Hacker News new | ask | show | jobs
by sidewndr46 669 days ago
Can you explain more about this QR code scam?
2 comments

My understanding (which may be incorrect) is this:

On the login page of the web version of Discord, you have the option to log in in two ways: either by using a username/password combination, or by scanning a QR code with the Discord app on your mobile.

The QR code is linked to your desktop session, and scanning the QR code with a mobile device will cause Discord to authenticate the desktop session with the credentials stored on the mobile.

Thus, if the attackers take one of the QR codes from their own desktop session and give it to you, scanning it will authenticate their desktop session with your credentials.

The QR codes have a rotating code that's meant to prevent old QR codes from being used, but that only means that the attackers just need to re-request the QR code every so often and show the new one.

If I'm reading GP right: there is a QR code displayed prominently on Discord login screen, which is an image. Opening the link on a phone that is also logged into Discord skips everything and completes login process. That QR code can be sent to a victim under false pretense for account takeover?