@considermycat Exactly this. đŻ
@callisto Ha ha, well put.
@h5e @ansuz Yes, and in the case of the queuing system I mention, they use a 3rd party provider so the app provider url is something completely different than the care provider url... and this still doesn't make people think twice.
And don't get me started on payment gateway urls... people just trust any form fields where your credit card number is asked for.
@DrVeronikaCH I actually haven't, but I've had it recommended to me before! Will add it to my Kobo reader đ
It's called quishing when a criminal gets you on the hook via a QR code and you hand over personal information such as credit card details, passwords and your home address.
There are many hooks in our everyday environment today.
QR codes are found in hotels, gas stations, museums, restaurants, medical centers and many other places you trust. It takes a second for a criminal to cover a QR code with his own sticker. How would you tell the difference?
Via the fake QR code you are guided through a flow that feels like what you expect. It's just controlled by someone with nefarious intent.
The German magazine Auto Motor Sport reported earlier this week about how this affects gas stations. https://per.ax/autoqr
Imagine scanning a QR code at a charging station to start charging your electric car. You enter your credit card details and press start. But the charging doesnât start. Because you just gave your card details to a criminal who put their own QR code sticker on the charging station.
A clever criminal will perhaps display an error message on the web page and redirect you to the real supplier, enabling you to start charging for real. In which case you may not even notice that money is being covertly withdrawn from your account until much later... or blame the charging supplier who is completely unaware...
But of course it doesn't just affect charging stations. It can happen anywhere.
Queuing systems at sampling locations increasingly rely on QR codes here in Sweden. Let's say a criminal covers this code with their own. You will arrive at a page that asks if you want to join the queue or pay the patient fee of 50 kronor in advance. You may know that you do not have to pay a patient fee. But does everyone know that? Maybe some will bite and pay.
If you join the queue, you will be directed to the correct queue. So not much to react to. And if you have paid the 50 kronor, you will then also be led to the correct queue.
The fake QR code can therefore go undetected for a long time.
As a company, do you know if someone perhaps has already covered your code and is quietly using it to create intermediate flows that steal personal data, or money? Do you have routines to check this? In some places, fake QR codes may live on year in and year out. Like a dripping data leak.
QR codes are in many cases a really, really bad idea from a security and privacy perspective. And it can be a real setback for your brand if people are duped on your premises. Or on your products.
So, do you encourage people to scan, or do you warn?
If I see a QR code in everyday life, I also see many ways to intercept and abuse it.
How did this vulnerability appear just about everywhere? It's as if QR codes have completely gone under the radar of security departments.
I will restructure this post for my blog/newsletter later, but didn't want to wait with my warning, after seeing the clear example from charging stations.
@steveportigal Incredible. Had not expected it to be this good.
Quishing kallas det nÀr en brottsling fÄr dig pÄ kroken via en QR-kod och du lÀmnar ifrÄn dig personliga uppgifter som kreditkort, lösenord och hemadress.
Det finns idag hur mÄnga krokar som helst i vÄr omvÀrld.
QR-koder finns pÄ hotell, tankstationer, museum, restauranger, vÄrdcentraler och mÄnga andra platser du litar pÄ. Det tar en sekund för en brottsling att tÀcka över en sÄdan QR-kod med sitt eget klistermÀrke. Hur ska du se skillnad?
Via QR-koden leds du sedan genom ett flöde som kÀnns som det du förvÀntar dig. Det styrs bara av nÄgon annan.
Computer Sweden skrev igÄr om att detta drabbar laddstationer.
TÀnk att du skannar en QR-kod pÄ en laddstation för att starta laddningen pÄ din elbil. Du matar in dina kreditkortsuppgifter och trycker pÄ starta. Men laddningen startar inte. För du har precis gett kortuppgifterna till en brottsling som klistrade sin egen QR-kod pÄ laddstationen.
En klurig brottsling visar ett felmeddelande pÄ webbsidan och pekar om dig till den riktiga leverantören av el, sÄ att du fÄr igÄng laddningen. DÄ kanske du inte ens mÀrker att pengar dras i lönndom förrÀn lÄngt senare⊠eller börjar brÄka pÄ laddföretaget som Àr helt ovetande...
Men det drabbar förstÄs inte bara laddstationer. Det kan hÀnda var som helst.
Kösystemen pÄ provtagningcentraler förlitar sig allt oftare pÄ QR-koder. LÄt sÀga att en brottsling klistrar över den med sin egen kod. Du kommer till en sida som frÄgar om du vill stÀlla dig i kön eller betala patientavgiften pÄ 50kr i förvÀg. Du kanske vet att att du inte ska betala patientavgift. Men vet alla det? Kanske nÄgra tycker det lÄter smidigt att göra det.
Om du stÀller dig i kö sÄ leds du till den rÀtta kön. AlltsÄ inte sÄ mycket att reagera pÄ. Och har du betalat 50kr sÄ leds du sedan ocksÄ till den korrekta kön.
Den falska QR-koden kan alltsÄ sitta dÀr lÀnge utan att nÄgon mÀrker det.
Vet du som företag om nĂ„gon har klistrat över din kod redan och skapar ett âmellan-flödeâ för att stjĂ€la personuppgifter, eller pengar? Har du rutiner för att kolla det? PĂ„ vissa platser sitter kanske falska QR-koder Ă„r ut och Ă„r in. Som en droppande datalĂ€cka.
QR-koder Àr sÄ dumt sÄ dumt ur ett sÀkerhets- och integritetsperpektiv. Och det kan bli ett rejÀlt bakslag för ditt varumÀrke om mÀnniskor blir lurade i dina lokaler. Eller pÄ dina produkter.
