this post was submitted on 25 Feb 2025
36 points (100.0% liked)

Technology

38112 readers
546 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 3 years ago
MODERATORS
top 11 comments
sorted by: hot top controversial new old
[–] [email protected] 7 points 2 days ago (1 children)

How am I supposed to scan a QR code sent to my phone… with my phone?

[–] [email protected] 2 points 2 days ago* (last edited 2 days ago)

On Android you can use Google Lens or, if you don't want to use Google products, any random QR code scanner app.

No idea about iPhone as I've never owned one, but I'd assume most QR code scanners can do that there as well.

[–] [email protected] 22 points 3 days ago (1 children)

The real reason is that they want to save money on the text messages (outside of the US they need to pay $0.05 each time), not because they actually care about user security.

Like when xitter ran out of money and didn't pay their sms bills and people were locked out of their accounts

[–] [email protected] 4 points 2 days ago (1 children)

i mean, it's also a security issue. sms is plaintext all the way from them to you.

[–] [email protected] 3 points 2 days ago

Also, it's dead simple to send someone else (or tell them over the phone) 6 numbers, when you're being phished. Much harder for people to send someone a QR code.

[–] [email protected] 6 points 3 days ago (1 children)

I'm confused about how this is supposed to act as a second authentication factor 🤔

[–] [email protected] 5 points 2 days ago* (last edited 2 days ago) (1 children)

A guess/suggestion:

You have an app with a private key. The qr code contains data encrypted with the corresponding public key. Your app decrypts the data and transmits it to googles servers, proving you are in possession of the secret key.

[–] [email protected] 1 points 2 days ago

oh so it would just be app-based MFA but without using TOTP. That makes sense

[–] [email protected] 11 points 3 days ago* (last edited 3 days ago)

Sadly the article is very light on how this actually works. I'm guessing it involves setting up an authenticator on the phone (something they encourage anyway) and just using a QR code as a new way of interacting with it?

[–] [email protected] 6 points 3 days ago (1 children)

Qrs don't seem safe to me
Scanning a Qr allows the installation of malware apps so I can look at a restaurant menu, & ding my card for recurring charges?

[–] [email protected] 1 points 2 days ago

The devil's in the details. And there aren't much details in this article.