this post was submitted on 14 Mar 2025
460 points (98.7% liked)

Comic Strips

18855 readers
1094 users here now

Comic Strips is a community for those who love comic stories.

The rules are simple:

Web of links

founded 2 years ago
MODERATORS
 

you are viewing a single comment's thread
view the rest of the comments
[–] baggins@lemmy.ca 49 points 5 months ago* (last edited 5 months ago) (25 children)

How would you make an arbitrary QR code have a verifiable signature?

[–] vaguerant@fedia.io 59 points 5 months ago (8 children)

I can see a system where you have to scan the QR code in a specific app for that purpose (e.g. a dedicated QR code payment app which approved businesses sign up to, which either includes or remotely queries a database of valid endpoints). At that point though, where you're requiring a dedicated app anyway, you may as well invent your own 2D code system with blackjack, hookers and signing. But yeah, I don't understand how this would work otherwise. QR codes just aren't made for security. They shouldn't be used anywhere security is required.

[–] mmddmm@lemm.ee 3 points 5 months ago (1 children)

Well, by using a QR code you don't have to invent your own 2D system, as blackjack and hookers aren't really necessary.

Just make your own URI protocol, and encode any signature in the link. Bonus if you can register your protocol in Android or IOS, but I don't know if this is possible.

[–] Natanael 2 points 5 months ago

Apps an indeed register URL schemes with their domain or chosen protocols to open by default on Android.

load more comments (6 replies)
load more comments (22 replies)