Bitcoin Forum
May 02, 2024, 04:51:50 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: How is sending bitcoin through a QR-code safe ?  (Read 231 times)
Becassine (OP)
Hero Member
*****
Offline Offline

Activity: 1820
Merit: 775


I love BitBox02 (Shiftcrypto) and Zeus (Cryptotag)


View Profile WWW
July 16, 2023, 12:40:40 AM
 #21

Incredible, I'd never have thought of all that. Thanks to LoyceV for the two articles, which I'll read now.

Now I have another question: I know you can personalize a QR-code so that people scan it and go to a website for example (I've already done this by modifying the colors, adding a logo etc), can you do the same with a bitcoin address (I assume so?) and which site do you recommend to do it safely?

Thanks

▄▄███████████████████▄▄
▄█████████▀█████████████▄
███████████▄▐▀▄██████████
███████▀▀███████▀▀███████
██████▀███▄▄████████████
█████████▐█████████▐█████
█████████▐█████████▐█████
██████████▀███▀███▄██████
████████████████▄▄███████
███████████▄▄▄███████████
█████████████████████████
▀█████▄▄████████████████▀
▀▀███████████████████▀▀
Peach
BTC bitcoin
Buy and Sell
Bitcoin P2P
.
.
▄▄███████▄▄
▄████████
██████▄
▄██
█████████████████▄
▄███████
██████████████▄
███████████████████████
█████████████████████████
████████████████████████
█████████████████████████
▀███████████████████████▀
▀█████████████████████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀

▀▀▀▀███▀▀▀▀
EUROPE | AFRICA
LATIN AMERICA
▄▀▀▀











▀▄▄▄


███████▄█
███████▀
██▄▄▄▄▄░▄▄▄▄▄
████████████▀
▐███████████▌
▐███████████▌
████████████▄
██████████████
███▀███▀▀███▀
.
Download on the
App Store
▀▀▀▄











▄▄▄▀
▄▀▀▀











▀▄▄▄


▄██▄
██████▄
█████████▄
████████████▄
███████████████
████████████▀
█████████▀
██████▀
▀██▀
.
GET IT ON
Google Play
▀▀▀▄











▄▄▄▀
1714625510
Hero Member
*
Offline Offline

Posts: 1714625510

View Profile Personal Message (Offline)

Ignore
1714625510
Reply with quote  #2

1714625510
Report to moderator
1714625510
Hero Member
*
Offline Offline

Posts: 1714625510

View Profile Personal Message (Offline)

Ignore
1714625510
Reply with quote  #2

1714625510
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714625510
Hero Member
*
Offline Offline

Posts: 1714625510

View Profile Personal Message (Offline)

Ignore
1714625510
Reply with quote  #2

1714625510
Report to moderator
1714625510
Hero Member
*
Offline Offline

Posts: 1714625510

View Profile Personal Message (Offline)

Ignore
1714625510
Reply with quote  #2

1714625510
Report to moderator
Mpamaegbu
Legendary
*
Offline Offline

Activity: 2674
Merit: 1208


Once a man, twice a child!


View Profile
July 16, 2023, 12:24:21 PM
 #22

First of all, the QR code itself can be replaced without hacking. For example, if it's a sticker, someone can put their own sticker on top of the original one. If it's a photo posted on social media, someone can edit it in Photoshop to put their address. You get the idea.

But on software level, this task is not as trivial as replacing a clipboard, but still could be achieved, at least theoretically. The QR-code scanner app could be exploited to replace Bitcoin adresses with hacker's address, if it has such a sophisticated vulnerability.
You see? In summary, it then simply means that the security of our funds lies only with us and not on some gadgets. These gadgets, to start with, are the creation of man. Man can manipulate them. It takes a man to break any system or manipulate any computer or software.

I haven't received Bitcoin or any crypto through a QR before. I consider it a more complicated process than copying and pasting addresses. When it comes to financial issues, whether with Bitcoin or fiat, I think those involved should exercise caution and patience. Go through the details slowly. That's what I do. I'm never going to be in a haste. What for? Except it's an old address that I've saved up on my wallet, I take my time to run through new addresses meticulously.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
LoyceV
Legendary
*
Offline Offline

Activity: 3304
Merit: 16582


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 17, 2023, 06:43:39 AM
 #23

I know you can personalize a QR-code so that people scan it and go to a website for example (I've already done this by modifying the colors, adding a logo etc), can you do the same with a bitcoin address (I assume so?) and which site do you recommend to do it safely?
I wouldn't recommend any website. I've used command line qrencode (a standard package easily installed on Linux).
Adding a logo is basically abusing the QR-code's built-in error correction: set is as high as possible, and test if the QR-code still works after you cover part of it with a logo.

Despairo
Hero Member
*****
Offline Offline

Activity: 1022
Merit: 833


View Profile WWW
July 17, 2023, 07:35:54 AM
 #24

Either you use QR code or paste your address, make sure you double or triple check all the characters, not only check on the last three characters. What make QR code isn't more safe than copy paste is you wouldn't know what it is especially it's shortened link.

You see? In summary, it then simply means that the security of our funds lies only with us and not on some gadgets. These gadgets, to start with, are the creation of man. Man can manipulate them. It takes a man to break any system or manipulate any computer or software.
You're just like saying there's nothing safe for anything created by other people, what about hardware wallet, non custodial wallet or device that used to be a cold storage? you're use that for holding your Bitcoin and those weren't created by you.
Becassine (OP)
Hero Member
*****
Offline Offline

Activity: 1820
Merit: 775


I love BitBox02 (Shiftcrypto) and Zeus (Cryptotag)


View Profile WWW
July 19, 2023, 08:39:40 AM
 #25

A bitcointalker sent a very interesting article about the potential fraudulent use of a QR-code (on another topic). This is of course not the same as sending btc to an address, but it had to be thought about nonetheless.

