So, if I send you a QR code via iMessage the URL in it will automatically be hit, using your IP address and browser/OS details. Wow that's quite an attack vector.
If you send me the URL directly it will be hit. A QR code wouldn't even add anything. And it's worked that way for many years, iMessage showing link previews.
Messages on my iPhone shows me link previews for links sent to me via SMS, not just via iMessage. I just checked to make sure. Those are necessarily generated on the recipient's end.
They could still be doing that through an Apple hosted proxy though? I believe services like discord and gmail webclient do that for links to not leak IPs.
Is it really better for SMS content to be sent to a server to achieve that? I like my SMS content to only be known to my telecom provider and my device.
I wonder if it would work with airdropped photos too. Another potential attack vector is, if you are using VPN and you rotate VPN servers every day, a website can display a unique QR code that is now saved to your browser cache, and then the next day after you have changed VPN server (and now have a new IP), macOS scans the QR code and basically tells the website your new IP
Is it? Has anyone actually tested sending a QR code over iMessage? Because doing that does not generate a link preview, and so there is no reason for Messages.app to be decoding it and fetching the URL.
If macOS really is background-scanning all images, and if Messages.app actually writes all received images out to disk as individual image files, then the background scanning could conceivably scan it. However I haven't seen anyone make this claim, it certainly doesn't seem necessary (why write it out to a file on disk?), and if this scanning is triggered by e.g. Spotlight indexing then it wouldn't be indexing cache files anyway.
So, has anyone actually demonstrated that sending a QR code over iMessage causes the recipient's device to fetch the URL? Because so far this just seems like complete speculation presented as fact.
Has anyone actually tested sending a QR code over iMessage?
I have, just now. Nothing happened at either end - the URL was not accessed at all. I can get it to recognise it's a QR code on my iPhone by tapping to focus the image, waiting for the OCR badge, tapping that, and then tapping the image again to bring up a small menu with the URL as a title and headed by "Open in Safari". None of those steps accesses the URL. You have to make a conscious action to access the URL...
Comments
So, if I send you a QR code via iMessage the URL in it will automatically be hit, using your IP address and browser/OS details. Wow that's quite an attack vector.
If you send me the URL directly it will be hit. A QR code wouldn't even add anything. And it's worked that way for many years, iMessage showing link previews.
If I send a URL directly it will be hit from my phone. Big difference there.
That is not true.
Messages on my iPhone shows me link previews for links sent to me via SMS, not just via iMessage. I just checked to make sure. Those are necessarily generated on the recipient's end.
Are you sure it auto expands the preview of a link without any user interaction? https://www.tatango.com/blog/ios-10-what-sms-marketers-need-...
This could be due to it being sent from someone in your contact list: https://support.twilio.com/hc/en-us/articles/360013199334-Ho...
They could still be doing that through an Apple hosted proxy though? I believe services like discord and gmail webclient do that for links to not leak IPs.
Is it really better for SMS content to be sent to a server to achieve that? I like my SMS content to only be known to my telecom provider and my device.
I wonder if it would work with airdropped photos too. Another potential attack vector is, if you are using VPN and you rotate VPN servers every day, a website can display a unique QR code that is now saved to your browser cache, and then the next day after you have changed VPN server (and now have a new IP), macOS scans the QR code and basically tells the website your new IP
Nobody said that.
That's exactly what happens though, and is an obvious method of attack.
Is it? Has anyone actually tested sending a QR code over iMessage? Because doing that does not generate a link preview, and so there is no reason for Messages.app to be decoding it and fetching the URL.
If macOS really is background-scanning all images, and if Messages.app actually writes all received images out to disk as individual image files, then the background scanning could conceivably scan it. However I haven't seen anyone make this claim, it certainly doesn't seem necessary (why write it out to a file on disk?), and if this scanning is triggered by e.g. Spotlight indexing then it wouldn't be indexing cache files anyway.
So, has anyone actually demonstrated that sending a QR code over iMessage causes the recipient's device to fetch the URL? Because so far this just seems like complete speculation presented as fact.
I have, just now. Nothing happened at either end - the URL was not accessed at all. I can get it to recognise it's a QR code on my iPhone by tapping to focus the image, waiting for the OCR badge, tapping that, and then tapping the image again to bring up a small menu with the URL as a title and headed by "Open in Safari". None of those steps accesses the URL. You have to make a conscious action to access the URL...