5 ms·
I think this is a bad idea. Now imaging a new channel for all sorts of fake BSODs and out-of-band malicious links in the shown QR codes.
by donlzx 10y ago
I think this is a bad idea. Now imaging a new channel for all sorts of fake BSODs and out-of-band malicious links in the shown QR codes.
- kabdib 10y agoNow your PC malware can infect your mobile device. Wheee! Microsoft is usually pretty good at modeling security threats these days. I'm surprised they did this, it's a bad idea.
- TorKlingberg 10y agoI really don't see what the problem is here.
- wila 10y agoThe idea they are talking about is most like the scenario where malware throws up a fake BSOD with its own QR code. The user then scans the QR code to open a link to the microsoft website with more details about the BSOD. Except the QR code is fake and it opens a page that is targeted to infect your phone/tablet. Now 2 devices are infected. Yay
- Someone1234 10y agoSeems pretty convoluted to the point of absurdity. If your threat model automatically assumes links are directly proportionate to infections then you're already screwed since getting a user to click a link is insanely easy, and if you had a link that would infect mobile devices you'd likely just drop it on a few news aggregators rather than go through this mess. Threat modeling is about evaluating the risks, including how realistic they are. Your risk model is just unrealistic, you're now infecting PCs with malware for the sole purpose of generating a fake BSOD, which in turn creates a link, which in turn infects mobile devices. Why even infect PCs in that scenario? Seems much MUCH easier to trick mobile users into clicking links OR redirecting them (e.g. AD hijacking). If you really wanted to attack mobile devices from an infected PC you'd likely use their direct USB connection, seems like a much more reliable route. Also may accomplish infections not normally possible from a simple link.
- DanBC 10y ago> Seems pretty convoluted to the point of absurdity. I dunno, trojan diallers and phishing seem pretty convoluted to me. Mobile phones are a major target for attack in the UK at the moment.
- Someone1234 10y agoI don't really understand what it is you're getting at. It is convoluted because a PC infection is unnecessary in that scenario. You could skip it and accomplish the same thing.
- kabdib 10y agoPhones contain valuable data, too.
- kabdib 10y agoOh man, you have no idea what the state of security is, or how persistent attackers are. This is definitely not absurd. In fact, I'll bet that attackers are writing code for this right now. I've encountered Bad Guys who happily walk users through enabling Debug mode on their Android devices (requires a bunch of gyrations and scary dialogs). Many users are absolutely clueless about security, and will follow instructions in pursuit of !!Free Stuff!!. It's amazing. Putting a QR code that takes your phone to some unpredictable site on the internet is a really, really bad idea. Even if you think your mobile platform is secure today, there will be zero-day exploits in the future, and malware authors will use this vector.
- dpark 10y agoWhat stops malware from doing this already? If your PC is compromised, what stops it, today, from popping up a message that says, "hey, open this url on your phone to [fix your registry|enter this contest|get free porn|pay our ransom|whatever]"? No new attack vector was created by adding QR codes to BSODs. Most people aren't going to scan the QR code anyway, for the same reason they didn't search for the error codes: they done know what to do with the info. They will restart the machine and eventually call a friend/relative/tech support for help.
- rahilb 10y agoCan't you just create QR code that goes to a site that tells you "Your PC broke, to fix it install this software" or something... Then just rely on less experienced users thinking the faked BSOD is real.
- dTal 10y agoI think it's a great idea, in theory (although Microsoft's use of it here is pointless though, as implemented). QR codes are just machine-readable text. Cryptic codes only accessible visually that are time-consuming and error prone to copy by hand? QR codes were designed for this. Security issues with QR codes, while they exist, should be considered flaws in the QR reader. Doing anything with a QR code by default apart from displaying its content (not the content behind the URL that might be in the QR code, the actual QR code content) should be considered a security risk. And if visiting URLs = ownage for your device, you've got bigger problems. If little bits of plain text are too insecure for us to handle, we may as well give up on the whole web, never mind QR codes.
- dave5104 10y agoOne of the problems, though, is that few, if any people (at least in the US) actually know how to scan QR codes.