8 ms·
I like the functionality of QR codes, but the fact that they're not human readeable makes them unsafe. It would'nt be unthinkable to make a QR-code, paste it ov
by dirktheman 7y ago
I like the functionality of QR codes, but the fact that they're not human readeable makes them unsafe. It would'nt be unthinkable to make a QR-code, paste it over an existing one (for instance: the QR code in the bar to pay for a tip) and redirect the user to a spoof website where they can tip me instead of the bar/musician.
- wccrawford 7y agoMy QR reader on Android (ZXing's Barcode Reader) shows you the information on the screen before you decide what you want to do with it. That's as "Human Readable" as it needs to be, for me.
- TeMPOraL 7y agoIt's only helpful if you know what to expect. A side effect of adtech and surveillance mania infecting everything, URLs in QR codes are likely to be either semirandom strings with tracking IDs, or links to URL shorteners that expand to such semirandom strings with tracking IDs. Either is very trivial to spoof with a similar-looking malicious URL.
- jakub_g 7y agoIt's the same with or without the QR code. Say you're on the bus stop and want to check upcoming buses (real stuff in the place where I live). The bus company could either slap a QR code, or a "bit.ly/bus-stop-1234" URL. And someone could paste over it a "evil.com/bus-stop-1234". Hint: use Firefox Focus as your default handler for URLs on mobile phone. It clears all history and cookies after each usage, which is perfect for opening unknown URLs.
- jschwartzi 7y agoI'm looking forward to 20 years from now when all QR codes have to be digitally signed to be valid, and the digital signature must be authorized by a certificate authority in your phone.
- zulln 7y agoAnd what would the benefit be from that? That is how HTTPS works today, and does not protect you against phishing at all.
- jandrese 7y agoMaybe if the QR reader gave you the CN and domain of the certificate so you at least knew who signed it. You scan your bust stop and it says "Verified Signed by City, County Bus service" instead of "anonymous asshole". Not perfect, but it at least gives the users a chance unlike the blind redirect situation we have now.
- dwiel 7y agoSigned by "Mobile Transportation Services inc."
- Normal_gaussian 7y agoHaving just navigated through a bunch of forms on my councils website I can verify that the following people are all on certificates at different points: * a freelance web dev * two design agencies * nobody (plain lets encryot) * a payments middle man company (stylised like "EZ pay") * the council themselves (on the confirmation pages...) So I would hazard a guess that "Mobile Transportation Services inc." ie a little too sensible to be trustworthy...
- oxygenoxy 7y agoThen you'll get "Verified Signed by Citÿ, County Bus service"
- theamk 7y agoThis sounds just like EV certificates, and they have not been shown to work very well. (There have been many articles explaining why, here is one: https://www.troyhunt.com/extended-validation-certificates-are-dead/ https://www.troyhunt.com/extended-validation-certificates-ar... )
- pmoriarty 7y agoI've also heard of QR-reader software being exploitable through QR codes that they're supposed to read. So any time I see a QR code, I hesitate to point a reader app at it because I'm concerned that my phone could get hacked through it.
- jandrese 7y agoIt would be really hard for a QR app to take over your phone, even if it is poorly written and gets owned. There are layers of protection below the aps on an OS like iOS. I'm not saying it's absolutely impossible, but if someone figured it out they could sell the technique for literally millions of dollars to a huge assortment of potential buyers. They probably aren't going to waste it on you.
- pmoriarty 7y agoMy phone is a rooted Android phone, though.
- somehnguy 7y agoYou already gave up your security then sooo
- Dylan16807 7y agoThen don't give the QR app root.
- 0b0001 7y agoThat's the case for any software that accepts any kind of input. Your browser, your PDF viewer, your messenger are just more popular, but not fundamentally different from a QR reader application.
- kazinator 7y agoYears ago, WinAmp on Windows was exploitable through a maliciously prepared .m3u playlist: a simple plain text file expected to be filled with pathnames of songs, one per line. If you're so scared, don't browse anything with your mobile device; browsers are exploitable through pages they land on.
- kazinator 7y agoI don't see how it can be made less dangerous. The QR code is read and decoded to a URL. The QR code is now gone, and it is the URL that is dangrous. The URL is dangerous no matter how you got it. On mobile devices, you can't hover the mouse pointer over a link to see where you're going. That's subtantially more dangerous than a URL reader which shows you the URL.
- Jemm 7y agoI think the app is Barcode Scanner, Not Barcode Reader.
- wccrawford 7y agoYou're right. The dumbest part is that I actually went to my phone to find the company name and still thought it said "Reader" for the app name. Thanks!
- m-p-3 7y agoImagine if someone discovers a flaw in the qrcode library and manage to execute an arbitrary command once read? It's already too late, the device already read the code. It's the same kind of issue that's possible with any kind of viewer (Adobe Reader, Flash Player, etc) Once the file or data string is read, it's already game over, and both the QR code and PDF, SWF, etc aren't human-readable.
- Groxx 7y agosure, but visiting any website or launching any app has those vulnerabilities too, except they're many times more complicated. even if it's a legit site, they could have been hacked, best to just not touch external data ever if that's your threat model.
- shakna 7y agoThis has actually happened before. [0] > An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. [0] https://talosintelligence.com/vulnerability_reports/TALOS-2018-0571 https://talosintelligence.com/vulnerability_reports/TALOS-20...
