Live data from Hacker News

macOS scanning and following downloaded QR codes has been retracted

twitter.com

61–70 of 80 posts

Re: macOS scanning and following downloaded QR codes has been retracted

#61
post #7

Earlier quoted context omitted.

This community is funny at times. A lot of people had their opinions on those two threads, didn't they? Kudos to the ones who questioned the origin of the phenomenon instead of declaring immediately that the world is falling.

It's not even at times. It's all the time. Theres many threads where the actual information is sparse but people sound extremely confident about their conclusions. Makes me realise that much of the time people are just making stuff up, there's just nobody to call them out.

Why bother calling them out? That would require considering and denying their claims. It is much easier to make your own stuff up.

Re: macOS scanning and following downloaded QR codes has been retracted

#62
post #18

Earlier quoted context omitted.

This stuff happens all the time. A few years back a company I was contracting for had one of their end users report a high severity security defect. Apparently he signed into the app and thought he had been hacked because a couple of large 6-figure transactions had been made. After several hours of inconclusive investigation where even identifying the user proved difficult, this turned out to be him seeing the market…

I’m quite curious to be a fly on the wall where the decision was made to accommodate the lowest common denominator. Why wouldn’t he just be dismissed rather than wasting hundreds or thousands of dollars of employee time? By chance could you illuminate the thought process?

I’m guessing they figured that the lowest common denominator was rather close to the “median” common denominator.

Re: macOS scanning and following downloaded QR codes has been retracted

#65
post #18

Earlier quoted context omitted.

This stuff happens all the time. A few years back a company I was contracting for had one of their end users report a high severity security defect. Apparently he signed into the app and thought he had been hacked because a couple of large 6-figure transactions had been made. After several hours of inconclusive investigation where even identifying the user proved difficult, this turned out to be him seeing the market…

I’m quite curious to be a fly on the wall where the decision was made to accommodate the lowest common denominator. Why wouldn’t he just be dismissed rather than wasting hundreds or thousands of dollars of employee time? By chance could you illuminate the thought process?

When you are in a regulated industry it’s better to be sure than incur the wrath of the regulator.

Re: macOS scanning and following downloaded QR codes has been retracted

#66
post #54

Earlier quoted context omitted.

I doubt it. All of bigtech gets the same deranged treatment: Google, Facebook, Microsoft, etc. It was a weird moment when I found myself defending fb on hn more often than I criticized them (I think they're atrocious), but the comments on bigtech stories are just that stupid.

I agree that all big tech gets it, and to be honest anything that’s not FOSS gets shit on a ton here. But I do think Apple get it worse than other companies. Android posts don’t get as many comments that range from conspiracy to calling users sheep. Google gets ribbed for their ADHD but rarely criticized anywhere as much if Safari or Chrome both add their web proposals before standardization. Apple hardware gets triv…

I suppose I haven't noticed that myself. Though I spend less time on hn than I used to, and the consensus on Apple used to be dramatically more positive, so it's possibly that colors my perception

Re: macOS scanning and following downloaded QR codes has been retracted

#67
post #18
post #15

I hope the Apple security team that was assigned to investigate this report is enjoying a nice beverage tonight. Dealing with unconfirmed critical security reports with few details can be a nightmare, especially when they turn out to be unfounded. Good practice for the real thing, though.

This stuff happens all the time. A few years back a company I was contracting for had one of their end users report a high severity security defect. Apparently he signed into the app and thought he had been hacked because a couple of large 6-figure transactions had been made. After several hours of inconclusive investigation where even identifying the user proved difficult, this turned out to be him seeing the market…

Was it Personal Capital? I always thought it was silly that the demo screenshots in the marketing were some absurd amount in the multi millions. Like, who do you think you are marketing to?

Re: macOS scanning and following downloaded QR codes has been retracted

#68

The retraction is that it's not the operating system doing it. But honestly, Firefox doing the same thing isn't great either. Am I alone in finding it surprising that the recent list actively polls the things on it?

Yeah and if you use a VPN and occasionally rotate IPs, this Firefox "recents" feature can leak your new IP to websites that you previously visited

Re: macOS scanning and following downloaded QR codes has been retracted

#69
post #18

Earlier quoted context omitted.

This stuff happens all the time. A few years back a company I was contracting for had one of their end users report a high severity security defect. Apparently he signed into the app and thought he had been hacked because a couple of large 6-figure transactions had been made. After several hours of inconclusive investigation where even identifying the user proved difficult, this turned out to be him seeing the market…

Was it Personal Capital? I always thought it was silly that the demo screenshots in the marketing were some absurd amount in the multi millions. Like, who do you think you are marketing to?

Might be useful internally though. Back when I had a pet dinosaur I worked on an accounting program. Most test data was moving around 4 digit numbers. I made myself a richer test company and uncovered a few numeric bugs this way :)

Re: macOS scanning and following downloaded QR codes has been retracted

#70

The retraction is that it's not the operating system doing it. But honestly, Firefox doing the same thing isn't great either. Am I alone in finding it surprising that the recent list actively polls the things on it?

I don't think Firefox was reading any QR codes, but instead was recrawling the link in the "Recents" list on a new tab or bookmarks screen.

This is in no way a problem. There is precedent for browsers eagerly loading links, it happens all the time in regular webpages. This is most of the reason why anchors should be safe/side-effect free.

Post reply on HN