good place for extra login instructions, your first pet's name, or whatnot. Like everything else, the notes sync with the browser without a need for extra servers. There's also a button for moving the current page into an isolation cage similar to Incognito Mode, but within the same set of tabs as the regular pages. This is also accessible via the right-click menu. This is a browser extension, and therefore is poorly supported on mobile devices. There is, however, a web app that includes the same password-making engine and runs well on mobile devices. It can be found at: https://synthpass.com/app

Risk Assessment

Analyzed
39.95
out of 100
LOW

97 security findings detected across all analyzers

Chrome extension requesting 6 permissions

Severity Breakdown

0
Critical
29
High
68
Medium
0
Low
0
Info

Finding Categories

29
Malware Signatures
61
IoC Indicators

YARA Rules Matched

6 rules(29 hits)
postinstall file manipulation postinstall network communication postinstall file download postinstall system command postinstall crypto operations postinstall obfuscation

Requested Permissions

6 permissions
history

Read and modify your browsing history

High
activeTab
Medium
storage
Low
scripting
Low
alarms
Low
contextMenus
Low

About This Extension

SynthPass is a different kind of password manager: it is a password synthesizer. With SynthPass, there is no "vault" that has to be protected from hackers because your passwords are synthesized on the fly, just as you need them. SynthPass-made passwords are always high strength and comprise letters, numbers, and special characters. Passwords for different websites are guaranteed to be totally different. You never have to change your Master Password. When a website forces you to change its password, simply change the optional serial that is used to synthesize that password. SynthPass will remember the serial, as well as your user ID. Your Master Password will never be stored, and it disappears from memory after five minutes not using it. And, if you absolutely must use a certain password, SynthPass can use that too! It is encrypted for storage and synced with the browser's own files so no third parties need to be involved. Unlike conventional password managers, SynthPass - won't pop up and interrupt your flow; it is activated only when you click its icon on the browser toolbar - won't store anything secret, only user IDs and optional serials, if you allow it - is always available, because it does not have to connect to "the Cloud" - makes only strong passwords - won't ask you for money - won't show ads SynthPass is based on the WiseHash key-stretching algorithm, which evaluates the information entropy of your Master Password and subjects it to a variable number of rounds of SCRYPT key-stretching. The weaker the password, the more stretching. This forces would-be hackers to spend an inordinate amount of computer time testing weak passwords before they can get to yours. SynthPass displays an accurate measurement of your Master Password's entropy to help you come up with a strong one. This is the same algorithm stretching the user password in PassLok Privacy and PassLok for Email, also in this web store. When there is no password to be filled, SynthPass displays a box where you can store securely encrypted notes for that particular website. Good place for extra login instructions, your first pet's name, or whatnot. Like everything else, the notes sync with the browser without a need for extra servers. There's also a button for moving the current page into an isolation cage similar to Incognito Mode, but within the same set of tabs as the regular pages. This is also accessible via the right-click menu. This is a browser extension, and therefore is poorly supported on mobile devices. There is, however, a web app that includes the same password-making engine and runs well on mobile devices. It can be found at: https://synthpass.com/app

Detailed Findings

29 total

YARA Rule Matches

6 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
28
IP Addresses
2
Domains
34
Strings
61

All Indicators · 61

Domain
detected Domain: result.name

XIOC detected Domain: result.name

extracted_from_files

Domain
detected Domain: addons.mozilla.org

XIOC detected Domain: addons.mozilla.org

extracted_from_files

URL
detected URL: https://github.com/fruiz500/whisehash

XIOC detected URL: https://github.com/fruiz500/whisehash

extracted_from_files

URL
detected URL: http://snippetrepo.com/snippets/bignum-base-conversion,

XIOC detected URL: http://snippetrepo.com/snippets/bignum-base-conversion,

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://chrome.google.com/webstore/detail/ignore-x-frame-headers/gleekbfjekiniecknbkamfmkohkpodhe

XIOC detected URL: https://chrome.google.com/webstore/detail/ignore-x-frame-headers/gleekbfjekiniecknbkamfmkohkpodhe

extracted_from_files

URL
detected URL: https://addons.mozilla.org/en-US/firefox/addon/ignore-x-frame-options-header/

XIOC detected URL: https://addons.mozilla.org/en-US/firefox/addon/ignore-x-frame-options-header/

extracted_from_files

URL
detected URL: http://tweetnacl.cr.yp.to/

XIOC detected URL: http://tweetnacl.cr.yp.to/

extracted_from_files

URL
detected URL: https://github.com/floodyberry/poly1305-donna

XIOC detected URL: https://github.com/floodyberry/poly1305-donna

extracted_from_files

URL
detected URL: https://github.com/dchest/scrypt-async-js

XIOC detected URL: https://github.com/dchest/scrypt-async-js

extracted_from_files

URL
detected URL: https://xato.net/passwords/more-top-worst-passwords,

XIOC detected URL: https://xato.net/passwords/more-top-worst-passwords,

extracted_from_files

URL
detected URL: https://github.com/first20hours/google-10000-english.

