Live data from Hacker News

QR code images in macOS are silently executed in the background hours/days later

twitter.com

101–110 of 111 posts

Re: QR code images in macOS are silently executed in the background hours/days later

#101
post #98

Earlier quoted context omitted.

> URL prefetching is usually only expected to happen "on demand" while you're using stuff I don't think this is my expectation. When I receive messages overnight, I want URLs in those messages prefetched, for example. The whole point is that when I open my mail or messages the previews are already available, instead of waiting.

I'm not sure you want that. At least a lot of people don't want that.

I'm quite sure that I want that. Why would I prefer to fetch previews while I'm trying to look at messages instead of while I'm sleeping?

Re: QR code images in macOS are silently executed in the background hours/days later

#102
post #73

Earlier quoted context omitted.

> URL prefetching is usually only expected to happen "on demand" while you're using stuff I don't think this is my expectation. When I receive messages overnight, I want URLs in those messages prefetched, for example. The whole point is that when I open my mail or messages the previews are already available, instead of waiting.

That still implies that you are actively "using" the messaging application. Just because it is listening to messages in this case doesn't mean it's inactive, you still expect it to push stuff to you. However in the case of the QR code, just because you "have" the QR code on your disk, doesn't imply you have an intent to visit a link it. That would be like if you had a .txt file with a string that looked like a URL in…

> Like imagine you download a restaurant menu to check out the food and they provided it as an image (pretty standard). As a part of that image is a QR code to their Facebook page (also usually benign). In this case, let's say you are uninterested in sharing your (or specifically your IP's) interest in that restaurant with Facebook, this feature as described would share the info for you without consent.

This isn't any different from someone sending me a link to the menu at their website and them seeing my IP hit the preview there, so I'm not sure why I would care either way; if anything, downloading the menu is more intent on my part than being sent it by someone (who I may or may not even know).

Re: QR code images in macOS are silently executed in the background hours/days later

#104

If, as he suggests, it may be happening on iOS as well then it would offer third parties the interesting possibility of "probing" some locations for iPhone photo events, especially if the background requests and their headers can be distinguished from intentional requests. Say you own a bar, nightclub, popular tourist location, or whatever. Place specific QR codes at locations of encoding URLs pointing to a server yo…

> if background scanning is active even before the picture is taken

Just tested this and no matter how many times I point Camera at my QR code, it doesn't access the URL until I specifically click on the little yellow callout box.

Re: QR code images in macOS are silently executed in the background hours/days later

#105

Earlier quoted context omitted.

Which results in that NOTHING works anymore. File search, email search. Literally nothing will work anymore.

"NOTHING, literally nothing works anymore" is an alarmist exaggeration, even if you would do the ham-fisted thing of adding your entire home directory to Spotlight's exclusion list. The sane and logical option is to add only your Pictures directory (or whatever folders you keep images in) to the exclusion list.

No it's not, because then you can't use any search on Pictures.

Re: QR code images in macOS are silently executed in the background hours/days later

#106

Earlier quoted context omitted.

“This link might be dangerous - better click on it!” I’d suspect it’s indexing for search rather than a security protocol - i feel like anybody security minded would have approached this differently

Antivirus software isn’t known for being security-minded. Running potential malware in a buggy kernel-space sandbox comes to mind.

Antivirus software is so sloppily written it actually increases your attack surface, often catastrophically so:

https://www.theregister.com/2016/05/17/tavis_ormandy_zeroes_...

https://www.computerworld.com/article/2493275/researcher-fin...

Re: QR code images in macOS are silently executed in the background hours/days later

#108
There's a clarification from the original poster of this [1]:

"Well, I was wrong. I now believe the canary token was triggered not by macOS decoding the QR, but by Firefox’s “recent” shortcuts on the home screen. I gave too much trust to a Stack Exchange answer. I have deleted the incorrect information. I regret the error."

False alarm, Get back to work folks! ;)

[1] https://twitter.com/hodgesmr/status/1577739222412312578

Re: QR code images in macOS are silently executed in the background hours/days later

#110
post #73

Earlier quoted context omitted.

That still implies that you are actively "using" the messaging application. Just because it is listening to messages in this case doesn't mean it's inactive, you still expect it to push stuff to you. However in the case of the QR code, just because you "have" the QR code on your disk, doesn't imply you have an intent to visit a link it. That would be like if you had a .txt file with a string that looked like a URL in…

> Like imagine you download a restaurant menu to check out the food and they provided it as an image (pretty standard). As a part of that image is a QR code to their Facebook page (also usually benign). In this case, let's say you are uninterested in sharing your (or specifically your IP's) interest in that restaurant with Facebook, this feature as described would share the info for you without consent. This isn't an…

No. In this example your IP is shared with a third party "Facebook" simply because of the embedded QR code to a social page hosted by them. This is something very different from, say, the website of the restaurant you downloaded the menu from knowing your IP.

The privacy implication is very different. If you enable link previews in a messaging app, you consented to any potential site getting your IP. If the restaurant adds a tracker on their page, they've consented to the 3rd party tracking from their end. But with the QR auto-loaded by the OS, neither you nor the first part have explicitly consented to the additional information being shared. There is strictly more information being shared.

> This isn't any different from someone sending me a link to the menu at their website and them seeing my IP hit the preview there

Again this is an inaccurate comparison. The closer analogy would be someone sending a link to a website and somehow your IP is exposed not only to the website that was shared, but also to every other website that the shared website links to.

Post reply on HN