[Cryptography] distributing fingerprints etc. via QR codes etc.

Dave Horsfall dave at horsfall.org
Sat Sep 13 14:46:48 EDT 2014


On Fri, 12 Sep 2014, Jerry Leichter wrote:

> If QR codes were truly "just a glob of data" which could not trigger any 
> automatic action, I might be willing to scan one.  But unfortunately 
> they trod the same path as e-mail, but before they were even released:  
> From just a blob of data that couldn't harm you to something 
> "convenient" - but laden with all kinds of hidden semantics that can not 
> just deliver, but even execute, attack code on your system.

Err, for the benefit of this netizen and others, what are these semantics?

I've just installed a QR reader on my MacBook (and I hate seeing myself 
when the camera is engaged), and also upon my Android phone.

Should I be worried?  And I don't mean by seeing myself in the morning...

-- Dave, a happy PINE/ALPINE user for many many years


More information about the cryptography mailing list