Live data from Hacker News

Show HN: Scan QR codes to check in guests registered via Google Forms

workspace.google.com

51–60 of 68 posts

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#52
post #28

Earlier quoted context omitted.

> Unfortunately, you don't know where the QR code leads you before you scan it and then it is already too late. iOS shows the domain if it is a URL and you have to tap it. It's no different from tapping on a link on a website, which I would say is more insecure since you don't even get the domain info before tapping.

This is true, but also mostly moot, sadly, due to the pervasive use of URL shorteners for QR code services. So instead of seeing a nice hover-over of "SuperDeliciousItalian.com/menu", as often as not it will be "qr.to/f2CrS" or somesuch. So exposing the URL encoded in the QR code doesn't provide all the information you need to assess its validity or safety.

Many URL shortening services actually do offer a way of inspecting the URL before loading it. And the issue of URL shorteners is in no way specific to QR Codes (they originated on Twitter, where they are still most commonly used by my observation, even though the reason for doing so has gone away). QR Codes are usually used to point to content on your own domain, so you can control the URL, hence very little reason to use shorteners, which would likely cost you a few visitors.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#53
post #37

What's cool also is that this is from the West African tech scene.

Is there actually an international West Africa tech scene? Or is it nation by nation?

Mostly nation by nation, but key hubs like Nigeria/Ghana (English) and Senegal/Ivory Coast (French) draw other countries in, due to the presence of a larger pool of investors.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#54
post #46

Earlier quoted context omitted.

An attacker is far more likely to hide behind puny code or a misleading subdomain like microsoft.com.orders.com because that adds more legitimacy than a url shortener. Professional uses of QR in advertisements would use URL shortening on their own domain, eg https://o2.com/trainpromo2 as that way they can demonstrate authenticity as well as owning the telemetry themselves. Table service in restaurants don’t need to w…

you do realize that a QR code "attack" doesn't have to be malicious, yeah? it could be some gorilla PR campaign of something like a local band essentially rick rolling the users. or sending them to the menu of the competing restaurant up the street. or goatse. or or or... at that point, it could just be someone that printed up a bunch of stickers and plastered them on anything they could find. people love jokes. like…

> you do realize that a QR code "attack" doesn't have to be malicious, yeah? it could be some gorilla PR campaign of something like a local band essentially rick rolling the users. or sending them to the menu of the competing restaurant up the street. or goatse. or or or...

They can do that already just by placing their logo, or whatever, instead of a QR code.

Plus whether it is malicious or not, it’s still hugely inefficient given all the other points I raised.

> at that point, it could just be someone that printed up a bunch of stickers and plastered them on anything they could find. people love jokes.

Again, nothing about this needs to be a QR code

> like unscrewing the salt/pepper shakers before they leave the restaurant type of asshattery.

And yet nobody suggests you shouldn’t use salt and pepper shakers at a restaurant. So why are QR codes suddenly “dangerous” if they’re at the same level of “asshattery”?

> at this point, i'm just trying to keep going to make it look like this reply's length is worthy of what ever rabbit hole you went down in some vain attempt at trying to prove a point.

I was giving you a breakdown as to why people don’t do the kind of QR attacks / jokes that you seem to assume are common place rather than just saying “nice theory but that doesn’t happen in the real world”. There’s no need for you to be snarky.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#55
post #54

Earlier quoted context omitted.

you do realize that a QR code "attack" doesn't have to be malicious, yeah? it could be some gorilla PR campaign of something like a local band essentially rick rolling the users. or sending them to the menu of the competing restaurant up the street. or goatse. or or or... at that point, it could just be someone that printed up a bunch of stickers and plastered them on anything they could find. people love jokes. like…

> you do realize that a QR code "attack" doesn't have to be malicious, yeah? it could be some gorilla PR campaign of something like a local band essentially rick rolling the users. or sending them to the menu of the competing restaurant up the street. or goatse. or or or... They can do that already just by placing their logo, or whatever, instead of a QR code. Plus whether it is malicious or not, it’s still hugely in…

> They can do that already just by placing their logo, or whatever, instead of a QR code

What in the world are you on about? Just slapping a logo on top of a QR code suggests to me you’ve lost the plot. The point is to hide your attempt at subverting the “attack”. You’re specifically trying to get the person to go to some other site in the normal process of scanning a QR code. Covering the original QR code with a logo would be obvious some subterfuge is at hand, and totally defeats the purpose. How is that not obvious to you?

> I was giving you a breakdown as to why people don’t do the kind of QR attacks / jokes that you seem to assume are common place rather than just saying “nice theory but that doesn’t happen in the real world”. There’s no need for you to be snarky

No, this is you: https://xkcd.com/386

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#56
post #54

Earlier quoted context omitted.

> you do realize that a QR code "attack" doesn't have to be malicious, yeah? it could be some gorilla PR campaign of something like a local band essentially rick rolling the users. or sending them to the menu of the competing restaurant up the street. or goatse. or or or... They can do that already just by placing their logo, or whatever, instead of a QR code. Plus whether it is malicious or not, it’s still hugely in…

> They can do that already just by placing their logo, or whatever, instead of a QR code What in the world are you on about? Just slapping a logo on top of a QR code suggests to me you’ve lost the plot. The point is to hide your attempt at subverting the “attack”. You’re specifically trying to get the person to go to some other site in the normal process of scanning a QR code. Covering the original QR code with a log…

Dude chill out. we are just having a discussion. That’s literally the point of forums.

https://news.ycombinator.com/newsguidelines.html

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#57
post #4

What's cool also is that this is from the West African tech scene.

Busted! Curious what gave it away, my username?

Awesome! You should be proud of this. I grew up next door in Ghana and I am delighted that someone from Togo is doing this. Well done.

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#58
post #56

Earlier quoted context omitted.

> They can do that already just by placing their logo, or whatever, instead of a QR code What in the world are you on about? Just slapping a logo on top of a QR code suggests to me you’ve lost the plot. The point is to hide your attempt at subverting the “attack”. You’re specifically trying to get the person to go to some other site in the normal process of scanning a QR code. Covering the original QR code with a log…

Dude chill out. we are just having a discussion. That’s literally the point of forums. https://news.ycombinator.com/newsguidelines.html

Again, you've lost the plot. Now, you're no longer even discussing anything but referencing the rules.

what discussion are you actually wanting to have, because you've now changed it 3 times

Re: Show HN: Scan QR codes to check in guests registered via Google Forms

#59
post #57
post #4

Earlier quoted context omitted.

Busted! Curious what gave it away, my username?

Awesome! You should be proud of this. I grew up next door in Ghana and I am delighted that someone from Togo is doing this. Well done.

Thanks tchalé ;) Btw, my parents never managed to decide if they were Togolese or Ghanaian
Post reply on HN