• ChaoticNeutralCzech@feddit.org
      link
      fedilink
      English
      arrow-up
      18
      ·
      edit-2
      1 month ago

      It’s easier to take precautions though. You probably don’t have an insulated USB port or throwaway host device but handling QR codes safely just takes basic tech and skill.

      Important advice:

      • Don’t use apps that auto-open URLs in QR codes when pointed at!
      • Make sure the app shows the full content of the QR code and lets you peruse it indefinitely before you open the link!
      • Know the structure of URLs and common pitfalls!

      Recommendations:

      • Be extra suspicious if there is no URL printed next to the code, or if the printed URL is different.
      • Use an open source reader app (most QR codes don’t contain secrets but it’s got permission to use either camera!) that does not resolve Punycode (Unicode in TLDs).
      • Strip any tracking parameters you spot before following any URLs.
      • Be careful if the QR code could have been easily tampered with (on a sticker over the original one, or on a plain sheet of paper inserted into a plastic wrap together with the rest)

      I think today’s generation’s equivalent is free Wi-Fi networks. Kids without mobile data in an area without an established public network will connect to just about any open one unless the SSID includes “LaserJet” or similar.

      • krolden@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        2 months ago

        WiFi and cellular networks as well. Using cellular data without some kind of tunneling for traffic/dns is nuts IMO.

      • Zagorath@aussie.zone
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        Strip any tracking parameters you spot before following any URLs.

        If it’s one of these QR codes at a restaurant for ordering, the parameters could possibly be necessary to properly connect your order to your table, depending on how they’re set up.

        • Zagorath@aussie.zone
          link
          fedilink
          arrow-up
          20
          ·
          2 months ago

          I have no idea what the law is in India, but if he got a “hacking” charge for this it would be a gross miscarriage of justice, considering he never once did anything resembling social engineering, brute forcing passwords, any sort of injection attack, or anything else that might actually be involved in hacking.

          However, assuming he never tried to reach out to the company themselves first (and I saw no indication in the article that he had), this is really quite a horrible irresponsible disclosure. It’s pretty obviously a significant leak of sensitive data—both customer and business data—and giving them 90 days to fix it before alerting the public to what you found is pretty basic security ethics.

          • dylanmorgan@slrpnk.net
            link
            fedilink
            arrow-up
            6
            ·
            2 months ago

            I also don’t know the laws in India, but in the US nearly every major “hacking” case for decades has been a miscarriage of justice to some degree or another.

            Like Kevin Mitnick who simply figured out that a major early ISP was keeping customer payment information in plaintext on an internet-connected server.

            • thesmokingman@programming.dev
              link
              fedilink
              arrow-up
              2
              ·
              2 months ago

              That’s a huge misrepresentation of what Mitnick did and how the government mischarged him. He did a bunch of dumb stuff that was illegal. He was overcharged in very bad ways supporting ridiculous lies from the companies he broke into.

  • NegativeInf@lemmy.world
    link
    fedilink
    arrow-up
    25
    arrow-down
    5
    ·
    2 months ago

    Absolute insanity.

    I would have abused this great and terrible power in just the same way he described. Random orders for random tables at random restaurants at random times in small quantities for as long as they aren’t protected. Just enough to be an inconvenience/awkward but not enough to raise alarms.

    And now I will check every QR code I scan at a restaurant.

    • Psychodelic@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      2 months ago

      That seems kinda fucked up. Why would you do something like that?

      I mean, I at least get fucking with people for money. Doing it for fun, not so much

      Also, anyone know what they meant with this line?

      I still loved my life so I didn’t want to use the Google custom search API.

      • NegativeInf@lemmy.world
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        edit-2
        2 months ago

        Because you can or to prove a point.

        As to the quoted text, I assumed it was a reference to not getting more deeply involved in it that would cause legal issues for himself.

  • Bezier@suppo.fi
    link
    fedilink
    arrow-up
    13
    ·
    edit-2
    2 months ago

    The main event here was pretty interesting, but I’d just like to say that

    It asked me for my name and Whatsapp mobile number.

    Why not just the mobile number. Do they also operate drive-ins that only accept BMWs?

    • Mountaineer@aussie.zone
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      2 months ago

      In certain places like India, WhatsApp is the default means of communication for everyone.
      You can use it without phone data if you are on wifi, it supports better quality than sms for sending images, you can video chat with it, it’s cross platform, etc etc.

      What’s more amazing to me is that it’s not more popular in western countries.

  • ElectricMachman@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 months ago

    Brilliant article - but it looks like it’s now been removed. Would be impressive if someone at Dotpe got wind in such a short space of time…

    • poVoq@slrpnk.netOP
      link
      fedilink
      arrow-up
      7
      ·
      2 months ago

      Huh, it was still working when I posted it one hour ago… unlucky I guess 🤷‍♂️

  • EngineerGaming@feddit.nl
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    2 months ago

    It asked for your phone number? That is the thing that angered me the most. I wonder why you would share this rather than ask a waiter and say you don’t have Whatsapp, for example.