@considermycat Exactly this. 💯
Per Axbom
@callisto Ha ha, well put.
@h5e @ansuz Yes, and in the case of the queuing system I mention, they use a 3rd party provider so the app provider url is something completely different than the care provider url... and this still doesn't make people think twice.
And don't get me started on payment gateway urls... people just trust any form fields where your credit card number is asked for.
@DrVeronikaCH I actually haven't, but I've had it recommended to me before! Will add it to my Kobo reader 😊
It's called quishing when a criminal gets you on the hook via a QR code and you hand over personal information such as credit card details, passwords and your home address.
There are many hooks in our everyday environment today.
QR codes are found in hotels, gas stations, museums, restaurants, medical centers and many other places you trust. It takes a second for a criminal to cover a QR code with his own sticker. How would you tell the difference?
Via the fake QR code you are guided through a flow that feels like what you expect. It's just controlled by someone with nefarious intent.
The German magazine Auto Motor Sport reported earlier this week about how this affects gas stations. https://per.ax/autoqr
Imagine scanning a QR code at a charging station to start charging your electric car. You enter your credit card details and press start. But the charging doesn’t start. Because you just gave your card details to a criminal who put their own QR code sticker on the charging station.
A clever criminal will perhaps display an error message on the web page and redirect you to the real supplier, enabling you to start charging for real. In which case you may not even notice that money is being covertly withdrawn from your account until much later... or blame the charging supplier who is completely unaware...
But of course it doesn't just affect charging stations. It can happen anywhere.
Queuing systems at sampling locations increasingly rely on QR codes here in Sweden. Let's say a criminal covers this code with their own. You will arrive at a page that asks if you want to join the queue or pay the patient fee of 50 kronor in advance. You may know that you do not have to pay a patient fee. But does everyone know that? Maybe some will bite and pay.
If you join the queue, you will be directed to the correct queue. So not much to react to. And if you have paid the 50 kronor, you will then also be led to the correct queue.
The fake QR code can therefore go undetected for a long time.
As a company, do you know if someone perhaps has already covered your code and is quietly using it to create intermediate flows that steal personal data, or money? Do you have routines to check this? In some places, fake QR codes may live on year in and year out. Like a dripping data leak.
QR codes are in many cases a really, really bad idea from a security and privacy perspective. And it can be a real setback for your brand if people are duped on your premises. Or on your products.
So, do you encourage people to scan, or do you warn?
If I see a QR code in everyday life, I also see many ways to intercept and abuse it.
How did this vulnerability appear just about everywhere? It's as if QR codes have completely gone under the radar of security departments.
I will restructure this post for my blog/newsletter later, but didn't want to wait with my warning, after seeing the clear example from charging stations.
@steveportigal Incredible. Had not expected it to be this good.
Quishing kallas det när en brottsling får dig på kroken via en QR-kod och du lämnar ifrån dig personliga uppgifter som kreditkort, lösenord och hemadress.
Det finns idag hur många krokar som helst i vår omvärld.
QR-koder finns på hotell, tankstationer, museum, restauranger, vårdcentraler och många andra platser du litar på. Det tar en sekund för en brottsling att täcka över en sådan QR-kod med sitt eget klistermärke. Hur ska du se skillnad?
Via QR-koden leds du sedan genom ett flöde som känns som det du förväntar dig. Det styrs bara av någon annan.
Computer Sweden skrev igår om att detta drabbar laddstationer.
Tänk att du skannar en QR-kod på en laddstation för att starta laddningen på din elbil. Du matar in dina kreditkortsuppgifter och trycker på starta. Men laddningen startar inte. För du har precis gett kortuppgifterna till en brottsling som klistrade sin egen QR-kod på laddstationen.
En klurig brottsling visar ett felmeddelande på webbsidan och pekar om dig till den riktiga leverantören av el, så att du får igång laddningen. Då kanske du inte ens märker att pengar dras i lönndom förrän långt senare… eller börjar bråka på laddföretaget som är helt ovetande...
Men det drabbar förstås inte bara laddstationer. Det kan hända var som helst.
Kösystemen på provtagningcentraler förlitar sig allt oftare på QR-koder. Låt säga att en brottsling klistrar över den med sin egen kod. Du kommer till en sida som frågar om du vill ställa dig i kön eller betala patientavgiften på 50kr i förväg. Du kanske vet att att du inte ska betala patientavgift. Men vet alla det? Kanske några tycker det låter smidigt att göra det.
Om du ställer dig i kö så leds du till den rätta kön. Alltså inte så mycket att reagera på. Och har du betalat 50kr så leds du sedan också till den korrekta kön.
Den falska QR-koden kan alltså sitta där länge utan att någon märker det.
Vet du som företag om någon har klistrat över din kod redan och skapar ett “mellan-flöde” för att stjäla personuppgifter, eller pengar? Har du rutiner för att kolla det? På vissa platser sitter kanske falska QR-koder år ut och år in. Som en droppande dataläcka.
QR-koder är så dumt så dumt ur ett säkerhets- och integritetsperpektiv. Och det kan bli ett rejält bakslag för ditt varumärke om människor blir lurade i dina lokaler. Eller på dina produkter.
Så, uppmuntrar du personer att skanna, eller varnar du?
