Live data from Hacker News

macOS is background scanning and following downloaded QR codes?

twitter.com

21–30 of 95 posts

Re: macOS is background scanning and following downloaded QR codes?

#22
post #20

Earlier quoted context omitted.

Scanning your images and followong links in them without user consent is pretty malicious.

What are you talking about? It sounds like you don’t understand what is going on here. Perhaps you think some data is going to Apple?

Having read the article I entirely understand what is going on here.

Do you expect your images to be scanned on disk and the links in them to be opened, leaking your ip? What if you do something as simple as screenshot an address bar in a browser? Save a menu QR code?

Now you are sending out traffic, accidentally, with your full ip to random places due to a service Apple inserted that you have no knowledge of.

Re: macOS is background scanning and following downloaded QR codes?

#24
post #20

Earlier quoted context omitted.

What are you talking about? It sounds like you don’t understand what is going on here. Perhaps you think some data is going to Apple?

Having read the article I entirely understand what is going on here. Do you expect your images to be scanned on disk and the links in them to be opened, leaking your ip? What if you do something as simple as screenshot an address bar in a browser? Save a menu QR code? Now you are sending out traffic, accidentally, with your full ip to random places due to a service Apple inserted that you have no knowledge of.

Do you seriously believe that your IP is private?

Do you know every site that has received your ip address?

I think the honest answer to both of these questions has to be no.

Re: macOS is background scanning and following downloaded QR codes?

#26
post #16

Quoted post unavailable.

This doesn't have to anything nefarious. It could be an unfortunate combination of code reuse and feature creep. Probably the QR scanner written for the iOS camera has an option to present URLs nicely (by fetching them), and some other OS component for image indexing reused the QR scanner without realizing it comes with side effects.

> This doesn't have to anything nefarious

It doesn't have to be explicitly nefarious to be a privacy issue. I'm sure there's some perfectly innocuous reason Apple could come up with for doing this, but unless and until Apple is forthcoming with those reasons and is transparent in how this is implemented (i.e. by providing source code) I have zero reason to take any such reason at face value.

Transparency is a dependency of trust. Apple is not transparent, and therefore is not trustworthy - especially when it's running a full-blown crawler on ostensibly-private messages.

Re: macOS is background scanning and following downloaded QR codes?

#27
post #21

Earlier quoted context omitted.

I am, and so is the author of those tweets.

Is your claim that data is being exfiltrated to Apple?

Data exfiltration is not necessary for this to be a privacy concern; data becomes a liability as soon as it's collected even locally.

EDIT: in this case, however, data exfiltration is happening, by means of Apple's closed-source software blindly sending HTTP requests to unknown servers. Apple might not be the recipient of the exfiltrated data, but the exfiltration is happening nonetheless.

Re: macOS is background scanning and following downloaded QR codes?

#28

I'll be interested to see if anyone else can reproduce this. I created a request bin [0], then created a QR code pointing at it, then downloaded that QR code. I'm not sure how often this "image scanning" is supposed to occur but just downloading it didn't cause a hit nor did the 10min I waited, nor did using QuickLook, nor opening it Preview, nor scanning it with my iPhone, the only thing that caused a request was cl…

The Twitter thread says it was created "a few days ago" and was hit "this morning" so I'm guessing 10 minutes might not be enough (if it is even something time-based).

I'm willing to bet that if you triggered a spotlight database rebuild that it would be triggered in that process. My guess is that spotlight sees an image to index, ocrs all the text and adds it to the index. It probably also detects qr codes and generates a 'preview' of their content by following the link. Possible it may also do that if you were to take a picture of a url clearly enough that it could be OCRed.

Re: macOS is background scanning and following downloaded QR codes?

#29
post #21

Earlier quoted context omitted.

Is your claim that data is being exfiltrated to Apple?

Data exfiltration is not necessary for this to be a privacy concern; data becomes a liability as soon as it's collected even locally. EDIT: in this case, however, data exfiltration is happening , by means of Apple's closed-source software blindly sending HTTP requests to unknown servers. Apple might not be the recipient of the exfiltrated data, but the exfiltration is happening nonetheless.

No post body was provided.

Re: macOS is background scanning and following downloaded QR codes?

#30
post #20

Earlier quoted context omitted.

Scanning your images and followong links in them without user consent is pretty malicious.

What are you talking about? It sounds like you don’t understand what is going on here. Perhaps you think some data is going to Apple?

If you have the misfortune of living in a country where accessing $BANNED_WEBSITE can get you a nighttime visit from the local goon squad, this could well get you tortured or killed.
Post reply on HN