A side effect of adtech and surveillance mania infecting everything, URLs in QR codes are likely to be either semirandom strings with tracking IDs, or links to URL shorteners that expand to such semirandom strings with tracking IDs. Either is very trivial to spoof with a similar-looking malicious URL.
Say you're on the bus stop and want to check upcoming buses (real stuff in the place where I live).
The bus company could either slap a QR code, or a "bit.ly/bus-stop-1234" URL. And someone could paste over it a "evil.com/bus-stop-1234".
Hint: use Firefox Focus as your default handler for URLs on mobile phone. It clears all history and cookies after each usage, which is perfect for opening unknown URLs.
That is how HTTPS works today, and does not protect you against phishing at all.
You scan your bust stop and it says "Verified Signed by City, County Bus service" instead of "anonymous asshole".
Not perfect, but it at least gives the users a chance unlike the blind redirect situation we have now.
* a freelance web dev * two design agencies * nobody (plain lets encryot) * a payments middle man company (stylised like "EZ pay") * the council themselves (on the confirmation pages...)
So I would hazard a guess that "Mobile Transportation Services inc." ie a little too sensible to be trustworthy...
(There have been many articles explaining why, here is one: https://www.troyhunt.com/extended-validation-certificates-ar... )
Paste that string into google, and tell me if you get the results you expect. You'll get a lot of Russian. Think people might go for that? There was an attack a while back where bad guys registered "adoḅe.com" and distributed malware. EV doesn't work.
Some assholes operating a digital signing authority get rich; good for you if you're one of them.
Requiring signatures will likely kill those applications.
Similar to how the existence of HTTPS does not kill the ability to transmit data over HTTP and visit sites with no certificate or a non-trusted certificate.
It could be as simple as a pop-up saying, "this QR code is not validated, continue anyway"?
So any time I see a QR code, I hesitate to point a reader app at it because I'm concerned that my phone could get hacked through it.
Your browser, your PDF viewer, your messenger are just more popular, but not fundamentally different from a QR reader application.
If you're so scared, don't browse anything with your mobile device; browsers are exploitable through pages they land on.
On mobile devices, you can't hover the mouse pointer over a link to see where you're going. That's subtantially more dangerous than a URL reader which shows you the URL.
Thanks!
It's the same kind of issue that's possible with any kind of viewer (Adobe Reader, Flash Player, etc)
Once the file or data string is read, it's already game over, and both the QR code and PDF, SWF, etc aren't human-readable.
> An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution.
[0] https://talosintelligence.com/vulnerability_reports/TALOS-20...
And this is not unique to QR codes -- the correct setup string looked like "b=USmtPf6GnLZYDuR9&s=PCheX14pPg==&p=AbCD123465". This already looks like gibberish to most people; if this was replaced with evil string, I am not sure user would realize that.
The former is easily ignorable, while the latter is no worse than typing random link shortener URL you found on paper.
For example, they could put the QR code behind glass, and have a sign telling people to only scan the code if they can see it behind the glass. Someone could still paste a QR code of their own outside the glass, but it would be pretty obvious.
Or instead of printing them on paper, they could have a small LCD screen dedicated to displaying the code. This could be designed to make it obvious if someone tries pasting a code over the screen. For instance, the screen could be a bit bigger than the QR code, which could move around the screen, like the bouncing ball or logo in many screen savers.
Teach machines to make use of human language instead of teaching humans to make use of machine language.
Both of these scan perfectly fine with QR. And in HR, those (and most of other damaged examples) would be unreadable.
Many payment QRs are actually dynamically generally on a POS machine LCD so you get amount and recipient on your device - so that fake sticker problem doesn't exist in these cases
For example, if you replace "tipme.com/some_bar" with "tipme.cz/some_bar", most people would have no idea the latter is the wrong URL; and even waiters/cleaners may not notice the change
They are readable when decoded; a lot of them just contain URL's.
There is a bit of an analogy here to shortened URL's.
https://i.imgur.com/uv09CuL.png
and without the tag
https://i.imgur.com/tOwHANb.png
Takes two seconds