Bitcoin Forum
June 29, 2024, 11:01:34 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: How is sending bitcoin through a QR-code safe ?  (Read 238 times)
Becassine (OP)
Hero Member
*****
Offline Offline

Activity: 1876
Merit: 813



View Profile WWW
July 16, 2023, 12:40:40 AM
 #21

Incredible, I'd never have thought of all that. Thanks to LoyceV for the two articles, which I'll read now.

Now I have another question: I know you can personalize a QR-code so that people scan it and go to a website for example (I've already done this by modifying the colors, adding a logo etc), can you do the same with a bitcoin address (I assume so?) and which site do you recommend to do it safely?

Thanks

▄▄███████████████████▄▄
▄█████████▀█████████████▄
███████████▄▐▀▄██████████
███████▀▀███████▀▀███████
██████▀███▄▄████████████
█████████▐█████████▐█████
█████████▐█████████▐█████
██████████▀███▀███▄██████
████████████████▄▄███████
███████████▄▄▄███████████
█████████████████████████
▀█████▄▄████████████████▀
▀▀███████████████████▀▀
Peach
BTC bitcoin
Buy and Sell
Bitcoin P2P
.
.
▄▄███████▄▄
▄████████
██████▄
▄██
█████████████████▄
▄███████
██████████████▄
███████████████████████
█████████████████████████
████████████████████████
█████████████████████████
▀███████████████████████▀
▀█████████████████████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀

▀▀▀▀███▀▀▀▀
EUROPE | AFRICA
LATIN AMERICA
▄▀▀▀











▀▄▄▄


███████▄█
███████▀
██▄▄▄▄▄░▄▄▄▄▄
████████████▀
▐███████████▌
▐███████████▌
████████████▄
██████████████
███▀███▀▀███▀
.
Download on the
App Store
▀▀▀▄











▄▄▄▀
▄▀▀▀











▀▄▄▄


▄██▄
██████▄
█████████▄
████████████▄
███████████████
████████████▀
█████████▀
██████▀
▀██▀
.
GET IT ON
Google Play
▀▀▀▄











▄▄▄▀
Mpamaegbu
Legendary
*
Offline Offline

Activity: 2744
Merit: 1225


Once a man, twice a child!


View Profile
July 16, 2023, 12:24:21 PM
 #22

First of all, the QR code itself can be replaced without hacking. For example, if it's a sticker, someone can put their own sticker on top of the original one. If it's a photo posted on social media, someone can edit it in Photoshop to put their address. You get the idea.

But on software level, this task is not as trivial as replacing a clipboard, but still could be achieved, at least theoretically. The QR-code scanner app could be exploited to replace Bitcoin adresses with hacker's address, if it has such a sophisticated vulnerability.
You see? In summary, it then simply means that the security of our funds lies only with us and not on some gadgets. These gadgets, to start with, are the creation of man. Man can manipulate them. It takes a man to break any system or manipulate any computer or software.

I haven't received Bitcoin or any crypto through a QR before. I consider it a more complicated process than copying and pasting addresses. When it comes to financial issues, whether with Bitcoin or fiat, I think those involved should exercise caution and patience. Go through the details slowly. That's what I do. I'm never going to be in a haste. What for? Except it's an old address that I've saved up on my wallet, I take my time to run through new addresses meticulously.

Before you boast of your material acquisition, take a stroll to a morgue and there you will find those who were once better than you're. Only fools think they've it all. Stay humble 🤔
LoyceV
Legendary
*
Offline Offline

Activity: 3360
Merit: 16944


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 17, 2023, 06:43:39 AM
 #23

I know you can personalize a QR-code so that people scan it and go to a website for example (I've already done this by modifying the colors, adding a logo etc), can you do the same with a bitcoin address (I assume so?) and which site do you recommend to do it safely?
I wouldn't recommend any website. I've used command line qrencode (a standard package easily installed on Linux).
Adding a logo is basically abusing the QR-code's built-in error correction: set is as high as possible, and test if the QR-code still works after you cover part of it with a logo.

Despairo
Hero Member
*****
Offline Offline

Activity: 1092
Merit: 858



View Profile WWW
July 17, 2023, 07:35:54 AM
 #24

Either you use QR code or paste your address, make sure you double or triple check all the characters, not only check on the last three characters. What make QR code isn't more safe than copy paste is you wouldn't know what it is especially it's shortened link.

You see? In summary, it then simply means that the security of our funds lies only with us and not on some gadgets. These gadgets, to start with, are the creation of man. Man can manipulate them. It takes a man to break any system or manipulate any computer or software.
You're just like saying there's nothing safe for anything created by other people, what about hardware wallet, non custodial wallet or device that used to be a cold storage? you're use that for holding your Bitcoin and those weren't created by you.

