this post was submitted on 28 May 2026
156 points (98.8% liked)

Privacy

4930 readers
216 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
 

I encountered this for the first time today while attempting to read something on archive.today.

I confirmed that decoding the qrcode using a computer and following the URL it contains is insufficient; the error it gave directed me here which is what the linked screenshot is of.

The old type of captcha remains available too, for now:

screenshot of text: Important: Mobile verification for Google Cloud Fraud Defense is an experimental challenge type in Preview. Visual and audio challenges are available as alternatives for users who can't complete mobile verification. To use them, click the Visual  or Audio  buttons.

OC writeup by @cypherpunks@lemmy.ml

all 31 comments
sorted by: hot top controversial new old
[–] DaddleDew@lemmy.world 69 points 2 months ago* (last edited 2 months ago) (1 children)

They better not implement that shit as mandatory because:

  • 1: I'm running a degoogled phone without Google Play Services
  • 2: I'm not installing their blatant spyware app
  • 3: I am not letting them create a link between my phone and my PC
  • 4: It looks like more trouble than before
  • 5: Fuck Google in general
[–] Lemming421@lemmy.world 56 points 2 months ago (3 children)
  1. Bad actors will start using clones of it with malicious QR codes to try and compromise your mobile device as well as your desktop one
[–] DaddleDew@lemmy.world 21 points 2 months ago

That is actually a valid point. It would create a new way to exploit users who don't know any better.

[–] Jiral@lemmy.org 4 points 2 months ago

My thoughts. All other issues aside, this sounds like a huge, unnercessary, attack vector.

[–] Mikina@programming.dev 2 points 2 months ago (3 children)

I keep hearing about malicious QR codes, but how does it actually work? Unless there's a serious vulnerability, how is it different from clicking on any link?

It has been a few years since I worked as a junior in offensive security, but that has been something I could never figure out when I looked into it.

Hmm, I guess you could use it for a pretty good phishing attempt. Just show a fake google login page and you're set, or maybe a fake .apk download "to confirm the captcha", but other than that, I don't really see a vector of attack.

[–] guywithadeathwish@lemmy.world 8 points 2 months ago* (last edited 2 months ago)

This example might shed some light on how malicious QR codes can work.

There's a lot of car parks in my area which have had QR codes stickered to the payment meters, instructing people to use the QR code to pay for their parking. These are council or private car parks, but the code takes you to a site that accurately mimics a usual carpark payment site. So people think they've paid for parking, but have actually sent money to a scammer, and they also end up with a fine for non-payment from the entity that actually owns the carpark.

[–] x00z@lemmy.world 2 points 2 months ago

That's exactly the attack vector.

The ClickFix social engineering attack is very effective:

[–] Lemming421@lemmy.world 1 points 2 months ago

Remember, not everyone is as tech savvy as us Lemmings.

For some of them, who mainly use their phones for Facebook or whatever, if they go to log into a website, it pops up a QR code, they’d scan it, install whatever potentially malicious software it told them to, then give it whatever access it wanted. Boom, compromised phone.

[–] OwOarchist@pawb.social 30 points 2 months ago

One step closer to "Drink verification can to continue."

[–] apfelwoiSchoppen@lemmy.world 22 points 2 months ago

I had this yesterday, I hate it. Switched to the eyeball icon and proceeded on.

[–] zr0@lemmy.dbzer0.com 21 points 2 months ago (2 children)

Reminder to NOT use or support archive.today or archive.is

[–] square@lemmy.zip 6 points 2 months ago (1 children)

Why, what did they...ooohhh

[–] Mikina@programming.dev 7 points 2 months ago* (last edited 2 months ago)

I'm out of the loop, what did you find?

EDIT: I guess you're talking about this? From a first reddit page about why is it down I could find.

The owner did it to themselves, by mounting a surreptitious DDoS campaign and altering the content of the archives to slander people, thus making it an unreliable source. This prompted Wikipedia to (correctly) remove it from all outbound links.

It's moot if it's online anymore or not - it's not a valid archive.

[–] MoreZombies@quokk.au 20 points 2 months ago

Fuck Sundar Pichai.

[–] Turret3857@infosec.pub 16 points 2 months ago

Inaction will do nothing. Commenting and complaining is inaction. Get your family on degoogled ROMs. Use Lineage or iode for devices that are supported, have them buy a used pixel for Graphene or Calyx otherwise. Have them complain to lawmakers. The more people who are with us, the less people to tell us to "get over it and be normal".

[–] XLE@piefed.social 14 points 2 months ago (1 children)

"Must"

Eye icon says not must.

[–] lemmysmash@beehaw.org 3 points 2 months ago (1 children)
[–] XLE@piefed.social 2 points 2 months ago

Absolutely. We should never expect them to be anything less than maximum evil when given the opportunity. If they could assume 100% of people used their OS, or the OS of a carefully studied (or complicit) competitor, we know they would.

[–] vk6flab@lemmy.radio 13 points 2 months ago

The word you're looking for is .. abomination.

[–] kernelle@lemmy.dbzer0.com 10 points 2 months ago (1 children)

"We've trained enough on crosswalks, fire hydrants, and motorbikes... Back to invasive data collection!"

On a serious note, this is the third time I've seen someone getting that new check. It's probably a trial run/slow rollout but they can't be removing accessibility features right? Alienating people because they can't scan seems evil.

Seems like a bear-trashcan problem. There's overlap between the most intelligent bot and least intelligent human.

[–] cybernihongo@reddthat.com 5 points 2 months ago (1 children)

Speaking of the crossroads and fire hydrants and motorbikes... I fucking hate recaptcha these days. I used to be able to go through those annoying fuckers first try. Now it's either I sit through that slow as hell sequence that fades out and in new pictures at a glacial pace and lose it, or I go through the ones where I'm expected to select several tiles in several big pictures (no longer just a single one) and inevitably I always fail this one. It's gotten so bad I've resorted to audio captchas in a few cases. Am I the only one?

[–] Sophocles@infosec.pub 1 points 1 month ago (1 children)

The tile select ones never work for me. I just click random squares until the fading one comes up. And that's only if I really care about whatever link it is. hCaptcha and arkoslabs are so much better

[–] cybernihongo@reddthat.com 2 points 1 month ago

I regularly use two websites which use recaptcha, one is necessary for work and the other is no-ip. The work one is annoying, it's almost every other day that I have to go through it.

[–] Jiral@lemmy.org 6 points 2 months ago

Locking down access for everyone not using US based services, should be illegal for sites (also) intended for the European market, quite frankly.

[–] greenbit@lemmy.zip 4 points 2 months ago

Captchas are human rights violations

[–] Kolanaki@pawb.social 3 points 2 months ago (1 children)

EA: "What? You guys don't have phones?"

Google: "Oooh! Write that down! Write that down!"

[–] DacoTaco@lemmy.world 3 points 2 months ago (1 children)

It was blizzard that said that, not ea :p

[–] Kolanaki@pawb.social 2 points 2 months ago

Yeah... Even IDK why I put EA when I was thinking of Diablo. They just suck that much. 🤷‍♂️

[–] Canconda@lemmy.ca 2 points 2 months ago

I don't like it but I saw this coming.