SĂ„, uppmuntrar du personer att skanna, eller varnar du?
Förra Äret beskrev jag i mitt nyhetsbrev hur det hÀr skulle kunna funka pÄ ett hotell dÀr man ska skanna en kod för att boka frukosttid. https://per.ax/qrhotell
Kort sagt: ser jag en QR-kod i vardagen sÄ ser jag ocksÄ mÄnga sÀtt genskjuta och missbruka den.
Hur blev det sÄ hÀr sÄrbart, precis överallt? Det Àr som om QR-koder helt gÄtt under radarn pÄ alla sÀkerhetsavdelningar.
Jag kommer strukturera upp det hÀr inlÀgget till bloggen/nyhetsbrevet, men ville inte vÀnta med att varna nu nÀr det fanns ett sÄ tydligt exempel.
Watching Good Will Hunting for the first time. Yup, the first time.
Well, I loved it. I feel like films arenât made like this anymore. The dialogue is some of the best Iâve experienced in a long time. Sure, some of it is certainly dated, but it came out 27 years ago.
As a Robin Williams fan itâs kind of wild for me to have missed seeing it for all these years.
@jon I do appreciate this perspective as well. Perhaps itâs about finding the right words. I obviously put these thoughts out there to gather how others reason. Iâve been reacting a lot lately to expressions of âgoodâ use disregarding any second or third order thinking.
Not sure I would agree itâs absolutist though, for me itâs about choosing to weigh in impact beyond immediate personal benefits and reasoning around them.
The question of âusefulâ always for me ends up at needing to understand useful for who, at whoâs expense? And from there: is it worth it? Perhaps, for many it, is. A great many people of course have no awareness at all of the harm, in my experience.
Iâd also emphasize that I am adressing the modern flavor of generative AI, rather than all the many flavors of machine automation. For translation, transcription and similar applications â within a dominant language â Iâd argue that large language models are incredibly useful. For many other applications itâs both deceptive and harmful, even ones where itâs argued they provide value. And so, I have to reason around if the positive applications are worth the many and varied costs, and hence can be considered good applications for the goals they help achieve (goals which likely can be arrived at in many other ways as well).
Clearly Iâm concerned when the primary beneficiaries are those who are already well-off, and the sufferers are those who are subjected to exploitation time and time again. Much of the generative AI world amplifies this arrangement. Perhaps itâs unfair of me to judge someoneâs experience of useful and good under this light, but Iâm having a really hard time accepting those conclusions when they risk exacerbating harmâŠ
Iâm going to give this some more thought and work it into some writing on my blog⊠thanks for offering objection, and sorry about a wall of unfinished pondering - much of how I reasoned was perhaps obvious.
@LeoR1010 Ălskar den hĂ€r matchen!
@highvizghilliesuit True. Though I feel for example the exploitation of cheap and underage labor has spun out of control. And general awareness about all these issues is higher. So then it becomes a question of balance, scale, opting for one methodology over another.
"Cool, I found a good use for AI, this tech can really save time!"
If you're arguing that generative AI has both good and bad applications, but your main reasons for finding it positive is that you found some personally useful applications - for example formatting or summarising content - I don't feel you're considering enough what the concepts of good or bad entail.
I'd argue that the definition of good is not that it benefits you at the same time as many others are harmed.
If your personal benefit, formatting content much faster than before, comes at the expense of escalating carbon costs, unregulated child labour in hazardous mines and PTSD amongst AI gig workers, I would argue that calling this feature "good" is a stretch.
The bigger picture is a hassle to consider but I don't see how it could responsibly be ignored.
Lagfinalen i bordtennis Ă€r klockan 15. đ
@creative_xl8 @hsorlie Thanks. I can also suggest these two posts for more references. It's obviously a bit much for a 5-10 minutes presentation but might provide some new ideas and arguments.
The Elements of AI Ethics
https://axbom.com/aielements/
AI responsibility in a hyped-up world
https://axbom.com/ai-responsibility/
If one ever wants to dig deeper there's also my collection of 3,000+ articles đ
:
https://raindrop.io//digital-ethics-6334413
https://raindrop.io/axbom/digital-ethics-6334413
Viktig lÀsning!
I Elementen inom AI-etik kallar jag detta för 'osynligt beslutsfattande':
More calls to slow down.
"Creativity is the labour, not the output."
@datarama I think youâre onto something here. Hygge is an excellent example. One big clue is that essentially all books written on ikigai are written by non-Japanese. All the blogs and youtube video you find will be from non-Japanese people. Because the Japanese havenât seen any need to write a book about something a word that is used in common language every day to just mention something that you love to do and makes your life worthwhile. There is no deeper philosophy hidden there.
The reason the podcast may be worth listening to is because itâs just interviews with people doing cool things and finding meaning in this. It overlaps with wellbeing and mindfulness, far from having âwhat you can get paid forâ as a prerequisite. đ
Every time I see someone write about the westernized misrepresentation of Ikigai, I sigh. Because itâs of course been blended up with capitalism and hyperbole to become essentially a sales pitch.
Ikigai, to the Japanese, was never about what you can get paid for. Taking care of your grandkids can also be your Ikigai. The stuff you do after work can be your Ikigai. And it changes over time. To me it feels like western thinking really pollutes a lot of beautiful insight and opportunity.
Also, Ikigai is not a Venn diagram.
To be fair, if that framework is helpful to you and inspires you, by all means use it. But itâs not Ikigai. Catching up with your friends can be.
If youâre curious about what Ikigai means to the Japanese, give The Ikigai Podcast a chance: https://ikigaitribe.com/podcasts/ â Itâs a series of interviews with Japanese professors, authors, experts, and people living their ikigai.