5 ms·
QR codes are a massive phishing scam waiting to happen. I'll just go cover up the one at my bank with a sticker of the same exact size that links to my own site
by gerggerg 15y ago
QR codes are a massive phishing scam waiting to happen. I'll just go cover up the one at my bank with a sticker of the same exact size that links to my own site that looks exactly like the bank's site. Or maybe I'll put one on the ATM and see how long I get traffic before someone takes it down.
- rglover 15y agoWow, never considered this but you're right. Scary. I'm glad I don't scan QR codes.
- dchest 15y agoYes, but you can also put a sticker that says "Go to www.bankofamerica-manage-account.com". Although, it's easier to notice, of course.
- burgerbrain 15y agoQR codes present a much lower barrier to entry though. That means they can be acted on before it occurs to the target that they should think about what they're doing.
- ori_b 15y agoThey're also not human readable. I can imagine scanning a QR code and not noticing that the URL is somewhat off. If I was forced to type the URL, I would probably realize that it wasn't entirely legitimate.
- gerggerg 15y agoThough they do pose an interesting avenue for protest/civil disobedience. I could easily post QR codes on fast food restaurants that go to PETA or on the back of bus seats that link to pages about transportation system corruption. Or perhaps what would be even more fun, is I could put download links for movies on their own posters.
- phillmv 15y agoYeah… if only anyone actually used qr codes.
- m_for_monkey 15y agoScanning software should handle this just like browsers the regular phishing sites. This won't eliminate the problem, of course, but it shouldn't be more dangerous then url faking.
- gerggerg 15y ago'cept if people are trained to use them. It's harder to read a url on a mobile device. Plus i can change the url and put up a new sticker. Or just use a bit.ly redirect. And then browsers would have to have a specific link warning instead of just having domain granularity.
- nostromo 15y agoI also think QR codes could eventually be used by "shock site" trolls as in the bad ol' days on Slashdot. It's perfect because there's no way to inspect the URL before visiting the website. I've scanned a few QR codes on street lamps (for music events, etc.) and this is always in the back of my head. Here's a much more fun example of a QR code prank: http://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-ash4/302963_10100624084077408_10715714_59172015_1090246928_n.jpg http://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-ash4/302963_1... (totally SFW of course)
- bri3d 15y agoI do agree that QR codes can be used for trolling, but there's absolutely no reason you can't inspect the URL before visiting a link from a QR code - all that's stored in the QR code, after all, is the URL! The trivial technical solution is a QR code reader which tells you where you're going before it sends you there, which ZXing (the Barcode Reader for Android) and several iOS QR readers already do.
- peterhajas 15y agoShort URLs (very common in the QR code space, for making a smaller code) quickly circumvent this solution. If I see "bit.ly/asdf", I'll assume they just shortened their URL.
- lambda 15y agoAnd this is one of many reasons that URL shorteners must die. If it weren't for Twitter, people wouldn't be so used to blindly clicking through short URLs. But anyhow, most URL shorteners offer an API to retrieve the long URL. You could implement that in your QR code scanner as well, for the most popular URL shorteners, to allow people to see where they will be redirected to.
- babebridou 15y agoAlternatively on Android, you can use FairyPreview to decode most minimized URLs for you before sending them to the browser. https://market.android.com/details?id=com.fairyteller.linkpreview https://market.android.com/details?id=com.fairyteller.linkpr...
- jeffgreco 15y agoThis is a similar concern to the one that people kept raising about short URLs a year or two ago, but they're hardly uncommon now.
- gerggerg 15y ago'cept I don't see any bit.ly links on Bank of America's website but I do see them using QR codes.