For those who don’t know, it’s where someone takes a QR code like on a poster for a concert and puts a sticker with a different QR code on top to a fake website that looks like the concert website (or a Rick Roll).

The obvious answer is to scratch off the QR code if you notice it’s a sticker, but It’s not always acceptable -or legal- to start damaging stuff to check if it’s real or not. Also what if it’s out of reach on a sign or something?

You can’t put a little text under saying what the website is as a sort of checksum because the vandal can just write their own website under their sticker.

  • jonathan7luke@lemmy.zip
    link
    fedilink
    arrow-up
    13
    ·
    1 month ago

    Unfortunately sometimes it’s really hard to avoid. I’ve been to restaurants that don’t even have physical menus. You could probably find a menu on their website, but not always.

      • MyBrainHurts@lemmy.ca
        link
        fedilink
        English
        arrow-up
        22
        arrow-down
        1
        ·
        1 month ago

        “Sorry date/group of friends/family/work function, we can’t eat here. I don’t want to scan a QR code.”

        • Rhynoplaz@lemmy.world
          link
          fedilink
          arrow-up
          5
          ·
          1 month ago

          I think I’ve only ever seen 2 or 3 places in my life that didn’t have physical menus. I didn’t walk out of the ones that didn’t, but I haven’t been back to any of them.

        • Lost_My_Mind@lemmy.world
          link
          fedilink
          arrow-up
          4
          arrow-down
          2
          ·
          1 month ago

          I work 7 days a week with 4 different jobs. I don’t have time to go out, much less have friends. But I have walked out of places and stopped in a gym signup process because they required a cell phone to use their service.

          • hitmyspot@aussie.zone
            link
            fedilink
            arrow-up
            4
            ·
            1 month ago

            Good for you to abandon dark patterns, however, people prioritising socialising might lead to less dark patterns in general.

        • hitmyspot@aussie.zone
          link
          fedilink
          arrow-up
          4
          arrow-down
          1
          ·
          1 month ago

          Australia did too. QR codes are probably the least invasive tracking you can imagine. You can open each one in a clean browser, like Firefox focus, if you like. They are just a shortcut for entering urls. If china wants to track its citizens, it’s not with QR codes as they track so much more from the data already on your phone.

          Most places with public transport have moved from cash to card based payment. It’s all traceable already. Sure, some places, you don’t need to register the card and can cycle through some, but many places you need to register to use one, or register for reduced fares.

          • osaerisxero@kbin.melroy.org
            link
            fedilink
            arrow-up
            6
            ·
            1 month ago

            They’re not a url, they’re just a string that’s often a url. There’s no (technical) reason why it couldn’t be a signed public key, or a signed url that the camera app could validate

            • hitmyspot@aussie.zone
              link
              fedilink
              arrow-up
              3
              ·
              1 month ago

              Yes, they are just data, but commonly that data encodes a url.

              I agree, it could be made more secure, but getting rid of url shorteners and trackers that obfuscate real urls would be a step in the right direction with no new software needed.