this post was submitted on 16 Sep 2026
98 points (97.1% liked)

Technology

88072 readers
2732 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] PierceTheBubble@lemmy.ml 3 points 5 hours ago (1 children)

So again by linking accounts to a device operated by police or customs in this case. Which for SMS confirmations, I understand can be intercepted and confirmed by authorities, but the QR exploit seems farther fetched (because who in their right mind would open a messenger and scan a random QR?); and of course if you have access to a target's unlocked device, it becomes trivial.

[–] x00z@lemmy.world 4 points 5 hours ago (1 children)

Who says a random QR though? Intercept mail and replace legit QR codes with the malicious ones. It's a common tactic for criminals to put them on payment gateways such as parking meters. And cops are criminals anyway.

[–] PierceTheBubble@lemmy.ml 3 points 2 hours ago

At least for WhatsApp and Signal, it appears the user is required to open the messenger app, navigate to the linking setting, authenticate themselves, and scan the QR code on the device that is to be linked (or one that corresponds to it, but hiding in a malicious e-mail). I can't find any flow that allows for a QR code to link directly to the authentication mechanism, and provide the authentication code to it, while bypassing user authentication.