4 ms·
I guess an interesting attack would be a screen in a public setting that alters the QR code based on information it has about the current user, without appearin
by Normal_gaussian 2y ago
I guess an interesting attack would be a screen in a public setting that alters the QR code based on information it has about the current user, without appearing to change significantly.
setup:
- make the QR code as a half/half code
- have a system to decide preference of target based on external input (e.g. camera based characteristic evaluation)
- make slight dynamic alterations to the colours of the code to bias the probability of it being picked up as the desired target. Desirable black/white can be made blacker/whiter, less desirable less so.
Where to use it maliciously:
- anywhere where people provide feedback - present alternate feedback forms to different demographics to engender the most positive (or negative) results.
- pretend to offer some form of probabilistic chance to win a prize, but bias winning to some identifiable characteristic. e.g. race, age, "beauty"
- target a specific person - have them join a different WiFi network, alter a payment page, etc.
In a static setting its less effective. I can't immediately think of a static attack that benefits from siphoning some reduced fraction of users.
I'm doubtful most people would notice a QR code dynamically changing, particularly in most public lighting.
- pockmarked19 2y agoYou don’t need any of this if you control the app doing the scanning (or the website/app handling the result).
- Normal_gaussian 2y agoYou wouldn't control the app doing the scanning. The attack is that a user looking at a QR code cannot determine that they are being served a different code to another person. In a public setting a user would have no idea they are even capable of being targetted and treated differently.
- csomar 2y agoStatic Qr-Code but serve different content? If you are targeting by the camera, you can try to link the person to the time the QrCode was scanned and have each QrCode print identified.
- t_mann 2y agoYou don't even need to change the QR code to treat users differently, that's the point. You just send users to some fixed URL, which is by far the most common use for QR codes (hence completely unsuspicious), and you decide who gets served what there, based on whatever data you gathered about them. And the users that would care are already acutely aware that that's how a majority of the web works nowadays, QR codes or not.
- Normal_gaussian 2y agoThe value of an attack vector is not negated by there being other ways to achieve it. This particular vector has the strength of being able to manipulate things other than URLs; QR codes support WiFi credentials, contact details, call, text (with content), email (with content), calendar events. Additionally, many app specific URIs never leave the device. It has the significant downside of being plainly visible as a possibility to those in the know. However, I suspect it may still be desirable to do this on the device rather than the server. The other properties it varies are the obvious lack of reliance on a server. The improved "transparency" of showing the target URL for trust. The removal of the need for an internet connection. But for an implementer I'd imagine the most beneficial upside is not needing to manage a timing-attack, and gaining additional targetting accuracy in the common case of a picture. There may also be organisational complexity reduction in pushing all the decisioning to the display/camera system. Its fun to think about, with the significant weakness in both its visibility and its probabilistic nature I wouldn't expect widespread use.
- alan 2y agoStatic a/b testing?
- Normal_gaussian 2y agoIdentifying this should be relatively easy in the core libraries; finding alternate valid QR codes using "less optimal" grids. Of course the API confusion here becomes non-trivial, which hampers securing against it. And with existing libraries being widespread, its going to linger as an attack for a long time.
- tbrownaw 2y ago> pretend to offer some form of probabilistic chance to win a prize, but bias winning to some identifiable characteristic. e.g. race, age, "beauty" Do a facial recognition lookup against the RealID database (I'm sure someone must be selling a leaked or hacked copy by now) and make the prize depend on the first letter of the person's last name.
- t_mann 2y agoAll of those could be done much more stealthily server-side, though, I don't get what the QR code modification would add here? Also, neither use case makes use of the hack described in the OP. Where I could see an attack based on that hack would be where an attacker plasters their code over a legitimate one. It would be kind of random which code gets read, so they could send some %-age of users to the original destination, hence possibly delaying detection. But it doesn't seem a given that this would compensate for the reduced traffic to their link.
- post-it 2y agoSome sort of MITM attack by someone who owns the display but not the server, maybe. Like a malicious ad company.