The QR-code refers to a fraudulent third-party application whose all authorizations must be validated. Then the scammer takes control of the smartphone remotely. Always the same thing: it is a question of promising a gift or threatening a fine (and sending the victim to pay on a fraudulent site). It is therefore quite simply a question of phishing as it has existed for a long time by email.

https://upgradedtamilan.com/an-ordinary-cup-of-tea-cost-a-woman-from-singapore-1-5-million-rubles/

▄▄███████████████████▄▄
▄█████████▀█████████████▄
███████████▄▐▀▄██████████
███████▀▀███████▀▀███████
██████▀███▄▄████████████
█████████▐█████████▐█████
█████████▐█████████▐█████
██████████▀███▀███▄██████
████████████████▄▄███████
███████████▄▄▄███████████
█████████████████████████
▀█████▄▄████████████████▀
▀▀███████████████████▀▀
Peach
BTC bitcoin
Buy and Sell
Bitcoin P2P
.
.
▄▄███████▄▄
▄████████
██████▄
▄██
█████████████████▄
▄███████
██████████████▄
███████████████████████
█████████████████████████
████████████████████████
█████████████████████████
▀███████████████████████▀
▀█████████████████████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀

▀▀▀▀███▀▀▀▀
EUROPE | AFRICA
LATIN AMERICA
▄▀▀▀











▀▄▄▄


███████▄█
███████▀
██▄▄▄▄▄░▄▄▄▄▄
████████████▀
▐███████████▌
▐███████████▌
████████████▄
██████████████
███▀███▀▀███▀
.
Download on the
App Store
▀▀▀▄











▄▄▄▀
▄▀▀▀











▀▄▄▄


▄██▄
██████▄
█████████▄
████████████▄
███████████████
████████████▀
█████████▀
██████▀
▀██▀
.
GET IT ON
Google Play
▀▀▀▄











▄▄▄▀
LoyceV
Legendary
*
Offline Offline

Activity: 3304
Merit: 16582


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 19, 2023, 08:56:04 AM
 #26

This attack could just as well have happened by email. The main problem isn't the QR-code, the problem is giving a phone access to a bank account that can send $20,000.
Here, banks are more and more moving towards mobile usage. Until now, I've been able to avoid it, but they're replacing more and more dedicated hardware devices by a code on an app. It's cheaper for the bank, but they sacrifice security for convenience.

Fuso.hp
Sr. Member
****
Online Online

Activity: 448
Merit: 260



View Profile
July 19, 2023, 10:19:07 AM
 #27

QR code to me is the safest way to scan and send payment since there is no copy and paste to send payment only scan and pay without copying address. QR code is already being designed with rightful address so there's no way to be attacked by any scammer or hacker. Although I can not say with all assurance that it can't be hacked, nowadays things are really happening because scammer are exploring different ways to phish people's funds.
I consider QR code scanning to be a safe mode of payment transfer as there is no option to make a mistake by scanning the QR code or sending the payment to another address. Most of the time we copy the address seen in the case of payment transfer and then send the money to that address but many times due to our little mistake we use the wrong address or some other word in the middle of the address, as a result of which our money goes to someone else's wallet or disappears. Mainly to eliminate this possibility QR code is scanned so that payment can be transferred to 100% correct address. If you have the option to scan the QR code for your payment transfer, you must scan the QR code and transfer the payment.

.
SPIN

       ▄▄▄██████████▄▄▄
     ▄███████████████████▄
   ▄██████████▀▀███████████▄
   ██████████    ███████████
 ▄██████████      ▀█████████▄
▄██████████        ▀█████████▄
█████████▀▀   ▄▄    ▀▀▀███████
█████████▄▄  ████▄▄███████████
███████▀  ▀▀███▀      ▀███████
▀█████▀          ▄█▄   ▀█████▀
 ▀███▀   ▄▄▄  ▄█████▄   ▀███▀
   ██████████████████▄▄▄███
   ▀██████████████████████▀
     ▀▀████████████████▀▀
        ▀▀▀█████████▀▀▀
.
RIUM
.
███
███
███
███
███
███
███
███
███
███
███
███
SAFE GAMES
WITH WITHDRAWALS
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
.
███
███
███
███
███
███
███
███
███
███
███
███
▄▀▀▀











▀▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
SIGN UP


▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▄











▄▄▄▀
satscraper
Hero Member
*****
Offline Offline

Activity: 728
Merit: 1338


Cashback 15%


View Profile
July 19, 2023, 11:10:14 AM
Merited by Becassine (1)
 #28

QR code to me is the safest way to scan and send payment since there is no copy and paste to send payment only scan and pay without copying address. QR code is already being designed with rightful address so there's no way to be attacked by any scammer or hacker. Although I can not say with all assurance that it can't be hacked, nowadays things are really happening because scammer are exploring different ways to phish people's funds.
I consider QR code scanning to be a safe mode of payment transfer as there is no option to make a mistake by scanning the QR code or sending the payment to another address.

Not at all.

Faulty QR readers may result in making mistake and sending payment into wrong address. Besides of that, QR code may be compromised  by malware  sitting on the source device. So it is a good practice to   always check the details of transaction rather than rely on QR code itself.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!