5 ms·
Why do I hear this so often? Isn’t the risk exactly the same as clicking random links on the internet? Do you do a background check before opening an external l
by echoangle 2y ago
Why do I hear this so often? Isn’t the risk exactly the same as clicking random links on the internet? Do you do a background check before opening an external link to a story on hacker news? The risk is exactly the same as when you scan a random QR code.
- TrianguloY 2y agoQrs may have other data, not only links, and there is always the extra (but minimal) risk of a vulnerability in the qr reader itself. Other than that, it's the same as clicking a link on an email, yes.
- pacifika 2y agoYou can hover over a link to see the destination, this isn’t always possible with a qr code as it depends on the client app
- gruez 2y agoHow many people actually hover/long press every link before clicking, especially on sites with UGC that allow for link spoofing (eg. <a href="http://evil.example">http://site.example</a> http://evil.example">http://site.example</a>)? If you're paranoid to do that, you can probably figure out how to audit qr codes before opening them. On iOS it's trivial to make one in Shortcuts. On Android, Firefox confirms the link before opening.
- pacifika 2y agoIf the native tooling always confirmed a qr code then I think you’d be right. Until then it’s security practices not paranoia.
- echoangle 2y agoAnd what does that tell you? How do you detect malware from the URL? Do you have a whitelist of known-good domains and don’t visit anything else?
- pacifika 2y agoThe http protocol uses human readable addresses for a reason.
- echoangle 2y agoYes, to make addresses memorable, not to detect malicious hosts. If I give you a random .com-domain, how do you determine wether it is safe? And do you actually do it if it’s the link of a hacker news post, for example?