- theamk 7y agoNote that it was not in the QR scanner itself -- the parsing part was fine, the image was always decoded safely. It is the network setup script which parsed the extracted text which was vulnerable. And this is not unique to QR codes -- the correct setup string looked like "b=USmtPf6GnLZYDuR9&s=PCheX14pPg==&p=AbCD123465". This already looks like gibberish to most people; if this was replaced with evil string, I am not sure user would realize that.
- theamk 7y agoUh, no? At least in mobile OS's, the applications are isolated very strongly. And QR reader app is likely to have minimal permissions, and does not declare "backgroup daemon" one -- so even if app is entirely taken over, the worst it can do is to show scary messages and redirect you to nasty URL. The former is easily ignorable, while the latter is no worse than typing random link shortener URL you found on paper.
- tobr 7y agoI agree that QR codes are a bad idea because they’re not human readable. But wouldn’t that particular hack be possible with a URL as well? It might be detected faster I suppose.
- dirktheman 7y agoSure, but not many people would knowingly and willingly enter a long URL in their browser. The ease of use and simplicity of QR codes (just point your camera!) is what makes them a potential risk, IMHO.
- jobigoud 7y agoWe most certainly have the computer vision tech to detect URLs from images of the camera stream. That could be an extra feature of QR code readers app if it's not already.
- shpx 7y agoIf you have a Pixel phone, open the camera, scroll right to More, open Lens and point your phone at a (human readable) URL. https://en.wikipedia.org/wiki/Google_Lens https://en.wikipedia.org/wiki/Google_Lens
- tobr 7y agoThen we have very different ideas of why QR codes are bad. I think they’re bad because they waste space with something that is completely useless to human senses. They should be replaced with good OCR, not with manual typing. Teach machines to make use of human language instead of teaching humans to make use of machine language.
- papln 7y ago99.9% of the information in your computing life is not human readable; it's encoded in radio waves and electrical pulses that your senses can't interpret.
- snarf21 7y agoIsn't this easily solvable by the URL based codes have to have a signature and other verification that the browser can enforce? So instead of a link to paypal to pay me, it is a link to the bar's website and that site has a paypal popup originated from the bar's website.
- jensv 7y agoCheck out HR codes, an alternative to QR codes which encode all valid URL characters to images. https://github.com/hantuzun/hr-code https://github.com/hantuzun/hr-code Human Response Codes are designed to be recognized by humans and OCR.
- sniperjzp 7y agoGreat idea, thanks for sharing this! But how could we prove what's behind the image is exactly what is shown? Could someone still hack it, pretend to be a normal link but actually is a phishing link?
- jagged-chisel 7y agoHow can you know the URL doesn't redirect to something malicious?
- ouid 7y agoyou can also use cash.
- theamk 7y agoThe big downside of this is lack of redundancy. QR codes are incredibly redundant. check out images 6 ("lose an edge") and 10 ("blob of paint") in the page: http://datagenetics.com/blog/november12013/index.html http://datagenetics.com/blog/november12013/index.html Both of these scan perfectly fine with QR. And in HR, those (and most of other damaged examples) would be unreadable.
- Kalium 7y agoI've seen this done in the wild. It's possible to defeat, but only if users are vigilant. Which not all are.
- kevinlou 7y agoThis unfortunately happens a lot in Asia - not sure what the best solution would be.
- tzs 7y agoIf that became widespread, I could see places that display QR codes like the bar in your example take steps to make the QR codes physically inaccessible. For example, they could put the QR code behind glass, and have a sign telling people to only scan the code if they can see it behind the glass. Someone could still paste a QR code of their own outside the glass, but it would be pretty obvious. Or instead of printing them on paper, they could have a small LCD screen dedicated to displaying the code. This could be designed to make it obvious if someone tries pasting a code over the screen. For instance, the screen could be a bit bigger than the QR code, which could move around the screen, like the bouncing ball or logo in many screen savers.
- sfifs 7y agoIf it's sticker based QR normally you just show your screen to the person behind the counter before you pay to verify recipient and amount. Many payment QRs are actually dynamically generally on a POS machine LCD so you get amount and recipient on your device - so that fake sticker problem doesn't exist in these cases
- theamk 7y agoI don't think making codes human-readable would help -- human-readable URLs are spoofable too. For example, if you replace "tipme.com/some_bar" with "tipme.cz/some_bar", most people would have no idea the latter is the wrong URL; and even waiters/cleaners may not notice the change
- samstave 7y agoYou can add the "human readable tag" as 'VISIBLE' underneath any QR code you create in Bartender. (the only caveat is if the item the QR points to is a really long string it becomes unwieldy.. hang on lemme give you some examples -- I.. make a QR that points here. https://i.imgur.com/uv09CuL.png https://i.imgur.com/uv09CuL.png and without the tag https://i.imgur.com/tOwHANb.png https://i.imgur.com/tOwHANb.png Takes two seconds
- kazinator 7y agoWell, the fact that they are not human readable and that some badly designed software takes dangerous actions with them without confirming with the user makes them unsafe. They are readable when decoded; a lot of them just contain URL's. There is a bit of an analogy here to shortened URL's.