XIOC detected URL: https://github.com/first20hours/google-10000-english.

extracted_from_files

URL
detected URL: https://synthpass.com/app

XIOC detected URL: https://synthpass.com/app

extracted_from_files

URL
detected URL: https://synthpass.com

XIOC detected URL: https://synthpass.com

extracted_from_files

URL
detected URL: https://github.com/fruiz500/synthpass

XIOC detected URL: https://github.com/fruiz500/synthpass

extracted_from_files

Domain
detected Domain: qwant.com

XIOC detected Domain: qwant.com

extracted_from_files

URL
detected URL: http://www.w3.org/1999/xhtml

XIOC detected URL: http://www.w3.org/1999/xhtml

extracted_from_files

URL
detected URL: https://github.com/dchest/scrypt-async-js--

XIOC detected URL: https://github.com/dchest/scrypt-async-js--

extracted_from_files

URL
detected URL: https://www.youtube.com/watch?v=RLGScvETOEc

XIOC detected URL: https://www.youtube.com/watch?v=RLGScvETOEc

extracted_from_files

URL
detected URL: https://www.youtube.com/watch?v=96pSh4h1CAU

XIOC detected URL: https://www.youtube.com/watch?v=96pSh4h1CAU

extracted_from_files

URL
detected URL: https://www.youtube.com/watch?v=Y5jwImGkzCc

XIOC detected URL: https://www.youtube.com/watch?v=Y5jwImGkzCc

extracted_from_files

URL
detected URL: https://passlok.com/seeonce

XIOC detected URL: https://passlok.com/seeonce

extracted_from_files

URL
detected URL: https://passlok.com/ursa

XIOC detected URL: https://passlok.com/ursa

extracted_from_files

URL
detected URL: https://passlok.com/stego

XIOC detected URL: https://passlok.com/stego

extracted_from_files

URL
detected URL: https://passlok.com/human

XIOC detected URL: https://passlok.com/human

extracted_from_files

URL
detected URL: https://passlok.com/lockdir

XIOC detected URL: https://passlok.com/lockdir

extracted_from_files

URL
detected URL: https://github.com/fruiz500/wisehash--

XIOC detected URL: https://github.com/fruiz500/wisehash--

extracted_from_files

URL
detected URL: https://github.com/dchest/tweetnacl-js--

XIOC detected URL: https://github.com/dchest/tweetnacl-js--

extracted_from_files

Domain
detected Domain: xato.net

XIOC detected Domain: xato.net

extracted_from_files

Domain
detected Domain: range.select

XIOC detected Domain: range.select

extracted_from_files

IP
detected Domain: snippetrepo.com

XIOC detected Domain: snippetrepo.com

extracted_from_files

Domain
detected Domain: box.select

XIOC detected Domain: box.select

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

URL
detected URL: https://passlok.com/app

XIOC detected URL: https://passlok.com/app

extracted_from_files

URL
detected URL: https://passlok.com/learn

XIOC detected URL: https://passlok.com/learn

extracted_from_files

Domain
detected Domain: wolframalpha.com

XIOC detected Domain: wolframalpha.com

extracted_from_files

Domain
detected Domain: gigablast.com

XIOC detected Domain: gigablast.com

extracted_from_files

Domain
detected Domain: swisscows.ch

XIOC detected Domain: swisscows.ch

extracted_from_files

Domain
detected Domain: metager.de

XIOC detected Domain: metager.de

extracted_from_files

Domain
detected Domain: oscobo.co.uk

XIOC detected Domain: oscobo.co.uk

extracted_from_files

URL
detected Domain: pageurl.click

XIOC detected Domain: pageurl.click

extracted_from_files

Domain
detected Domain: document.location.host

XIOC detected Domain: document.location.host

extracted_from_files

Domain
detected Domain: duckduckgo.com

XIOC detected Domain: duckduckgo.com

extracted_from_files

Domain
detected Domain: search.disconnect.me

XIOC detected Domain: search.disconnect.me

extracted_from_files

Domain
detected Domain: gibiru.com

XIOC detected Domain: gibiru.com

extracted_from_files

Domain
detected Domain: startpage.com

XIOC detected Domain: startpage.com

extracted_from_files

Domain
detected Domain: findx.com

XIOC detected Domain: findx.com

extracted_from_files

Domain
detected Domain: searx.me

XIOC detected Domain: searx.me

extracted_from_files

Domain
detected Domain: tweetnacl.cr.yp.to

XIOC detected Domain: tweetnacl.cr.yp.to

extracted_from_files

Domain
detected Domain: nacl.secretbox.open

XIOC detected Domain: nacl.secretbox.open

extracted_from_files

Domain
detected Domain: nacl.box

XIOC detected Domain: nacl.box

extracted_from_files

Domain
detected Domain: nacl.box.open

XIOC detected Domain: nacl.box.open

extracted_from_files

Domain
detected Domain: nacl.sign.open

XIOC detected Domain: nacl.sign.open

extracted_from_files

Domain
detected Domain: array.prototype.slice.call

XIOC detected Domain: array.prototype.slice.call

extracted_from_files

Domain
detected Domain: activetab.id

XIOC detected Domain: activetab.id

extracted_from_files

Domain
detected Domain: passlok.com

XIOC detected Domain: passlok.com

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Domain
detected Domain: www.youtube.com

XIOC detected Domain: www.youtube.com

extracted_from_files

Domain
detected Domain: synthpass.com

XIOC detected Domain: synthpass.com

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: chrome.google.com

XIOC detected Domain: chrome.google.com

extracted_from_files

Security Analysis Summary

Security Analysis Overview

SynthPass is a Chrome Web Store extension published by [email protected]. Version 0.2.9 has been analyzed by the Risky Plugins security platform, receiving a risk score of 39.95/100 (LOW risk) based on 97 security findings.

Risk Assessment

This extension presents low security risk. Some minor findings were detected, but nothing that would prevent typical usage. Reviewing the detailed findings below is recommended before use in sensitive environments.

Findings Breakdown

  • High: 29 finding(s)
  • Medium: 68 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

SynthPass is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 41 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions