← Back to context

Comment by bigfishrunning

3 hours ago

So people scan a QR code, and then enter a secure banking pin? this sounds like a security problem waiting to happen...

The QR code doesn't open a link. It's just "gibberish" text only usable by app that can understand it (e.g. banking apps).

(I don't know anything about UPI, but in Indonesia we use a similar system)

  • Its not gibberish text.

    Its just a URI.

      upi://pay?pa=payeeID&pn=payeeName
    

    You can add things like &am= to prefill the amount. Merchant txns have reference IDs and all that stuff.

  • I am Indian and I think what you are saying is correct. It opens up the banking app or in our case UPI providers app so like Google pay, Phonepe,paytm, Bhim UPI and other such apps.