Better (and more secure) QR code login flow
Here's a simple way to massively reduce QR code scams. Open a network port on the mobile device, and if the computer that's trying to log in sends specific data to that mobile device.
Here's the thing: If they made it so they ping local addresses, the computer can't connect to the phone. If the phone doesn't receive a ping, it can't register it.
From there, simply add a little bit of text that says "Connect your phone to the same network as the computer".
For backwards compatibility, show a little option on mobile to enable any logins, for those in Cellular networks. Add a bit of giant text that warns the user of potential scams then maybe geo-lock it to the same country. These little extra steps should help prevent these sorts of things from happening
Please sign in to leave a comment.
Comments
0 comments