• 13 Posts
  • 1.17K Comments
Joined 4 months ago
cake
Cake day: June 22nd, 2024

help-circle
    1. Because if you scan it, it is saved into your app and not stored anywhere else. If you take a photo of it, it’s saved into your camera roll, which is a security vulnerability. Same goes for the other party.

    Why should anyone take a camera to take a screenshot or click on ‘save image’? Additionally, the secret key would be stored as well on the messenger app you are using to share the key among the group members.

    1. What is the other party supposed to do when they receive it? They can’t scan their phone screen with their phone camera…?

    Aegis, e.g. can open images containing a QR code and import the key that way. I assume other apps can do the same.







  • Beside it’s inefficient to send text data as an image, why does it make a difference?

    If the app has offers option to open an image with a QR code, IMHO it is more convenient, to send the image of the QR code (I’d try ‘save image as’ instead of a screenshot though). When sending text, you and the recipient manually have to copy the information and the recipient also has to paste it into the right field.









  • A TOTP app basically generates a token based on a secret key. If you share the secret key between the members of your group, any of them is able to generate the token. Maybe it is even possible to register several authenticators with different secret keys, then you would not need to share the key and, if a device gets lost, you could simply remove the compromised key from the list of valid keys.