A side effect of adtech and surveillance mania infecting everything, URLs in QR codes are likely to be either semirandom strings with tracking IDs, or links to URL shorteners that expand to such semirandom strings with tracking IDs. Either is very trivial to spoof with a similar-looking malicious URL.
Say you're on the bus stop and want to check upcoming buses (real stuff in the place where I live).
The bus company could either slap a QR code, or a "bit.ly/bus-stop-1234" URL. And someone could paste over it a "evil.com/bus-stop-1234".
Hint: use Firefox Focus as your default handler for URLs on mobile phone. It clears all history and cookies after each usage, which is perfect for opening unknown URLs.
That is how HTTPS works today, and does not protect you against phishing at all.
You scan your bust stop and it says "Verified Signed by City, County Bus service" instead of "anonymous asshole".
Not perfect, but it at least gives the users a chance unlike the blind redirect situation we have now.
* a freelance web dev * two design agencies * nobody (plain lets encryot) * a payments middle man company (stylised like "EZ pay") * the council themselves (on the confirmation pages...)
So I would hazard a guess that "Mobile Transportation Services inc." ie a little too sensible to be trustworthy...
(There have been many articles explaining why, here is one: https://www.troyhunt.com/extended-validation-certificates-ar... )
Paste that string into google, and tell me if you get the results you expect. You'll get a lot of Russian. Think people might go for that? There was an attack a while back where bad guys registered "adoḅe.com" and distributed malware. EV doesn't work.
Some assholes operating a digital signing authority get rich; good for you if you're one of them.
Requiring signatures will likely kill those applications.
Similar to how the existence of HTTPS does not kill the ability to transmit data over HTTP and visit sites with no certificate or a non-trusted certificate.
It could be as simple as a pop-up saying, "this QR code is not validated, continue anyway"?
So any time I see a QR code, I hesitate to point a reader app at it because I'm concerned that my phone could get hacked through it.
Your browser, your PDF viewer, your messenger are just more popular, but not fundamentally different from a QR reader application.
If you're so scared, don't browse anything with your mobile device; browsers are exploitable through pages they land on.
On mobile devices, you can't hover the mouse pointer over a link to see where you're going. That's subtantially more dangerous than a URL reader which shows you the URL.
It's the same kind of issue that's possible with any kind of viewer (Adobe Reader, Flash Player, etc)
Once the file or data string is read, it's already game over, and both the QR code and PDF, SWF, etc aren't human-readable.
> An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution.
[0] https://talosintelligence.com/vulnerability_reports/TALOS-20...
And this is not unique to QR codes -- the correct setup string looked like "b=USmtPf6GnLZYDuR9&s=PCheX14pPg==&p=AbCD123465". This already looks like gibberish to most people; if this was replaced with evil string, I am not sure user would realize that.
The former is easily ignorable, while the latter is no worse than typing random link shortener URL you found on paper.
Thanks!