Greenfrog Computing

Call Us: 01246 520000

sales@greenfrogcomputing.co.uk

  • REMOTE SUPPORT
  • Team
  • Support
  • Security
  • Solutions
  • Infrastructure
  • Industry
  • More
    • About Us
    • Referral Program
    • 3CX
    • Web Design and Development
    • OpenText GroupWise
    • OpenText Filr
    • OpenText Open Enterprise Server
    • Cyber Essentials
    • Testimonials
    • Blog
  • Menu Menu

Tech Insight : QR Codes … A Security Risk?

October 6, 2021/in Technology News/by Greenfrog Computing

In this tech-insight, we take a look at what QR codes are used for, review some well-known security risks, and outline what action you can take to protect yourself from malicious QR codes.

Quick Response (QR) Codes

A QR code is a machine-readable (e.g., by smartphones), matrix barcode invented in 1994 by the Japanese Toyota subsidiary automotive company Denso Wave as a way to track vehicles and parts during the manufacturing process. A QR code stores information as a series of pixels in a square grid that can be read in two directions, top to bottom and right to left.

How They Work

The three large squares outside the QR code show that everything contained inside the square is a QR code. Patterns in QR codes represent binary codes that can be interpreted to reveal the data. The codes can be read using built-in QR scanners or QR apps on smartphones (via the camera), iPads, tablets, and other devices.

Uses

QR codes can store website URLs, phone numbers, or up to 4,000 characters of text. These codes have multiple uses including sales and marketing (e.g. sending information about a business or product), or as a menu (for example) to be sent to a user’s phone. QR codes are also used for linking directly to download an app (Apple App Store or Google Play), postal services tracking, education, authenticating online accounts and verifying login details, accessing Wi-Fi (storing encryption details) sending and receiving payment information. QR codes have also recently been used in coronavirus tracing (apps).

Are They Safe?

QR codes themselves can’t be hacked and QR codes do not collect personally identifiable information, but they do collect other data such as location, the number of times a code has been scanned (at what time), and what operating system (iPhone or Android) is being used. Although this is generally a safe technology, consumer watchdog ‘Which?’ says of QR codes “not all of them are safe.”

Risks

Research (e.g. observations by the Unit 42 threat intelligence team at Palo Alto Networks) indicates that the proliferation of QR codes, particularly during the pandemic (good for ‘no-contact’) has meant that cyber criminals are discussing and exploring ways to exploit them.

Some of the risks associated with QR codes include :

– QR codes can’t be read by humans, so they are unable to see any potential risks just by looking at the code.

– Hackers can create malicious QR codes which direct users to fake websites / phishing websites that capture their personal data.

– Attackers can embed malicious URLs (containing custom malware) into a QR code, which could steal data from a mobile device when scanned.

– Malicious QR codes can be used to add contacts or compose emails on a user’s device, thereby posing security threats.

– Threat actors could present a malicious QR code with the promise of free internet-access, which could actually link to an unsafe Wi-Fi network where hackers could eavesdrop, intercept data, and steal personable identifiable information.

– Malicious QR codes can be used to cover up/replace legitimate QR codes.

Protection

Ways that you can protect yourself from threats posed by the use of malicious QR codes include:

– Only download QR scanning apps from trusted sources e.g., Apple’s App Store or the Google Play Store, and make sure that the app you download is backed by plenty of positive reviews.

– Use a QR scanner that checks that scanned links are safe before submitting any information to you.

– Check to make sure that the QR code you’re about to scan is being presented to you by a reputable source.

– Don’t scan a QR code if you’re not sure where it will lead and preview the website and domain to be sure.

What Does This Mean For Your Business?

QR codes are a convenient, fast, and flexible way to present data but, criminals/cybercriminals are always looking for new ways to operate scams such as phishing, and QR codes represent a possible new scamming opportunity.

Businesses can make sure that their own QR codes haven’t been tampered with or replaced with malicious versions by regularly carrying out integrity checks on their sites and apps (e.g. by scanning the code to check if the link within the QR code is correct). Businesses should also educate staff about how QR codes can be used by cyber criminals, while as individuals we should always use QR scanning apps from reputable sources and be cautious about scanning QR codes in unfamiliar locations and situations. It is also sensible to avoid using public Wi-Fi networks for business generally (without a VPN), and to avoid any ‘free Internet’ offers where there’s a QR code.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
https://www.greenfrogcomputing.co.uk/wp-content/uploads/2021/10/photo-4.jpg 375 500 Greenfrog Computing https://www.greenfrogcomputing.co.uk/wp-content/uploads/2022/08/greenfrog-computing-logo-22-1.png Greenfrog Computing2021-10-06 04:14:522021-10-06 04:14:53Tech Insight : QR Codes … A Security Risk?

Recent Comments

    © Copyright - Greenfrog | Registered in England 04653352 | VAT No. GB 813 689800 | Legal - T&Cs | Cookies & Privacy Policy
    • Link to LinkedIn
    • Link to Facebook
    Link to: Tech News : Amazon To Start Selling Cyber Insurance Link to: Tech News : Amazon To Start Selling Cyber Insurance Tech News : Amazon To Start Selling Cyber Insurance Link to: Featured Article: Domain Security Link to: Featured Article: Domain Security Featured Article: Domain Security
    Scroll to top Scroll to top Scroll to top

    We are using cookies to give you the best experience on our website.

    You can change your consent by clicking Settings.

    Greenfrog Computing
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

    Strictly Necessary Cookies

    Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

    3rd Party Cookies

    This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

    Keeping this cookie enabled helps us to improve our website.