Live data from Hacker News

Enough with the QR Codes

ramisayar.com

61–70 of 76 posts

Re: Enough with the QR Codes

#62
post #49

I see people scan QR codes often, and even occasionally do myself; but then, I live in Japan. Here, QR codes became popularized well before the 'smartphone', because everybody's regular phone has been able to scan them for years. (I think from around the turn of the millennium, at least.) That makes sense, because as as bad as smartphone on-screen keyboards are, entering URLs on a numeric keypad was even worse . Two…

Plus the fact that not ALL QR Codes are URLs to marketing sites. I have seen plenty of "stick in a microwave" type meals that have a QR code which, when scanned, display nutritional information which would never have fit on the tiny label. Mind you this is also in Japan so....

JAPAN FOR THE WIN! I like that use case...

Re: Enough with the QR Codes

#63

> Firstly, that’s a huge security risk in my mind, it’s like I am trying to open an email attachment from an unknown sender because nobody knows who put up these ads. It's not like opening an email attachment, it's more like opening a URL. The only documented QR code attack I know of consists of a QR code with a malicious URL ( http://isc.sans.edu/diary.html?storyid=12760 ). The QR code only served as a 'mask' to the…

I used the email analogy cause I figured that would be more obvious for people to recognize the security risk... it's hard to explain things like drive-by downloading for non-techy people.

Re: Enough with the QR Codes

#64

I feel like there's a routine anti-QR code thread on HN once a month and it's always the same argument. They'll die naturally when nobody wants them. For now it seems like certain people want them.

It seems more like people want people to want them so they're sticking around. Sometimes they're useful, but that's pretty rare.

> people want people to want them

LOL Nice.

Re: Enough with the QR Codes

#65

Reposting my comment from the blog, because it's still "awaiting moderation". QR Codes do have uses, but everyone uses them wrong. The first and most obvious use is as a replacement barcode. Add to physical products to expand scanning use-cases. But not as a marketing stunt. The next, which I quite like is for device -> device communication. For example displaying a QR code on your phone and having it automatically s…

Apologies for the "awaiting moderation", I was sleeping. It's up now.

Re: Enough with the QR Codes

#67

> Firstly, that’s a huge security risk in my mind, it’s like I am trying to open an email attachment from an unknown sender because nobody knows who put up these ads. It's not like opening an email attachment, it's more like opening a URL. The only documented QR code attack I know of consists of a QR code with a malicious URL ( http://isc.sans.edu/diary.html?storyid=12760 ). The QR code only served as a 'mask' to the…

But opening unknown URL IS dangerous. It's like URL shorteners that plague internet since Twitter - you never know where link will take you and what scripts etc. will run in your browser.

Re: Enough with the QR Codes

#68
post #42
post #40

Earlier quoted context omitted.

Well you can still track how many people scan it, right ? e.g. by providing a proxy link ?

Yeah sure - plenty of people do QR codes that go through bit.ly, just as possible to do it through any other tracking platform.

bitly provides qr codes for every link generated with their service. Just go to the info page. ex: https://bitly.com/FPUVjU+

Re: Enough with the QR Codes

#69
post #67

> Firstly, that’s a huge security risk in my mind, it’s like I am trying to open an email attachment from an unknown sender because nobody knows who put up these ads. It's not like opening an email attachment, it's more like opening a URL. The only documented QR code attack I know of consists of a QR code with a malicious URL ( http://isc.sans.edu/diary.html?storyid=12760 ). The QR code only served as a 'mask' to the…

But opening unknown URL IS dangerous. It's like URL shorteners that plague internet since Twitter - you never know where link will take you and what scripts etc. will run in your browser.

On my device (android with bar code scanner device), the experience is that I scan a QR code with a URL, it tells me that the QR code has a URL & shows me what the URL is, then gives me the option to visit the link.

Depending on if the URL is a shortened URL, it is just as safe or moreso than regular browsing.

Is your experience different from this?

Re: Enough with the QR Codes

#70
post #27
post #7

Context is everything. For example, QR codes are huge in Japan. Witness this video: http://www.youtube.com/watch?v=myzLAXtqoa8&feature=playe... ! People literally lining up to take snapshots of QR codes.

Playing the Japan card during discussion of a cultural phenomenon is the equivalent of playing the Hitler card in a political debate. If there's one thing that's clear, it's that they will do absolutely anything in Japan. EDIT: In Japan, this is the kind of thing they watch on TV: http://youtu.be/xqoXcLqVemA

Yeah. Those wacky Orientals, eh?
Post reply on HN