Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That seems particularly open to abuse.

Couldn't I just link someone to a copy of the QR code and be automagically logged in as them?



It raises an approval screen on the phone. It says

By proceeding, you give another computer access to the following accounts: * [email protected]

STOP! Only proceed if you arrived at this page by scanning a login barcode at google.co. Otherwise, do not proceed!

(start with GMail) (start with iGoogle)


Ah, I see. Thanks for adding that info


There's a bright highlighted warning that says "STOP! Only proceed if you arrived this page by scanning a login barcode at google.com. Otherwise, do not proceed!"

Will users read the warning? I would—and did—it really grabs your attention given the fact its background is yellow and takes up so much of the iPhone screen.

I suppose there are probably other safeguards as well, given that this is Google—maybe timed expiration?


I left the page open and after finished reading comments (a minute or two) in HN, the page gave me this popup dialog:

[Alert] Login session has expired. Press Ok to reload.


This + 2 Factor-Authentication = Pretty Damn Secure.


but those two are different things. They are not complimentry (from what i understand)


I assume it is valid for only a short period like the code generated from the Google Authenticator app.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: