logoalt Hacker News

bgwalterlast Monday at 2:20 AM1 replyview on HN

Modern cryptography should also not allow users to activate a sketchy linked device feature by scanning a QR code:

"Because linking an additional device typically requires scanning a quick-response (QR) code, threat actors have resorted to crafting malicious QR codes that, when scanned, will link a victim's account to an actor-controlled Signal instance."

This is a complete failure of the cryptosystem, worse than the issue of responding in plaintext. You can at least design an email client that simply refuses to send plaintext messages because PGP is modular.


Replies

tptaceklast Monday at 6:06 PM

I'm comfortable with what this thread says about our respective arguments. Thanks!