Live data from Hacker News

macOS scanning and following downloaded QR codes has been retracted

twitter.com

31–40 of 80 posts

Re: macOS scanning and following downloaded QR codes has been retracted

#31
post #17

Earlier quoted context omitted.

incite rage with anti-apple sentiment -> get twitter followers and engagement admit you were wrong and made it all up -> get people to ‘respect’ you and even more twitter followers

I wouldn’t say that’s a fair characterization. Besides the ham fisted approach, the original vuln idea seemed reasonable. They were wrong, it happens to the best of us. I’d say the potential security risk was worth raising the flag over. Better be wrong and safe, having many of us learn something along the way, then overly cautious and leave a potential problem unaddressed.

> then overly cautious and leave a potential problem unaddressed.

I don't think "do even the most cursory verification to check if the extraordinary thing I've just seen is actually happening" could be counted as "overly cautious".

Re: macOS scanning and following downloaded QR codes has been retracted

#32
post #30

One of the quicker cycles of "extraordinary claim" to "retracted" I've seen recently.

Because a ton of people replied saying they couldn't reproduce the issue. It didn't help that the guy was snarky to a bunch of security researchers who asked him for more info.[1] He also neglected to mention that he'd recently visited the canary URL on that computer (which is why it was in Firefox’s recent shortcuts). Had he been more forthcoming with information, people would have figured it out sooner and his misi…

> Had he been more forthcoming with information

It would have been better to have done some verification first, before tweeting, to check whether it was actually doing what it appeared to be. Especially when you know your tweets have considerable reach.

Re: macOS scanning and following downloaded QR codes has been retracted

#33
post #22

Earlier quoted context omitted.

Great job by the author for looking more closely and clarifying this was not an issue.

> Great job by the author for looking more closely I mean, I wouldn't say "great" when you've incited a security panic because you didn't even do the bare minimum of ... > looking more closely

Better to miss issues that aren’t reported or scramble to handle near misses? Optimize for false negatives at your own peril.

Re: macOS scanning and following downloaded QR codes has been retracted

#34
post #33

Earlier quoted context omitted.

> Great job by the author for looking more closely I mean, I wouldn't say "great" when you've incited a security panic because you didn't even do the bare minimum of ... > looking more closely

Better to miss issues that aren’t reported or scramble to handle near misses? Optimize for false negatives at your own peril.

Probably there’d be less hostility had the author not been so egregiously snarky towards people who couldn’t reproduce it.

Re: macOS scanning and following downloaded QR codes has been retracted

#36
post #30

One of the quicker cycles of "extraordinary claim" to "retracted" I've seen recently.

Because a ton of people replied saying they couldn't reproduce the issue. It didn't help that the guy was snarky to a bunch of security researchers who asked him for more info.[1] He also neglected to mention that he'd recently visited the canary URL on that computer (which is why it was in Firefox’s recent shortcuts). Had he been more forthcoming with information, people would have figured it out sooner and his misi…

> Matt Hodges @hodgesmr

> lololol @ the "security researchers" sliding into my DMs asking me to run shell commands and send them the output

> Go run your Little Snitch and WireShark and tcpdump and mdimport and mitmproxy and system_profiler on yourself; I'm not your SOC

Wow this guy comes across like a right twat. No wonder his apology sounds like it's coming out from furiously gritted teeth.

Still, I hope he learned something useful from this experience. Many of us have gone through a similar period of arrogance in our younger years, only to be shocked into looking back in shame later on.

Re: macOS scanning and following downloaded QR codes has been retracted

#37
post #18
post #15

I hope the Apple security team that was assigned to investigate this report is enjoying a nice beverage tonight. Dealing with unconfirmed critical security reports with few details can be a nightmare, especially when they turn out to be unfounded. Good practice for the real thing, though.

This stuff happens all the time. A few years back a company I was contracting for had one of their end users report a high severity security defect. Apparently he signed into the app and thought he had been hacked because a couple of large 6-figure transactions had been made. After several hours of inconclusive investigation where even identifying the user proved difficult, this turned out to be him seeing the market…

I’m quite curious to be a fly on the wall where the decision was made to accommodate the lowest common denominator. Why wouldn’t he just be dismissed rather than wasting hundreds or thousands of dollars of employee time?

By chance could you illuminate the thought process?

Re: macOS scanning and following downloaded QR codes has been retracted

#38
post #7

Earlier quoted context omitted.

This community is funny at times. A lot of people had their opinions on those two threads, didn't they? Kudos to the ones who questioned the origin of the phenomenon instead of declaring immediately that the world is falling.

It's not even at times. It's all the time. Theres many threads where the actual information is sparse but people sound extremely confident about their conclusions. Makes me realise that much of the time people are just making stuff up, there's just nobody to call them out.

Yeah and to be clear, that's not merely an HN thing, or an internet thing. People - even people who seem very clever - generally have no idea what they're talking about.

It's sort of exhilarating to truly understand just how much of the world is built on absolute bullshit.

Re: macOS scanning and following downloaded QR codes has been retracted

#39
post #33

Earlier quoted context omitted.

Better to miss issues that aren’t reported or scramble to handle near misses? Optimize for false negatives at your own peril.

Probably there’d be less hostility had the author not been so egregiously snarky towards people who couldn’t reproduce it.

Assuming everyone else is lazy or not trying hard enough to reproduce a misreported issue wasn't a great move

Re: macOS scanning and following downloaded QR codes has been retracted

#40

Prior discussions (when macOS was presumed at fault): - https://news.ycombinator.com/item?id=33095608 (83 comments) - https://news.ycombinator.com/item?id=33096540 (102 comments)

I flagged both of those at the time because it seemed more likely to be user error than anything. Bold claims like that need more evidence before publishing. One thing that any programmer knows is that until you have a way to reproduce something in a clean environment, a bug report on its own cannot be fully trusted. That doesn't mean you ignore the possibility that the reporter is correct, because sometimes reproduc…

> We should be humble and careful about jumping to conclusions.

Agreed, but it's also important to look out for confirmation bias. There were users on Twitter and even one HN commenter in the linked threads above who claimed to have reproduced the issue and verified the flaw. The HN commenter later updated their comment to admit their mistake. However, it's interesting to see how once the idea has been seeded, people are primed to accept any suggestion that it might be true.

Post reply on HN