The author originally made it sound like they just generated the QR code, saved it, and then left it in the downloads folder. Now they are saying the Firefox "recents" feature on the home screen triggered it. This would have to mean the author already visited the link embedded in the QR code. If the author had mentioned that fact, then internet speculation would have probably figured out the real cause a lot earlier.
Though I gotta say, this is still an attack vector that I hadn't considered. If you use a VPN and occasionally rotate IPs, this Firefox "recents" feature can leak your new IP to websites that you previously visited.
The original tweets explained it. The user agent is impersonating a shared Facebook/Twitter/etc link preview/thumbnail. Many sites respond with markup more appropriate for a thumbnail when using that user agent, and if not, it’s unlikely that they serve anything worse, so it’s little harm done.
Comments
The tweet has now been deleted and the author has retracted his claim.
https://twitter.com/hodgesmr/status/1577739222412312578
https://news.ycombinator.com/item?id=33100130
The author originally made it sound like they just generated the QR code, saved it, and then left it in the downloads folder. Now they are saying the Firefox "recents" feature on the home screen triggered it. This would have to mean the author already visited the link embedded in the QR code. If the author had mentioned that fact, then internet speculation would have probably figured out the real cause a lot earlier.
Though I gotta say, this is still an attack vector that I hadn't considered. If you use a VPN and occasionally rotate IPs, this Firefox "recents" feature can leak your new IP to websites that you previously visited.
The explanation for the retraction doesn't explain that user agent string. It's weird enough coming from macOS; it's even weirder coming from Firefox.
The behavior's still concerning in any case, whether it's macOS silently doing it or Firefox silently doing it.
The original tweets explained it. The user agent is impersonating a shared Facebook/Twitter/etc link preview/thumbnail. Many sites respond with markup more appropriate for a thumbnail when using that user agent, and if not, it’s unlikely that they serve anything worse, so it’s little harm done.