Signal应用如何在桌面与移动端配对时防范QRLjacking攻击?
Great question—QRLjacking is a sneaky social engineering trick that targets users' trust in QR code pairing workflows, so it makes total sense to look at how Signal locks this down. Let’s break down their key defenses:
双向验证码验证,把扫码变成"请求发起"而非"直接授权"
Signal’s pairing process doesn’t stop at scanning a QR code. When you initiate pairing on desktop, your mobile app will display the desktop device’s name (e.g., "Sarah’s Desktop") and a unique 6-digit verification code. You have to manually enter this code on the desktop to finalize the pairing. Even if an attacker creates a fake pairing QR code, they can’t access this real-time code, so they can’t complete the session link. This turns a single-step trust-based action into a two-factor verification flow that blocks basic QRLjacking attempts.一次性、时效性的配对二维码
Signal generates pairing QR codes that are single-use and short-lived (usually expiring within a few minutes). If the code is scanned (even if pairing isn’t completed) or passes its expiration time, it becomes instantly invalid. Attackers who screenshot or share an old QR code won’t get anywhere—either the code is dead, or it’s already been tied to a legitimate pairing attempt.清晰的配对警示提示
When a pairing request hits your mobile device, Signal pops up a prominent notification that explicitly states: "A device is requesting to pair with your Signal account." It also shows the device type (laptop/desktop) and a rough geographic region (based on IP, no precise location). This forces users to pause and verify: "Did I just start pairing on my own computer?" If not, they can tap "Reject" immediately. Signal also reinforces this in-app and in documentation, reminding users never to scan unknown pairing QR codes.与设备身份强绑定的端到端加密
Even if someone somehow bypassed the above steps (which is extremely unlikely), Signal’s E2EE is tightly bound to each device’s unique identity keys. When a new device pairs, it generates fresh encryption keys that sync only with already trusted devices. An attacker’s unvalidated device can’t access these keys, so even if they managed to initiate a pairing request, they couldn’t decrypt any messages or take over the session.
At its core, Signal’s design takes QR code pairing from a "blind trust" action to a verified, user-driven process. QRLjacking relies on tricking users into granting access with a single scan, but Signal adds that critical second layer of manual verification—making the attack far harder to pull off.
内容的提问来源于stack exchange,提问作者Oleg Dulin