Förra året beskrev jag i mitt nyhetsbrev hur det här skulle kunna funka på ett hotell där man ska skanna en kod för att boka frukosttid. https://per.ax/qrhotell
Kort sagt: ser jag en QR-kod i vardagen så ser jag också många sätt genskjuta och missbruka den.
Hur blev det så här sårbart, precis överallt? Det är som om QR-koder helt gått under radarn på alla säkerhetsavdelningar.
Jag kommer strukturera upp det här inlägget till bloggen/nyhetsbrevet, men ville inte vänta med att varna nu när det fanns ett så tydligt exempel.
Watching Good Will Hunting for the first time. Yup, the first time.
Well, I loved it. I feel like films aren’t made like this anymore. The dialogue is some of the best I’ve experienced in a long time. Sure, some of it is certainly dated, but it came out 27 years ago.
As a Robin Williams fan it’s kind of wild for me to have missed seeing it for all these years.
@jon I do appreciate this perspective as well. Perhaps it’s about finding the right words. I obviously put these thoughts out there to gather how others reason. I’ve been reacting a lot lately to expressions of “good” use disregarding any second or third order thinking.
Not sure I would agree it’s absolutist though, for me it’s about choosing to weigh in impact beyond immediate personal benefits and reasoning around them.
The question of “useful” always for me ends up at needing to understand useful for who, at who’s expense? And from there: is it worth it? Perhaps, for many it, is. A great many people of course have no awareness at all of the harm, in my experience.
I’d also emphasize that I am adressing the modern flavor of generative AI, rather than all the many flavors of machine automation. For translation, transcription and similar applications – within a dominant language – I’d argue that large language models are incredibly useful. For many other applications it’s both deceptive and harmful, even ones where it’s argued they provide value. And so, I have to reason around if the positive applications are worth the many and varied costs, and hence can be considered good applications for the goals they help achieve (goals which likely can be arrived at in many other ways as well).
Clearly I’m concerned when the primary beneficiaries are those who are already well-off, and the sufferers are those who are subjected to exploitation time and time again. Much of the generative AI world amplifies this arrangement. Perhaps it’s unfair of me to judge someone’s experience of useful and good under this light, but I’m having a really hard time accepting those conclusions when they risk exacerbating harm…
I’m going to give this some more thought and work it into some writing on my blog… thanks for offering objection, and sorry about a wall of unfinished pondering - much of how I reasoned was perhaps obvious.
@LeoR1010 Älskar den här matchen!
@highvizghilliesuit True. Though I feel for example the exploitation of cheap and underage labor has spun out of control. And general awareness about all these issues is higher. So then it becomes a question of balance, scale, opting for one methodology over another.
"Cool, I found a good use for AI, this tech can really save time!"
If you're arguing that generative AI has both good and bad applications, but your main reasons for finding it positive is that you found some personally useful applications - for example formatting or summarising content - I don't feel you're considering enough what the concepts of good or bad entail.
I'd argue that the definition of good is not that it benefits you at the same time as many others are harmed.
If your personal benefit, formatting content much faster than before, comes at the expense of escalating carbon costs, unregulated child labour in hazardous mines and PTSD amongst AI gig workers, I would argue that calling this feature "good" is a stretch.
The bigger picture is a hassle to consider but I don't see how it could responsibly be ignored.
Lagfinalen i bordtennis är klockan 15. 🏓
@creative_xl8 @hsorlie Thanks. I can also suggest these two posts for more references. It's obviously a bit much for a 5-10 minutes presentation but might provide some new ideas and arguments.
The Elements of AI Ethics
https://axbom.com/aielements/
AI responsibility in a hyped-up world
https://axbom.com/ai-responsibility/
If one ever wants to dig deeper there's also my collection of 3,000+ articles 😅:
https://raindrop.io//digital-ethics-6334413
https://raindrop.io/axbom/digital-ethics-6334413
Viktig läsning!
I Elementen inom AI-etik kallar jag detta för 'osynligt beslutsfattande':
More calls to slow down.
"Creativity is the labour, not the output."
@datarama I think you’re onto something here. Hygge is an excellent example. One big clue is that essentially all books written on ikigai are written by non-Japanese. All the blogs and youtube video you find will be from non-Japanese people. Because the Japanese haven’t seen any need to write a book about something a word that is used in common language every day to just mention something that you love to do and makes your life worthwhile. There is no deeper philosophy hidden there.
The reason the podcast may be worth listening to is because it’s just interviews with people doing cool things and finding meaning in this. It overlaps with wellbeing and mindfulness, far from having “what you can get paid for” as a prerequisite. 😁
Every time I see someone write about the westernized misrepresentation of Ikigai, I sigh. Because it’s of course been blended up with capitalism and hyperbole to become essentially a sales pitch.
Ikigai, to the Japanese, was never about what you can get paid for. Taking care of your grandkids can also be your Ikigai. The stuff you do after work can be your Ikigai. And it changes over time. To me it feels like western thinking really pollutes a lot of beautiful insight and opportunity.
Also, Ikigai is not a Venn diagram.
To be fair, if that framework is helpful to you and inspires you, by all means use it. But it’s not Ikigai. Catching up with your friends can be.
If you’re curious about what Ikigai means to the Japanese, give The Ikigai Podcast a chance: https://ikigaitribe.com/podcasts/ – It’s a series of interviews with Japanese professors, authors, experts, and people living their ikigai.