Skip to content

Comment on Login to your Google account by scanning a QR codeparent

Comments

> MITM this page, and serve you a bad QR code

You're then reading the QR code on what is assumed to be a trusted device on a trusted network (your mobile phone). The QR code would have to link to a bogus website mascarding as google in order to intercept your username & password. It requires a degree of vigilance on the part of the user at this point to ensure that the login page is genuinely google, but anyone using this auth mechanism must be reasonable security conscious to start with.

By your assertion, the only solution is to not use untrusted computers / networks at all. In the event that you have to this is one way to do so more securely.

This is not what he's talking about. Someone could open the sesame page on another computer, and use MITM to serve that code to you. Then, you're giving someone else access instead of yourself when you log in on your phone.

If you're this distrustful, don't use the computer. This entry only seems to prevent keylogging attacks.

Thanks for explaining what I meant in simpler terms.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.