Skip to content
This repository has been archived by the owner on May 16, 2023. It is now read-only.

QR code recovery or more than once use. #665

Open
niz11 opened this issue Jul 20, 2021 · 6 comments
Open

QR code recovery or more than once use. #665

niz11 opened this issue Jul 20, 2021 · 6 comments
Labels
question Further information is requested

Comments

@niz11
Copy link

niz11 commented Jul 20, 2021

The issue was already discussed, but was closed because of: "feature decision".

There must be a way to scan your QR code a second time.
Either through some special PIN associated with the QR or through the users phone number: two steps authentication.

Why again?

  1. The user can easily lose access to his app for various reasons..
  2. QR code are usually not a one time use tool.
  3. Users who deleted their test for various reasons.
@dsarkar
Copy link
Member

dsarkar commented Jul 20, 2021

@niz11 Thanks for your contribution.

  1. I understand that you refer to PCR / RAT test QR codes?
  2. It is currently being investigated how to issue EU test DCC directly to the user (e.g. via email). Such EU DCC certificates (test, vaccination, recovery) can be scanned currently unlimited times and on several devices. This might change in future, i.e. there might be a check and a certificate might be deemed invalid for some reason (e.g. expired).

Corona-Warn-App Open Source Team

@dsarkar
Copy link
Member

dsarkar commented Jul 20, 2021

see comment corona-warn-app/cwa-app-ios#1198 (comment)

@jucktnich
Copy link

I thought about something like this: The user can makes the qrcode scannable again, if he deletes the qrcode from his device

@dsarkar
Copy link
Member

dsarkar commented Jul 20, 2021

@jucktnich The problem I see is the following: If the user was positive and warned others he might do this again from another device. In order to avoid such a situation, if one implemented that a central server keeps track if a user deletes a QR code, so that it can be scanned again when deleted, we weaken bit by bit the decentralised approach.

Of course we will forward this wish-list item again, however, I personally think there is a good compromise already on its way with the EU certificates, which can be scanned unlimited times (unless maybe deemed invalid in a future version of the CWA).


Corona-Warn-App Open Source Team

@jucktnich
Copy link

Ive finally had time to read the documentation and the easiest way would be to generate a qrcode with the registration token and delete it on the old device.

@heinezen heinezen transferred this issue from corona-warn-app/cwa-wishlist Jul 22, 2021
@heinezen heinezen added the question Further information is requested label Jul 22, 2021
@Ein-Tim
Copy link
Contributor

Ein-Tim commented Apr 18, 2022

It should be decided how to proceed here, either answer the question, close the issue as answered (in the comments above) or transform it to a feature request and move to the wishlist.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

5 participants