███████████████████████
███████████████████████
████████▀█▀████████████
████████████████████████
████████████████▀▀██████
████▀▀▀█████████████████
████████████▄▄▄▄███████
█████████████████▄▄▄████
█████████████████▀█████
████████████▀██▀████████
████████████████████████
███████████▄▄█████▄▄█████

███████████████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
.
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██




██
██
██
██
██
██
██
██
██
████
████▀▀▀
▀▄
▌░░▐▌
█████▄▄█
████████▄
████████▌
███████
███████
██████
██████
█████
██




██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
.
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
.
..Play Now..
[
Becassine (OP)
Hero Member
*****
Offline Offline

Activity: 1876
Merit: 813



View Profile WWW
July 19, 2023, 08:39:40 AM
 #25

A bitcointalker sent a very interesting article about the potential fraudulent use of a QR-code (on another topic). This is of course not the same as sending btc to an address, but it had to be thought about nonetheless.

The QR-code refers to a fraudulent third-party application whose all authorizations must be validated. Then the scammer takes control of the smartphone remotely. Always the same thing: it is a question of promising a gift or threatening a fine (and sending the victim to pay on a fraudulent site). It is therefore quite simply a question of phishing as it has existed for a long time by email.

https://upgradedtamilan.com/an-ordinary-cup-of-tea-cost-a-woman-from-singapore-1-5-million-rubles/

▄▄███████████████████▄▄
▄█████████▀█████████████▄
███████████▄▐▀▄██████████
███████▀▀███████▀▀███████
██████▀███▄▄████████████
█████████▐█████████▐█████
█████████▐█████████▐█████
██████████▀███▀███▄██████
████████████████▄▄███████
███████████▄▄▄███████████
█████████████████████████
▀█████▄▄████████████████▀
▀▀███████████████████▀▀
Peach
BTC bitcoin
Buy and Sell
Bitcoin P2P
.
.
▄▄███████▄▄
▄████████
██████▄
▄██
█████████████████▄
▄███████
██████████████▄
███████████████████████
█████████████████████████
████████████████████████
█████████████████████████
▀███████████████████████▀
▀█████████████████████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀

▀▀▀▀███▀▀▀▀
EUROPE | AFRICA
LATIN AMERICA
▄▀▀▀











▀▄▄▄


███████▄█
███████▀
██▄▄▄▄▄░▄▄▄▄▄
████████████▀
▐███████████▌
▐███████████▌
████████████▄
██████████████
███▀███▀▀███▀
.
Download on the
App Store
▀▀▀▄











▄▄▄▀
▄▀▀▀











▀▄▄▄


▄██▄
██████▄
█████████▄
████████████▄
███████████████
████████████▀
█████████▀
██████▀
▀██▀
.
GET IT ON
Google Play
▀▀▀▄











▄▄▄▀
LoyceV
Legendary
*
Offline Offline

Activity: 3360
Merit: 16944


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 19, 2023, 08:56:04 AM
 #26

This attack could just as well have happened by email. The main problem isn't the QR-code, the problem is giving a phone access to a bank account that can send $20,000.
Here, banks are more and more moving towards mobile usage. Until now, I've been able to avoid it, but they're replacing more and more dedicated hardware devices by a code on an app. It's cheaper for the bank, but they sacrifice security for convenience.

Fuso.hp
Sr. Member
****
Offline Offline

Activity: 504
Merit: 298



View Profile
July 19, 2023, 10:19:07 AM
 #27

QR code to me is the safest way to scan and send payment since there is no copy and paste to send payment only scan and pay without copying address. QR code is already being designed with rightful address so there's no way to be attacked by any scammer or hacker. Although I can not say with all assurance that it can't be hacked, nowadays things are really happening because scammer are exploring different ways to phish people's funds.
I consider QR code scanning to be a safe mode of payment transfer as there is no option to make a mistake by scanning the QR code or sending the payment to another address. Most of the time we copy the address seen in the case of payment transfer and then send the money to that address but many times due to our little mistake we use the wrong address or some other word in the middle of the address, as a result of which our money goes to someone else's wallet or disappears. Mainly to eliminate this possibility QR code is scanned so that payment can be transferred to 100% correct address. If you have the option to scan the QR code for your payment transfer, you must scan the QR code and transfer the payment.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
satscraper
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1445



View Profile
July 19, 2023, 11:10:14 AM
Merited by Becassine (1)
 #28

QR code to me is the safest way to scan and send payment since there is no copy and paste to send payment only scan and pay without copying address. QR code is already being designed with rightful address so there's no way to be attacked by any scammer or hacker. Although I can not say with all assurance that it can't be hacked, nowadays things are really happening because scammer are exploring different ways to phish people's funds.
I consider QR code scanning to be a safe mode of payment transfer as there is no option to make a mistake by scanning the QR code or sending the payment to another address.

Not at all.

Faulty QR readers may result in making mistake and sending payment into wrong address. Besides of that, QR code may be compromised  by malware  sitting on the source device. So it is a good practice to   always check the details of transaction rather than rely on QR code itself.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!