Google is trying to normalize a new "complete the captcha on your phone by scanning a QR code" flow, which I'm sure will be a whole new vector for scams.
Users are habituated to clicking links (mostly from their email) as verification, too. QR codes get a weird amount of hate for something that basically amounts to a hyperlink you can transmit through meatspace.
It’s because people don’t yet understand that scanning a code can be just as risky as clicking a link. They will trust whatever they see on the other side, while they may be more suspicious of what they see after following a hyperlink.
Comments
Google is trying to normalize a new "complete the captcha on your phone by scanning a QR code" flow, which I'm sure will be a whole new vector for scams.
Can’t wait for the first “scan this code to verify” scam that takes you to a mobile Chrome 0day
Or you could send them to download some spyware/adware Play Store app
Couldn't any exploit possible via that pathway also be executed based on a link? I don't see how a QR code makes the situation any worse.
Once users are habituated to scanning QR codes for verification, it becomes easier.
Users are habituated to clicking links (mostly from their email) as verification, too. QR codes get a weird amount of hate for something that basically amounts to a hyperlink you can transmit through meatspace.
It’s because people don’t yet understand that scanning a code can be just as risky as clicking a link. They will trust whatever they see on the other side, while they may be more suspicious of what they see after following a hyperlink.