@darius they can use some CSRF and stuff like that if other apps or websites have vulnerabilities... but that's the only security issue i can think about at the moment
Conversation
Notices
-
Ekaitz Zárraga 👹 (ekaitz_zarraga@mastodon.social)'s status on Monday, 14-Feb-2022 20:34:02 CET Ekaitz Zárraga 👹
-
Darius Kazemi (darius@friend.camp)'s status on Monday, 14-Feb-2022 20:34:03 CET Darius Kazemi
People on infosec Twitter keep saying it's extremely bad that lots of people scanned a random QR code. But I'm genuinely not sure how it's different than clicking on a link? My understanding is the flow for most users goes:
- take picture with phone
- see url preview
- click urlIs the issue that the preview step doesn't exist for a lot of people? Otherwise it seems similar to being presented with any url at all.
-