this post was submitted on 14 Mar 2025
480 points (98.6% liked)

Comic Strips

15976 readers
1800 users here now

Comic Strips is a community for those who love comic stories.

The rules are simple:

Web of links

founded 2 years ago
MODERATORS
 

(page 2) 4 comments
sorted by: hot top controversial new old
[–] [email protected] 53 points 1 month ago* (last edited 1 month ago) (14 children)

How would you make an arbitrary QR code have a verifiable signature?

[–] [email protected] 58 points 1 month ago (9 children)

I can see a system where you have to scan the QR code in a specific app for that purpose (e.g. a dedicated QR code payment app which approved businesses sign up to, which either includes or remotely queries a database of valid endpoints). At that point though, where you're requiring a dedicated app anyway, you may as well invent your own 2D code system with blackjack, hookers and signing. But yeah, I don't understand how this would work otherwise. QR codes just aren't made for security. They shouldn't be used anywhere security is required.

load more comments (9 replies)
[–] [email protected] 2 points 1 month ago (1 children)

Just pay a public CA everytime you make one /s

load more comments (1 replies)
[–] [email protected] -5 points 1 month ago (2 children)

A verifiable signature could be created but the use of public keys lets malicious actors to sign using the same key

load more comments (2 replies)
load more comments (11 replies)
load more comments
view more: ‹ prev next ›