- t_mann 2y agoOk, but then I'd still prefer a method that sends users to a unique URL. OP's method may help with obfuscating the changing of the code, but I'm sure there are ways to better achieve that without having to introduce this quasi-randomness. The simplest would probably be to just to regularly hide/show the code (which would happen anyway on a typical digital ad display that cycles through a number of ads).
- post-it 2y agoBut hypothetically, the owner of the ad might pop in and make sure 1. the ad looks correct, and 2. the URL is the one they expect So there may be a use case for a QR code that looks almost identical but goes somewhere else, allowing them to swap it out while someone is looking at it without them realizing. A niche use case, to be sure, but being able to exploit a niche vulnerability is a skill.
- michaelmior 2y agoBut if you own the display, you can send the user to whatever server you want.
- 2y ago
- janniehater 2y ago[dead]
- eieio 2y agoI appreciate you laying out malicious use-cases instead of just having the setup section; I would have struggled to think of those! FWIW the place my brain went was some kind of magic trick, since having control of this could function kind of like a forcing a specific card or something
- nroets 2y agoI guess similarly you can carefully craft a poster with a QR code and put it on a wall in a room with two LED bulbs. The bulbs will have different color temperature and the decoding will be dependent on which bulb is lit. Another idea would be a poster that's not quite flat: Each pixel that is different is slightly raised (pyramid shaped) and the sides of the pyramid is colored differently. So the QR code scans differently from different sides. One of the dominant banks here in Tbilisi allows sharing of IBAN number as QR codes. In theory, the trick could be used to steal money, but in practice, there are many safeguards such as the banking app displaying the name of the beneficiary before completing the process.
- chii 2y ago> banking app displaying the name of the beneficiary and the scammer make an account with a name that look similar at a glance (e.g., swap the l with a 1, or something of the sort).
- fxtentacle 2y agoMost likely, they have <1s bank transfers, too, like pretty much all of Asia. That way, if you pay someone with a QR code, they'll immediately get the notification that they received your payment. And if they don't, you immediately know that something went wrong.
- echoangle 2y agoBut then it’s too late, you have to find out before send the money.
- fxtentacle 2y agoMost scammers will try to avoid situations where you can punch them in the face. => If scams usually get notified before the perpetrator can run away, that will discourage scamming. => In practice, it might be "good enough" if you know immediately after sending money.
- 2y ago
- michaelt 2y agoThere are actually attacks based on changing public QR codes already! They don't need anything as sophisticated as this dual QR code, though - the attackers just go to a car park with a "pay by phone" sign, slap their own QR code over the "scan to pay" code, and wait for the credit card details to start coming in.
- Terr_ 2y agoHmmm, there might be some criminal utility in capturing <100% of visitors, so that the true owner doesn't easily realize that activity for that location has ceased. In other words, giving up a certain number of victims in order to keep the attack going for longer. That said, it'd probably be easier to implement that in software, where the phishing site redirects a certain portion of visits back to the legitimate one. P.S.: There's also the physical stealth aspect, but I think a lenticular design would probably be easier for a human worker to notice, compared to a regular flat sticker which just happens to encode a typo-squatting URL.
- alphan0n 2y agoI almost got taken in by a fake parking ticket scam, perfect ticket/envelope, the url printed on the ticket led to a 404 on the legitimate city website, the QR code led to a very convincing website/url, especially on mobile. The only reason I caught it was that I had gotten a legitimate ticket a month prior for parking too close to the fire hydrant and had marked the curb with chalk at the correct distance. So I tried to dispute the fine and discover that the ticket didn’t actually exist. And the city had no interest in the fake ticket whatsoever. They were just like “yeah, it happens all the time”.
- dr-detroit 2y ago[dead]
- hnlmorg 2y ago> alters the QR code based on information it has about the current user, without appearing to change significantly. I doubt many people would notice if your average QR code was to change significantly. Most machine readable formats are just indistinguishable white noise to most people.