this post was submitted on 14 Mar 2025
460 points (98.7% liked)

Comic Strips

18904 readers
1202 users here now

Comic Strips is a community for those who love comic stories.

The rules are simple:

Web of links

founded 2 years ago
MODERATORS
 

you are viewing a single comment's thread
view the rest of the comments
[–] vaguerant@fedia.io 59 points 5 months ago (8 children)

I can see a system where you have to scan the QR code in a specific app for that purpose (e.g. a dedicated QR code payment app which approved businesses sign up to, which either includes or remotely queries a database of valid endpoints). At that point though, where you're requiring a dedicated app anyway, you may as well invent your own 2D code system with blackjack, hookers and signing. But yeah, I don't understand how this would work otherwise. QR codes just aren't made for security. They shouldn't be used anywhere security is required.

[–] Dave@lemmy.nz 22 points 5 months ago* (last edited 5 months ago) (3 children)

QR codes just aren't made for security. They shouldn't be used anywhere security is required.

I get what you're saying but it's at least a little bit funny that they are regularly used for security in the form of scan to login (e.g. Steam), verify your session (e.g. Matrix), etc. Of course these are in a closed ecosystem so the QR code itself is not the security. But I just found it funny you said that when 90% of my QR code usage is for security.

[–] rockerface@lemm.ee 24 points 5 months ago (1 children)

I mean, generating a one time QR code for login is one thing. It's the equivalent of a one time password. But a permanent QR code is not that. They still aren't inherently secure, but they can be used in situations where showing a code in plain text would be just as secure.

[–] vaguerant@fedia.io 8 points 5 months ago

Yeah, my language was overly broad. You can use QR codes as part of a system where the security is going on elsewhere, but the integrity of the QR code itself isn't something that can be relied on for security.

load more comments (1 replies)
load more comments (5 replies)