Live data from Hacker News

Organised gangs behind rise in QR 'quishing' scams

bbc.com

11–20 of 49 posts

Re: Organised gangs behind rise in QR 'quishing' scams

#11
post #4

Hey, guys, I have this crazy idea. How about we have people give small bits of paper to other people to pay for things? Or maybe even wave small cards of plastic in front of things that can read them? Maybe how about not using my fucking phone for every goddamn thing ? Crazy, right? KTHXBYE.

Those have lots of security problems too.

Re: Organised gangs behind rise in QR 'quishing' scams

#12
Was wondering why such scams are not a thing in India (yet?), and realized there is always a person next to the QR to verify the payment. So such QR quishing scams are much harder to pull off.

[Not saying there are no scams in India. Just that QRs for payments are very popular here as well, and scammers are smart and active, so was wondering why not]

Re: Organised gangs behind rise in QR 'quishing' scams

#13

The parking garage one can be really insidious. The parking apps where I live in Canada have a terrible design; you absolute cannot start parking session without an account that requires you to input name, address, phone number, and then the app itself has other technical glitches that genuinely made me wonder if I had been scammed. What makes it doubly so is that the parking companies have been removing the parking…

I never pay parking if a machine isn't there. I've never been caught. And if I'm ever fined I'm taking that all the way to court. One must have extreme disdain for such things.

Re: Organised gangs behind rise in QR 'quishing' scams

#14
post #8
post #3

How do you protect yourself from this? Treat public QR codes like "free" USB drives – don't use them?

The same way you might treat a URL randomly written on a billboard. Barring vulnerabilities in your QR reader, it should be enough to just read the URL.

and how do you know the real parking company's URL is 'city-secure-parking.com' and not 'express-city-parking.com'?

Re: Organised gangs behind rise in QR 'quishing' scams

#15
post #9

The parking garage one can be really insidious. The parking apps where I live in Canada have a terrible design; you absolute cannot start parking session without an account that requires you to input name, address, phone number, and then the app itself has other technical glitches that genuinely made me wonder if I had been scammed. What makes it doubly so is that the parking companies have been removing the parking…

That's just all parking apps in my experience. The websites (if they exist) are usually about as bad. Car parks make more money if they can fine you, so there's no incentive to make payment easy or make it work reliably.

Car parks in Australia just have credit card NFC terminals which are provided by the banks.

Re: Organised gangs behind rise in QR 'quishing' scams

#16
post #9

The parking garage one can be really insidious. The parking apps where I live in Canada have a terrible design; you absolute cannot start parking session without an account that requires you to input name, address, phone number, and then the app itself has other technical glitches that genuinely made me wonder if I had been scammed. What makes it doubly so is that the parking companies have been removing the parking…

That's just all parking apps in my experience. The websites (if they exist) are usually about as bad. Car parks make more money if they can fine you, so there's no incentive to make payment easy or make it work reliably.

Oh damn I never realised that. There is a class of services where they want to make payment difficult to collect penalties.

Re: Organised gangs behind rise in QR 'quishing' scams

#17
post #5
post #2

Why not a short URL where one can at least read the domain name and see if it looks reasonable before progressing with whatever the task ($£kr) is

Even seeing the domain name doesn't solve the fundamental trust problem. A malicious actor could post a fake QR code or fake short URL leading to "city-parking-secure.com" or similar legitimate-looking domain. The real solution is establishing a trusted channel - citizens need to know they should only pay for municipal parking through their city's official domain (e.g., sf.gov/parking). But this isn't possible when i…

The parking company could use a subdomain, say parking.sf.gov

Re: Organised gangs behind rise in QR 'quishing' scams

#18
post #14
post #8

Earlier quoted context omitted.

The same way you might treat a URL randomly written on a billboard. Barring vulnerabilities in your QR reader, it should be enough to just read the URL.

and how do you know the real parking company's URL is 'city-secure-parking.com' and not 'express-city-parking.com'?

Call the city to verify.

If enough people do it, they'll find a way to solve the problem (e.g. a subdomain of the official city site, putting back regular parking meters/machines, ...)

Re: Organised gangs behind rise in QR 'quishing' scams

#19
post #5

Earlier quoted context omitted.

Even seeing the domain name doesn't solve the fundamental trust problem. A malicious actor could post a fake QR code or fake short URL leading to "city-parking-secure.com" or similar legitimate-looking domain. The real solution is establishing a trusted channel - citizens need to know they should only pay for municipal parking through their city's official domain (e.g., sf.gov/parking). But this isn't possible when i…

The parking company could use a subdomain, say parking.sf.gov

That could help, as `.gov` can only be registered by the US government. But... a lot of the millennial and gen X generation have misguided beliefs about the trustworthiness of TLDs. Such as thinking `.com` is more trustworthy than `.net` under the assumption that it can only be registered by a real company.

I'm convinced the only responsible solutions are chip-only payment processors and conventional coin machines, as pricey as they are.

Re: Organised gangs behind rise in QR 'quishing' scams

#20
post #11
post #4

Hey, guys, I have this crazy idea. How about we have people give small bits of paper to other people to pay for things? Or maybe even wave small cards of plastic in front of things that can read them? Maybe how about not using my fucking phone for every goddamn thing ? Crazy, right? KTHXBYE.

Those have lots of security problems too.

Stealing my wallet is generally worth less than stealing my phone even before you take into account the value of the data and the grief and expense of replacing my phone.

The fact that parking systems won't install wireless credit card readers and instead will foist the externality onto me of 1) having a phone, 2) that is currently charged, 3) has a relatively high resolution camera, and 4) capable of high bandwidth internet access is the kind of thing that ticks me off.

Post reply on HN