Live data from Hacker News

Encoding your WiFi access point password into a QR code

feeding.cloud.geek.nz

171–180 of 234 posts

Re: Encoding your WiFi access point password into a QR code

#171
post #149
post #65

Earlier quoted context omitted.

Or when you setup a new apple computer, you have to enter the wifi password without being able to see what you type, without being sure it is the right casing, and if you are not in the US without being sure you are using the right keyboard layout in the first place (the is no opportunity to type something else in a clear text box before that step).

When a friend tried to connect to a new network on their MacBook, a second friend with an iPad got a pop-up that such-and-such was attempting to connect to their network, and if they wanted to share connection details. One click and they were in. Creepy, but convenient.

Not sure if it is really that creepy - IIRC there is an encrypted advertisement over bluetooth that your contacts have the key to recognize/decrypt.

Re: Encoding your WiFi access point password into a QR code

#172
post #39

I painted my wifi password as a QR code on 40x40cm canvas.. Painted as in with a brush and paint, it was a bit of work, but now it's both pragmatic and pretty :)

Pics or it didn't happen.

My wifi password is AdapterHorse7462Yeah, whatcha gonna do with that information? ;)

Re: Encoding your WiFi access point password into a QR code

#174

This is super helpful for mobile devices. But it makes rather confusing on how to connect it on an e.g. laptop without having to scan the QR code with the mobile device first. If the password is 63-char length, typing it wouldn't be 'quick'.

There should be a laptop app which can import a QR code picture from a file. Most of the laptops also have a webcam nowadays, perhaps it could be used too.

Re: Encoding your WiFi access point password into a QR code

#175
post #167

Earlier quoted context omitted.

Remember bitly, AMP, CDNs? Also, as to something like a javascript exploit in a URL itself, QRs can hold a surprising amount of data, enough to max out most URL browser limits around 2,048 bytes.

Ok but if it's a bitly link then I'm still not clicking. Just like it an email includes an obviously shortened email.

Bitly is so useful though for making usable QR links

Re: Encoding your WiFi access point password into a QR code

#176
post #140

Earlier quoted context omitted.

Qrafter on iOS has exactly that UI, which is why I use it.

If anyone knows of an equivalent on Android (preferably available on F-Droid), I'm all ears.

I recommend “Privacy Friendly QR Scanner” (https://github.com/SecUSo/privacy-friendly-qr-scanner) by the SECUSO group, who specialize in apps that respect user privacy.

Worked great for me on my last phone, and peace of mind knowing you aren’t being tracked.

Available to download on fdroid or the play store.

https://github.com/SecUSo

Re: Encoding your WiFi access point password into a QR code

#177
post #142

Earlier quoted context omitted.

You're shifting responsibility from developers to the users. If reading a QR code triggers a bank transaction, that's an issue with the QR scanner and the banking application. Users cannot check if a domain is "ok" by looking at it. You visit websites to discover what's there. A few years ago it was common knowledge that ".to" is shady and ".com" looks more legit. Now we have more TLDs than I can count. How is someon…

I was mostly thinking about URLs in untrusted contexts, like maybe from an ad you see on the street, that you want to screen by hand against malicious intent; not so much about things like your banking app example, which should always have some kind of confirmation anyway.

It really shouldn't matter to the browser what URL you enter. Maybe it's not the page you're looking for. But opening a website itself should cause no harm.

Just compare with today's internet advertising. Legit websites are still full of somewhat malicious ads. And users click on it - of course, since that's what a website is for.

What I'm trying to make clear is that there is no such case where QR scanners, browsers or application may consider a safe context where the user implicitly consents with malicious actions by the QR/website/...

Re: Encoding your WiFi access point password into a QR code

#178
post #22
post #5

Is it only Android 10 that can do this with scanning a qr code, or also v9?

Android 9: Camera search icon on Google assistant (long press "home" and cancel voice command) offers "join network" option for this kind of QR code

I had to install Google Lens first. When I tap join network, the reply is that I have to manually join the network. This is Android 9, and is an Android One phone (yes, still on Android 9 and not even a year old).

Update: Actually it works with the build-in Camera. Point to QR, it decodes it and shows SSID and password, there's a wifi icon button, and pressing that immediately connects.

Re: Encoding your WiFi access point password into a QR code

#179
post #5

Is it only Android 10 that can do this with scanning a qr code, or also v9?

Works for me on Android 7.0 on Xiaomi Redmi Note 4X 4G Phablet since 2017 with the com.xiaomi.scanner app.

Bonus: I can also share my WiFi settings by opening a QR code on my phones display.

Post reply on HN