Live data from Hacker News

macOS scanning and following downloaded QR codes has been retracted

twitter.com

21–30 of 80 posts

Re: macOS scanning and following downloaded QR codes has been retracted

#21
Glad I saw this and now I wonder how often something turns out to be false and then we don‘t happen to read about the retraction. Next we incorporate the false information as facts into discussions with other people. I mean, I‘m worried enough about infosec that I had enough interest to read the story but then I wouldn‘t have returned to look further into the story, eventually finding out it was false. Instead I‘m just lucky to have checked out HN once again today.

Re: macOS scanning and following downloaded QR codes has been retracted

#23
post #18
post #15

I hope the Apple security team that was assigned to investigate this report is enjoying a nice beverage tonight. Dealing with unconfirmed critical security reports with few details can be a nightmare, especially when they turn out to be unfounded. Good practice for the real thing, though.

This stuff happens all the time. A few years back a company I was contracting for had one of their end users report a high severity security defect. Apparently he signed into the app and thought he had been hacked because a couple of large 6-figure transactions had been made. After several hours of inconclusive investigation where even identifying the user proved difficult, this turned out to be him seeing the market…

> The app never even got installed and he never signed up for it.

....that is some serious "My computer won't turn on. No I can't check to see if the power cord is plugged in, its too dark to see back there because the power is out." energy.

Re: macOS scanning and following downloaded QR codes has been retracted

#24
post #17

One of the quicker cycles of "extraordinary claim" to "retracted" I've seen recently.

incite rage with anti-apple sentiment -> get twitter followers and engagement admit you were wrong and made it all up -> get people to ‘respect’ you and even more twitter followers

I wouldn’t say that’s a fair characterization.

Besides the ham fisted approach, the original vuln idea seemed reasonable.

They were wrong, it happens to the best of us.

I’d say the potential security risk was worth raising the flag over.

Better be wrong and safe, having many of us learn something along the way, then overly cautious and leave a potential problem unaddressed.

Re: macOS scanning and following downloaded QR codes has been retracted

#25
post #8

Earlier quoted context omitted.

It's equally funny to see the collective sigh-of-relief expressed through this post's upvotes. OCSP is real and can hurt you, warrantless iCloud access still goes un-mitigated, but thank God! The QR code IP leak turned out to be a fake. Who knew MacOS was a nice and private operating system all along?

OK, now how do we solve it? I’ve been thinking about this problem a lot. It seems to me you either go full send on the privacy front -> use FLOSS operating systems and self-host Nextcloud, or you want the comforts of modern apps and services -> buy into Apple’s or Google’s ecosystem. There exists no option where you get to keep your privacy and enjoy modern technology.

I'd love Apple to build iCloud hosting via your home mac or a new version of the server they used to sell. That way all data sits on and is processed by a machine you control. Admittedly wishful thinking but I can dream.

Re: macOS scanning and following downloaded QR codes has been retracted

#26
post #7

Earlier quoted context omitted.

This community is funny at times. A lot of people had their opinions on those two threads, didn't they? Kudos to the ones who questioned the origin of the phenomenon instead of declaring immediately that the world is falling.

It's not even at times. It's all the time. Theres many threads where the actual information is sparse but people sound extremely confident about their conclusions. Makes me realise that much of the time people are just making stuff up, there's just nobody to call them out.

You’re not kidding. From the earlier discussion:

> this is the exact same technology Apple lets China use to hunt down their religious and political minorities

> one thing is for certain; Apple doesn't treat privacy as a human right. If you can live with that, then more power to you.

Something tells me people won’t use this as an excuse to accuse Firefox of human rights abuses though.

Re: macOS scanning and following downloaded QR codes has been retracted

#27
post #8

Earlier quoted context omitted.

It's equally funny to see the collective sigh-of-relief expressed through this post's upvotes. OCSP is real and can hurt you, warrantless iCloud access still goes un-mitigated, but thank God! The QR code IP leak turned out to be a fake. Who knew MacOS was a nice and private operating system all along?

OK, now how do we solve it? I’ve been thinking about this problem a lot. It seems to me you either go full send on the privacy front -> use FLOSS operating systems and self-host Nextcloud, or you want the comforts of modern apps and services -> buy into Apple’s or Google’s ecosystem. There exists no option where you get to keep your privacy and enjoy modern technology.

How is using good Linux based OSes and self hosted FOSS not "enjoying modern technology".

The systems are very nice honestly, because they give you much more control (e.g. windows vs Linux).

Re: macOS scanning and following downloaded QR codes has been retracted

#28
post #19

Earlier quoted context omitted.

I flagged both of those at the time because it seemed more likely to be user error than anything. Bold claims like that need more evidence before publishing. One thing that any programmer knows is that until you have a way to reproduce something in a clean environment, a bug report on its own cannot be fully trusted. That doesn't mean you ignore the possibility that the reporter is correct, because sometimes reproduc…

In a now deleted tweet, the person was also ridiculing security researchers who were DMing him for more information, painting them as lazy, as if they hadn't tried to reproduce themselves. But nobody could reproduce the issue.

"""

lololol @ the "security researchers" sliding into my DMs asking me to run shell commands and send them the output

Go run your Little Snitch and WireShark and tcpdump and mdimport and mitmproxy and system_profiler on yourself; I'm not your SOC.

"""

https://webcache.googleusercontent.com/search?q=cache:e2HBeu...

Re: macOS scanning and following downloaded QR codes has been retracted

#29
post #22

One of the quicker cycles of "extraordinary claim" to "retracted" I've seen recently.

Great job by the author for looking more closely and clarifying this was not an issue.

> Great job by the author for looking more closely

I mean, I wouldn't say "great" when you've incited a security panic because you didn't even do the bare minimum of ...

> looking more closely

Re: macOS scanning and following downloaded QR codes has been retracted

#30

One of the quicker cycles of "extraordinary claim" to "retracted" I've seen recently.

Because a ton of people replied saying they couldn't reproduce the issue. It didn't help that the guy was snarky to a bunch of security researchers who asked him for more info.[1] He also neglected to mention that he'd recently visited the canary URL on that computer (which is why it was in Firefox’s recent shortcuts). Had he been more forthcoming with information, people would have figured it out sooner and his misinformation wouldn't have spread as far.

1. See the bottom of the archived tweet thread: https://archive.ph/qKyA3

Post reply on HN