4 ms·
Because urls have letters & words in english that I can read and determine if the website is authentic or not as opposed to QR code that no human can read? Hav
by ryder9 7y ago
Because urls have letters & words in english that I can read and determine if the website is authentic or not as opposed to QR code that no human can read?
Have you never come across phishing scams that looked eerily authentic only to be clued in by the fake url? I can read the URL before going to the website, and unless QR codes have a step where you have to manually confirm going to the url provided by the code (most don't) then that's a security risk
- BiteCode_dev 7y agoQr code readers show you the url, you have push a button to navigate to it. So it's no different than having it copied manually. Not that it matters much for most users, as I said earlier, they blindly type url. They have no idea what it is. You could put a warning saying "are you sure, this is going to kill your mother and steal all your money" and people would click on it if it's easy to do.
- tialaramex 7y agoMicrosoft did that research. Well, they didn't propose to kill anybody's mother but the test participants used their real bank credentials and Microsoft tested different behaviours in IE to see what would deter users from giving these credentials to a bogus site having accepted a task to log in and perform some basic operation. Nothing. Nothing deterred the users. Warning dialogs were clicked past, obvious problems or mismatched information was ignored. The only way to stop users from giving their credentials to bad guys was what I call Brick Wall UX. The browser has to stubbornly refuse to let you do it. Unable to complete their task the user at last gives up. This is a teachable moment. Your users are probably not going to be smarter, better informed or more cautious at least on average than in this test.
- Arbalest 7y agoThis sounds like something which should be continuously tested, as a litmus test as to how careful people are. I don't suppose you have a link or pointed search terms for this instance?
- reaperducer 7y agoBecause urls have letters & words in english that I can read and determine if the website is authentic You must have some super-human ability to read a computer's mind if you can grok the kind of urls that usually come in emails like https://tinyurl.com/uvc58uq https://tinyurl.com/uvc58uq
- hunter2_ 7y agoYou can see what the tinyurl redirect destination URL is (value of Location response header) without also requesting that URL. Not with a typical browser configuration, but with curl or some hosted solution delivering this functionality. Of course, if the email actually has a unique URL per recipient, then doing this gives away the fact that you interacted with the email.
- deleted 7y ago[deleted]