Live data from Hacker News

Show HN: Scan QR codes to check in guests registered via Google Forms

workspace.google.com

41–50 of 68 posts

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#41

Earlier quoted context omitted.

Trust me when I say randos aren’t dropping modern 0days on restaurant menus. Not when a novel attack can fetch millions through brokers.

Not only do I agree with you, but I don’t think anyone would be able to tell an attack was imminent if they were to see the URL anyway. I was just providing facts to the comment above that didn’t seem to think RCE are a thing anymore.

Makes sense, my phrasing was poor I should have made that a more general statement not directed at you necessarily. I think the average techy has through some combination of general news like this and just enough technical know how formed an unrealistic threat model for themselves.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#42
post #31
post #28

Earlier quoted context omitted.

This is true, but also mostly moot, sadly, due to the pervasive use of URL shorteners for QR code services. So instead of seeing a nice hover-over of "SuperDeliciousItalian.com/menu", as often as not it will be "qr.to/f2CrS" or somesuch. So exposing the URL encoded in the QR code doesn't provide all the information you need to assess its validity or safety.

That’s a risk with any and all hyperlinks. There’s nothing unique to QR codes with that.

while that's not exactly unique, it is something specific to QR codes. the longer the URL, the more complex the QR code will be. the more complex, the larger the block will need to be to ensure "scanability". most of the online free QR code generators I've seen have all recommended using a shortner. now, maybe they are trying to do that to collect all of the metrics they can by recommending a service that offer or get kickbacks from the shortening service.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#43
post #7

Earlier quoted context omitted.

Ah indeed ;)

that's pretty good that someone went past your original link and looked at more of what you were doing. looks like the effort pays off!

Indeed; I didn't expect this level of interest, to be honest. The HN demographics didn't seem to match my target market.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#44

Hopefully, the Googster doesn't pull the rug out from under your feet and decide to deprecate whatever product(s) you are using of theirs. It is always something to keep in mind with using anything from G as a central part of your offerings.

Spot on. Fortunately, the underlying platform itself is independent of Google.

The Forms and Sheets add-ons are just customer acquisition channels, just like our Zapier integration [1]. These mostly use our API, and very little of our UI (mostly the scanner).

[1] https://zapier.com/apps/trak-qr-automation/integrations

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#45

Earlier quoted context omitted.

Not only do I agree with you, but I don’t think anyone would be able to tell an attack was imminent if they were to see the URL anyway. I was just providing facts to the comment above that didn’t seem to think RCE are a thing anymore.

Makes sense, my phrasing was poor I should have made that a more general statement not directed at you necessarily. I think the average techy has through some combination of general news like this and just enough technical know how formed an unrealistic threat model for themselves.

> the average techy has through some combination of general news like this and just enough technical know how formed an unrealistic threat model for themselves.

amen :)

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#46
post #31

Earlier quoted context omitted.

That’s a risk with any and all hyperlinks. There’s nothing unique to QR codes with that.

while that's not exactly unique, it is something specific to QR codes. the longer the URL, the more complex the QR code will be. the more complex, the larger the block will need to be to ensure "scanability". most of the online free QR code generators I've seen have all recommended using a shortner. now, maybe they are trying to do that to collect all of the metrics they can by recommending a service that offer or ge…

An attacker is far more likely to hide behind puny code or a misleading subdomain like microsoft.com.orders.com because that adds more legitimacy than a url shortener.

Professional uses of QR in advertisements would use URL shortening on their own domain, eg https://o2.com/trainpromo2 as that way they can demonstrate authenticity as well as owning the telemetry themselves.

Table service in restaurants don’t need to worry about data density because they have their customers literally sat at the table with the QR code in hand (it doesn’t get any easier to scan a code than like that).

If you’re dealing with a restaurant small enough not to have anyone manage the design then you can also bet that restaurant isn’t worth the effort targeting for this kind of attack. Think about what it would entail:

1. Having someone physically visit the restaurant

2. Measure that QR code so that you know the dimensions of the sticky label you want to print

3. Now visit that restaurant dozens more times to replace the existing QR codes. Each time hoping you get a different menu and/or table

4. Pull of this replacement in a short enough time so that people don’t report that their QR code does something different before you’ve captured enough devices (whatever your attack might be).

5. Hope that the owners don’t notice that the QR codes are now stickers (eg they don’t sit flush on the menu)

6. And hope that they don’t refresh their menus regularly. Which might even just happen because someone spilt the QR code / kids have drawn on it accidentally/ etc

7. And all the while, hope that you don’t get caught. Because restaurants will usually have cameras up. You better also not pay for your meal on card too.

It’s such an inefficient yet also high risk and short lived attack that it’s just not all that likely anyone would bother.

I do get the concern about opening up random websites, but rather than singling out QR codes specifically and letting everything else rot, I suggest we look at the root cause of the issues here. And that root cause isn’t QR codes.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#47
post #46

Earlier quoted context omitted.

while that's not exactly unique, it is something specific to QR codes. the longer the URL, the more complex the QR code will be. the more complex, the larger the block will need to be to ensure "scanability". most of the online free QR code generators I've seen have all recommended using a shortner. now, maybe they are trying to do that to collect all of the metrics they can by recommending a service that offer or ge…

An attacker is far more likely to hide behind puny code or a misleading subdomain like microsoft.com.orders.com because that adds more legitimacy than a url shortener. Professional uses of QR in advertisements would use URL shortening on their own domain, eg https://o2.com/trainpromo2 as that way they can demonstrate authenticity as well as owning the telemetry themselves. Table service in restaurants don’t need to w…

you do realize that a QR code "attack" doesn't have to be malicious, yeah? it could be some gorilla PR campaign of something like a local band essentially rick rolling the users. or sending them to the menu of the competing restaurant up the street. or goatse. or or or...

at that point, it could just be someone that printed up a bunch of stickers and plastered them on anything they could find. people love jokes. like unscrewing the salt/pepper shakers before they leave the restaurant type of asshattery. you really just need to get off this white knighting of the QR code and be a little more creative in your thinking of what could go wrong.

at this point, i'm just trying to keep going to make it look like this reply's length is worthy of what ever rabbit hole you went down in some vain attempt at trying to prove a point.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#48

The issue is, at least for me, I consider all QR codes as unsafe. Unfortunately, you don't know where the QR code leads you before you scan it and then it is already too late. So you can't do the equivalent of inspecting the link before you click it. Recently we were in a restaurant which required scanning a QR code to get served (for some reason asian restaurants like doing this). The codes were labels attached to t…

Android 14's camera shows you the URL and doesn't load it right away...

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#49
post #3

Just a reminder to anyone using Google forms that you may exclude non-Google customers. My child’s school uses them and it often the forms ask for a login. Google doesn’t necessarily respect your choice to make a form public.

> exclude non-Google customers.

There are literally dozens of them! /s

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#50
post #49
post #3

Just a reminder to anyone using Google forms that you may exclude non-Google customers. My child’s school uses them and it often the forms ask for a login. Google doesn’t necessarily respect your choice to make a form public.

> exclude non-Google customers. There are literally dozens of them! /s

When you’re running taxpayer funded public services for millions of people that adds up.
Post reply on HN