Live data from Hacker News

macOS scanning and following downloaded QR codes has been retracted

twitter.com

11–20 of 80 posts

Re: macOS scanning and following downloaded QR codes has been retracted

#11
post #8
post #7

Earlier quoted context omitted.

This community is funny at times. A lot of people had their opinions on those two threads, didn't they? Kudos to the ones who questioned the origin of the phenomenon instead of declaring immediately that the world is falling.

It's equally funny to see the collective sigh-of-relief expressed through this post's upvotes. OCSP is real and can hurt you, warrantless iCloud access still goes un-mitigated, but thank God! The QR code IP leak turned out to be a fake. Who knew MacOS was a nice and private operating system all along?

So... I think replication was needed and have a MacBook myself. However, the claim in question was tricky to verify because it was supposedly occuring over the course of days.

I also think it says a lot about collective anxieties over not using an open OS. The scanning wasn't happening but it was plausible and there wasn't really much to do about it other than try to verify it.

I think the episode says less about collective unwarranted paranoia and more about collective vulnerabilities.

I still am scratching my head about the new tweet though. It doesn't say the scanning isn't happening, just that it's not MacOS.

Re: macOS scanning and following downloaded QR codes has been retracted

#12
post #3

It's nice to see people clarify when they make mistakes. I'm still REALLY curious about the Facebook useragent. Where was that from, specifically? Firefox?

Yes, I just tried it and apparently Firefox on iOS uses that user agent when it gets a thumbnail of a page for its "Recently Saved" and "Jump Back In" sections on the new tab page.

Re: macOS scanning and following downloaded QR codes has been retracted

#13
post #11
post #8

Earlier quoted context omitted.

It's equally funny to see the collective sigh-of-relief expressed through this post's upvotes. OCSP is real and can hurt you, warrantless iCloud access still goes un-mitigated, but thank God! The QR code IP leak turned out to be a fake. Who knew MacOS was a nice and private operating system all along?

So... I think replication was needed and have a MacBook myself. However, the claim in question was tricky to verify because it was supposedly occuring over the course of days. I also think it says a lot about collective anxieties over not using an open OS. The scanning wasn't happening but it was plausible and there wasn't really much to do about it other than try to verify it. I think the episode says less about col…

> The scanning wasn't happening but it was plausible

I didn't think it is plausible which is why I set up a whole bunch of replication scenarios to verify the extraordinary claim.

> It doesn't say the scanning isn't happening, just that it's not MacOS.

I think it's clear that the scanning isn't happening and that it was just Firefox refetching something?

"I now believe the canary token was triggered [...] by Firefox’s “recent” shortcuts on the home screen"

Re: macOS scanning and following downloaded QR codes has been retracted

#14

Prior discussions (when macOS was presumed at fault): - https://news.ycombinator.com/item?id=33095608 (83 comments) - https://news.ycombinator.com/item?id=33096540 (102 comments)

I flagged both of those at the time because it seemed more likely to be user error than anything. Bold claims like that need more evidence before publishing.

One thing that any programmer knows is that until you have a way to reproduce something in a clean environment, a bug report on its own cannot be fully trusted. That doesn't mean you ignore the possibility that the reporter is correct, because sometimes reproduction is very difficult indeed, but you have to allow for the fact that something about the user's environment or workflow unrelated to your own code might be at fault.

We are all susceptible to errors in our methodology or limitations in our understanding of how complex systems interact. We should be humble and careful about jumping to conclusions.

Re: macOS scanning and following downloaded QR codes has been retracted

#15
I hope the Apple security team that was assigned to investigate this report is enjoying a nice beverage tonight. Dealing with unconfirmed critical security reports with few details can be a nightmare, especially when they turn out to be unfounded.

Good practice for the real thing, though.

Re: macOS scanning and following downloaded QR codes has been retracted

#16
post #8
post #7

Earlier quoted context omitted.

This community is funny at times. A lot of people had their opinions on those two threads, didn't they? Kudos to the ones who questioned the origin of the phenomenon instead of declaring immediately that the world is falling.

It's equally funny to see the collective sigh-of-relief expressed through this post's upvotes. OCSP is real and can hurt you, warrantless iCloud access still goes un-mitigated, but thank God! The QR code IP leak turned out to be a fake. Who knew MacOS was a nice and private operating system all along?

OK, now how do we solve it?

I’ve been thinking about this problem a lot. It seems to me you either go full send on the privacy front -> use FLOSS operating systems and self-host Nextcloud, or you want the comforts of modern apps and services -> buy into Apple’s or Google’s ecosystem.

There exists no option where you get to keep your privacy and enjoy modern technology.

Re: macOS scanning and following downloaded QR codes has been retracted

#17

One of the quicker cycles of "extraordinary claim" to "retracted" I've seen recently.

incite rage with anti-apple sentiment -> get twitter followers and engagement

admit you were wrong and made it all up -> get people to ‘respect’ you and even more twitter followers

Re: macOS scanning and following downloaded QR codes has been retracted

#18
post #15

I hope the Apple security team that was assigned to investigate this report is enjoying a nice beverage tonight. Dealing with unconfirmed critical security reports with few details can be a nightmare, especially when they turn out to be unfounded. Good practice for the real thing, though.

This stuff happens all the time.

A few years back a company I was contracting for had one of their end users report a high severity security defect. Apparently he signed into the app and thought he had been hacked because a couple of large 6-figure transactions had been made.

After several hours of inconclusive investigation where even identifying the user proved difficult, this turned out to be him seeing the marketing example screens in the app store and having a panic. The app never even got installed and he never signed up for it.

The marketing screens were quickly updated to show something less impressive and with a sample data only warning...

Re: macOS scanning and following downloaded QR codes has been retracted

#19

Prior discussions (when macOS was presumed at fault): - https://news.ycombinator.com/item?id=33095608 (83 comments) - https://news.ycombinator.com/item?id=33096540 (102 comments)

I flagged both of those at the time because it seemed more likely to be user error than anything. Bold claims like that need more evidence before publishing. One thing that any programmer knows is that until you have a way to reproduce something in a clean environment, a bug report on its own cannot be fully trusted. That doesn't mean you ignore the possibility that the reporter is correct, because sometimes reproduc…

In a now deleted tweet, the person was also ridiculing security researchers who were DMing him for more information, painting them as lazy, as if they hadn't tried to reproduce themselves. But nobody could reproduce the issue.

Re: macOS scanning and following downloaded QR codes has been retracted

#20
post #18
post #15

I hope the Apple security team that was assigned to investigate this report is enjoying a nice beverage tonight. Dealing with unconfirmed critical security reports with few details can be a nightmare, especially when they turn out to be unfounded. Good practice for the real thing, though.

This stuff happens all the time. A few years back a company I was contracting for had one of their end users report a high severity security defect. Apparently he signed into the app and thought he had been hacked because a couple of large 6-figure transactions had been made. After several hours of inconclusive investigation where even identifying the user proved difficult, this turned out to be him seeing the market…

I wonder how big of a company you'd have to be to go through all the effort of changing marketing screens because of that. I can think of the biggest company I've worked for laugh at that and move on.
Post reply on HN