Live data from Hacker News

macOS is background scanning and following downloaded QR codes?

twitter.com

61–70 of 95 posts

Re: macOS is background scanning and following downloaded QR codes?

#61
post #23

So, if I send you a QR code via iMessage the URL in it will automatically be hit, using your IP address and browser/OS details . Wow that's quite an attack vector.

If you send me the URL directly it will be hit. A QR code wouldn't even add anything. And it's worked that way for many years, iMessage showing link previews.

If I send a URL directly it will be hit from my phone. Big difference there.

Re: macOS is background scanning and following downloaded QR codes?

#62

Apple should be proxying and caching these results to avoid the risk of exposing client devices, prevent incidental DDOS, as well as the obvious privacy issues.

We'll just switch to user-specific QR codes then, like unique links in spam mails to find out who clicked it.

Re: macOS is background scanning and following downloaded QR codes?

#63

"Background scanning" sounds more nefarious than what's probably really going on -- which is probably either generating thumbnail previews (for Finder) or indexing (for Spotlight), both of which are desired. Or maybe malware scanning to put files in quarantine if they point to dangerous content? macOS is also becoming more intelligent about text in images, e.g. it OCR's images so you can select text. I don't know if…

Regardless, theis shouldn't happen. Indexing the URL, fine. Fetching it is a very poor idea and a can of worms.

Re: macOS is background scanning and following downloaded QR codes?

#64
post #47

Earlier quoted context omitted.

so you are saying apple is doing something they already knew is a bad idea?

No. I’m saying your information is outdated and wrong.

What do you mean? The OP said that this is how Pegasus pwned (notice the past tense) the iPhone. That's correct. Moreover while Apple might have closed that specific vulnerability, would you bet your money (or even your live) on there not being other vulnerabilities in the apple indexer?

Re: macOS is background scanning and following downloaded QR codes?

#65
post #9

Earlier quoted context omitted.

I feel like there are better ways to do this, to the point that this 'feature' actually looks really out-of-place. Why wouldn't you get these thumbnail previews when you actually scan the QR Code? You're going to be fetching/caching the favicon and framebuffer for the page anyways, there's literally no reason not to get that data at runtime rather than 3 hours later. It's not exactly malicious, but weird "we know bet…

> Why wouldn't you get these thumbnail previews when you actually scan the QR Code? These aren't scanned, they're located inside .png image files you can download or generate locally on your computer. > You're going to be fetching/caching the favicon and framebuffer for the page anyways, there's literally no reason not to get that data at runtime rather than 3 hours later. No one asked the OS to fetch the favicon/fra…

That's definitely a more sane analysis of the situation, thank you for your two cents.

In general, these things frustrate me just as much as they did on Windows. I don't want random processes jumping up to use 100% of my CPU for no reason. I can't even count the number of times my Mac gets pinned by mdworker processes running in the background. It's reminiscent of pulling my hair out trying to understand why OneDrive or Edge is pinning one of my cores even though it isn't open.

My overall gripe is this pattern of behavior. I'd rather spend 2-5 seconds waiting for my QR code to load instead of my OS deciding to randomly cache it at some indeterminate point. Maybe other people disagree, though. Us HN users don't really tend to reflect the opinions of Joe Shmoe and his feelings towards modern computing.

Re: macOS is background scanning and following downloaded QR codes?

#66
post #61

Earlier quoted context omitted.

If you send me the URL directly it will be hit. A QR code wouldn't even add anything. And it's worked that way for many years, iMessage showing link previews.

If I send a URL directly it will be hit from my phone. Big difference there.

That is not true.

Messages on my iPhone shows me link previews for links sent to me via SMS, not just via iMessage. I just checked to make sure. Those are necessarily generated on the recipient's end.

Re: macOS is background scanning and following downloaded QR codes?

#67

Earlier quoted context omitted.

Scanning your images and followong links in them without user consent is pretty malicious.

How is it malicious? “Malicious” doesn’t mean “unwanted behaviour”. You are saying that Apple intend to do harm with this. How?

On the one hand, I get where you're coming from and I agree that this specific example isn't malicious (as I've highlighted elsewhere in the thread)

...on the other hand, this is the exact same technology Apple lets China use to hunt down their religious and political minorities. Maybe they don't intend harm to Americans, but one thing is for certain; Apple doesn't treat privacy as a human right. If you can live with that, then more power to you.

Re: macOS is background scanning and following downloaded QR codes?

#69
post #52

Earlier quoted context omitted.

how can you be so confident that it's "closed"? the last time apple announced the high protection mode for state sponsored targets in new ios (whatever it's called), they disable all auto previews in that mode. if they are as confident as you are that it's "closed" that doesn't seem necessary?

I’m confident that it’s closed because they claimed to have closed it. As for the high protection mode - of course that reduces the attack surface.

If this forum were to live up to its name, you would be laughed out of here after that comment.

Re: macOS is background scanning and following downloaded QR codes?

#70

Earlier quoted context omitted.

How is it malicious? “Malicious” doesn’t mean “unwanted behaviour”. You are saying that Apple intend to do harm with this. How?

On the one hand, I get where you're coming from and I agree that this specific example isn't malicious (as I've highlighted elsewhere in the thread) ...on the other hand, this is the exact same technology Apple lets China use to hunt down their religious and political minorities. Maybe they don't intend harm to Americans, but one thing is for certain; Apple doesn't treat privacy as a human right. If you can live with…

Seems a bit like a witch hunt to me. It's your PC executing the request. Nowhere does it say this data gets send to apple servers.
Post reply on HN