• rockerface 🇺🇦@lemm.ee
    link
    fedilink
    arrow-up
    22
    arrow-down
    1
    ·
    1 day ago

    I mean, generating a one time QR code for login is one thing. It’s the equivalent of a one time password. But a permanent QR code is not that. They still aren’t inherently secure, but they can be used in situations where showing a code in plain text would be just as secure.

    • vaguerant@fedia.io
      link
      fedilink
      arrow-up
      7
      ·
      1 day ago

      Yeah, my language was overly broad. You can use QR codes as part of a system where the security is going on elsewhere, but the integrity of the QR code itself isn’t something that can be relied on for security.