this post was submitted on 14 Mar 2025
460 points (98.7% liked)

Comic Strips

18548 readers
1255 users here now

Comic Strips is a community for those who love comic stories.

The rules are simple:

Web of links

founded 2 years ago
MODERATORS
 

you are viewing a single comment's thread
view the rest of the comments
[–] baggins@lemmy.ca 49 points 4 months ago* (last edited 4 months ago) (25 children)

How would you make an arbitrary QR code have a verifiable signature?

[–] vaguerant@fedia.io 59 points 4 months ago (8 children)

I can see a system where you have to scan the QR code in a specific app for that purpose (e.g. a dedicated QR code payment app which approved businesses sign up to, which either includes or remotely queries a database of valid endpoints). At that point though, where you're requiring a dedicated app anyway, you may as well invent your own 2D code system with blackjack, hookers and signing. But yeah, I don't understand how this would work otherwise. QR codes just aren't made for security. They shouldn't be used anywhere security is required.

[–] Dave@lemmy.nz 22 points 4 months ago* (last edited 4 months ago) (3 children)

QR codes just aren't made for security. They shouldn't be used anywhere security is required.

I get what you're saying but it's at least a little bit funny that they are regularly used for security in the form of scan to login (e.g. Steam), verify your session (e.g. Matrix), etc. Of course these are in a closed ecosystem so the QR code itself is not the security. But I just found it funny you said that when 90% of my QR code usage is for security.

[–] Fiery@lemmy.dbzer0.com 7 points 4 months ago

I mean it's more like it's used to transfer small amounts of data over a visual medium in those cases. Basically just a shortcut over having to type a whole string of characters manually.

load more comments (2 replies)
load more comments (6 replies)
load more comments (22 replies)