this post was submitted on 12 Dec 2023
157 points (100.0% liked)

Technology

58011 readers
2887 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
top 16 comments
sorted by: hot top controversial new old
[–] [email protected] 32 points 9 months ago (1 children)

So the issue isn't QR codes, but people being unable to recognize scammers additions to public infrastructure and the websites being scams. Basically, it's the same principle as scammers sticking an additional device on top of cash machines.

No news here.

[–] [email protected] 27 points 9 months ago (1 children)

Okay, but explain to me how you're supposed to tell the difference between a legitimate QR code and a fake one?

It's trivially easy to make a mockup of a restaurant's QR menu so that people scan it when they sit down, expecting to get an online menu.

[–] [email protected] 7 points 9 months ago (2 children)

Is the QR Code applied professionally to the surface, possibly behind some security feature such as glass or another surface finish? Is the menu on the table in the general style of the restaurant, or does it look off or entirely different? Is the QR code applied on top of something else, possible another QR code?

Don't use apps which directly open QR codes. Any sensible app will tell what the information is before processing it.

And at last, the simplest and most efficient security measure of all: Commonsense. Don't scan everything you come across. Restaurant menu? Sure. Some random poster out in the woods promising a quick buck, happy time or their like? Hard pass.

[–] [email protected] 16 points 9 months ago

Part of the problem with security is they even when it's legitimate, it acts like the scammers.

I've seen restaurants where their (legitimate) QR code is clearly printed on a home printer and used in lieu of physical menus in order to save money. If the link changes, they will simply tape the new one on top of the old, even on the most official copy you can find.

[–] [email protected] 8 points 9 months ago (1 children)

Given that how restaurants present these various greatly, it wouldn't be terribly unexpected for the official QR to be a sticker on the menu or table either

[–] [email protected] 2 points 9 months ago

I've been at restaurants where that's exactly the case. The QR is just a sticker on the table. Or a laminated card with the code on it.

Would be trivially easy to replace it with a malicious site.

[–] [email protected] 6 points 9 months ago

This is the best summary I could come up with:


The US Federal Trade Commission has become the latest organization to warn against the growing use of QR codes in scams that attempt to take control of smartphones, make fraudulent charges, or obtain personal information.

The code opens a page on a browser or app of the phone, where the account password is already stored.

Two-factor authentication apps provide a similar flow using QR codes when enrolling a new account.

For more than two years now, parking lot kiosks that allow people to make payments through their phones have been a favorite target.

The scam QR codes lead to look-alike sites that funnel funds to fraudulent accounts rather than the ones controlled by the parking garage.

“A scammer’s QR code could take you to a spoofed site that looks real but isn’t,” the advisory stated.


The original article contains 389 words, the summary contains 135 words. Saved 65%. I'm a bot and I'm open source!

[–] [email protected] 5 points 9 months ago (2 children)

An unreadable box us a lot harder the read than scamMyAss.ru

[–] [email protected] 11 points 9 months ago* (last edited 9 months ago) (2 children)

QR is just image to text, most QR reading apps I have used, show you the QR content before going to the website (or let you disable opening the link directly) so you should be able to check the URL or content and see if the link is legit or not.

But let's be honest most people don't know or don't even bother and that's the real problem.

[–] [email protected] 6 points 9 months ago (2 children)

It's also pretty easy to disguise the malicious part. For instance, hxxp://[email protected]

(Hoping that didn't get blocked as spam)

On many apps, that would truncate somewhere around the .com

[–] [email protected] 3 points 9 months ago

Or just legitbusiness-online-order[.]com

[–] [email protected] 2 points 9 months ago

Thankfully a lot of browsers already detect and block this behavior

[–] [email protected] 2 points 9 months ago

But let’s be honest most people don’t know or don’t even bother and that’s the real problem.

100% they see the code and assume it can't be mean.

[–] [email protected] 8 points 9 months ago (1 children)

I clicked your link and provided my banking details. When do I get my PS5?

[–] [email protected] 4 points 9 months ago

Right away, but it shipped to my house.

[–] [email protected] 1 points 1 month ago

I agree, people don't really pay attention or bother to read about stuff like How to check if a QR code is safe. Honestly, I've been dealing with QR codes for quite a while, and I still occasionally spend time looking things up, reading about quishing, and whatever new scam/term appears.