339
No Scan Do (i.kinja-img.com)
submitted 10 months ago by tree@lemmy.zip to c/theonion@midwest.social
you are viewing a single comment's thread
view the rest of the comments
[-] gila@lemm.ee 7 points 10 months ago

So we shouldn't use smartphone features if they could potentially have exploits? With this logic you shouldn't have a phone.

[-] hemko@lemmy.dbzer0.com 1 points 10 months ago* (last edited 10 months ago)

We shouldn't replace perfectly good solutions with unreliable, cumbersome, insecure, annoying shitty tech just because.

[-] lolcatnip@reddthat.com 2 points 10 months ago

Thinking that simply visiting a web site for a business you've already decided to patronize is dangerous is some serious boomer logic.

[-] hemko@lemmy.dbzer0.com 1 points 10 months ago

If we only focus on the security part, how the do you know it's even their site you're visiting? Often those qr codes are just stickers on table, trivial to slap a new one there

But it also adds a lot of annoyance for customers who came to eat food, not doomscroll on their fucking mobile phone

[-] gila@lemm.ee 1 points 10 months ago* (last edited 10 months ago)

My whole point is that the perfectly good extant solutions are equally flawed. QR codes don't create a situation where e.g mimicing a website is easier. It is already easy. It is not any more difficult to mimic a website with a fake domain name purposefully named in plaintext in a way to deceive.

Literally the only difference is you are looking at letters, which you are confident in your ability to parse, with a code which you are not. A URL being short and easy to type doesn't make it less likely to be malicious.

The key thing to remember is that yours, my, everyone's assessment of perceived risk is very incomplete. Your specific comfort with plaintext is itself a potential attack vector. So an approach to privacy/security where you simply avoid all possible circumstances with any perceived risk attached to them is a shitty approach. Engaging with an acceptable risk level is the only way to teach yourself vigilance.

People recently started seeing QR codes everywhere and feel confronted by this new reality, that's natural. But the truth is that this is fear of QR codes is irrational where it is not reconciled with the perceived risk of generally using the internet and following links. There might be a difference in the physical characteristics of the link format, but in terms of computer security the difference doesn't matter.

Just because some commenters here remember seeing a CVE in 2016, or read about QRgen one time, doesn't mean QR code protocol is inherently vulnerable. It is in fact quite ridiculous to suggest that would be the case and all the manufacturers would continue to support it.

[-] Baines@lemmy.world 1 points 10 months ago

no but QR is a shit bug/exploit riddled mess of a format

this post was submitted on 17 Jan 2024
339 points (92.7% liked)

The Onion

4565 readers
940 users here now

The Onion

A place to share and discuss stories from The Onion, Clickhole, and other satire.

Great Satire Writing:

founded 2 years ago
MODERATORS