• PierceTheBubble@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    13 hours ago

    So again by linking accounts to a device operated by police or customs in this case. Which for SMS confirmations, I understand can be intercepted and confirmed by authorities, but the QR exploit seems farther fetched (because who in their right mind would open a messenger and scan a random QR?); and of course if you have access to a target’s unlocked device, it becomes trivial.

    • x00z@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      13 hours ago

      Who says a random QR though? Intercept mail and replace legit QR codes with the malicious ones. It’s a common tactic for criminals to put them on payment gateways such as parking meters. And cops are criminals anyway.

      • PierceTheBubble@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        10 hours ago

        At least for WhatsApp and Signal, it appears the user is required to open the messenger app, navigate to the linking setting, authenticate themselves, and scan the QR code on the device that is to be linked (or one that corresponds to it, but hiding in a malicious e-mail). I can’t find any flow that allows for a QR code to link directly to the authentication mechanism, and provide the authentication code to it, while bypassing user authentication.