this post was submitted on 26 Sep 2026
49 points (94.5% liked)
Linux
67794 readers
678 users here now
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Rules
- Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
- No misinformation
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
founded 7 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
So it's leaking information about your system to an external site?
That's just what we need.
The theory is that the site just hosts a small JS snippet that locally decodes and shows you your logs.
But yeah, now that you mention it, it would be trivial for the site to get and store the logs, and you wouldn't even notice.
Oh I see. If the URL puts the sensitive information after the anchor, like
https://example.com/bsod#sensitive-info-goes-herethen the browser would never send that part to the server. Everything after the anchor is just used locally by the browser to scroll the page to a specific place (or in this case for the javascript to read and process).You'd need to check every time you scan a QR code though that the
#is in the URL and it's not malformed. Trivially replacing the#with a?would turn the private URL into one that sends all the data in theGETrequest. It's training users to do something risky.Oh and it also assumes that the javascript hasn't been tampered with to upload the data somewhere.
I don't like it.
It's possible to use QR code reader apps that do not automatically go to the WWW.
But who's going to go to that effort on their slab of glass?
I agree that the whole concept of QR code scanning is problematic.
Those who would like to make extra sure their data stays private. On an unrelated note, what kinds of data could be considered confidential in said log?
Yes, well, exactly. You know not every question is a literal question, right?
I was wondering that myself. It's "the kmsg log", something to do with kernel mode switching or "graphics". My guess: the log itself is not problematic, but there might be some metadata added. Or then one creates that metadata by submitting the QR code.
I use URLChecker on Android as my default browser so I can inspect any kind of link before opening it. It's the most useful tool I've found on mobile.
No.
Scanning the QR code (on a different device presumably) might do that though.
It's kinda what QR codes do.
But I agree, it's not a good idea. Because people will scan that code and let their slabs of glass do their thing.