Table of Contents
QR Codes are Everywhere!
Lately, everyone has been talking about QR codes and the potential risks they could pose when it comes to security. QR codes can be found everywhere, on your ceilings, inside your walls (it’s probably living there!) and probably on the insides of your shoes.
Jokes aside, for those who don’t know, QR codes are another way of accessing URLs and have been very common on business cards, connecting to your Wi-Fi directly (most access points come with these now) and for authentication services like 2FA and MFA through an app i.e. Microsoft Authenticator.
Potential Risks of QR Codes
While QR codes could be used for malicious purposes, the URL needs to be available for the compromise to happen. If the URL has already been taken down, the risk clearly will be removed. The below risks are just to inform you of the potential risks.
People Just Scans Them
Everyone tends to scan QR codes whenever they see them. Curious users will scan any QR code without thinking of the risks hence why there is a security risk. Much like how we’ve trained users to be vigilant with URLs, we need to do the same with QR codes.
Hard to Miss
Since barcodes can be seen everywhere, it’s hard not to have the urge to scan them. Business cards, letters, online advertisements, and billboards, both physical and digital can use them. While the majority will be for legitimate businesses, some formats, especially digital/online formats may be set up by attackers to trick you into giving away your personal information.
Social Engineering
Anyone can pretend to be a legitimate business or a person trying to get business. Attackers may use social engineering to trick you into visiting a website riddled with malware. Online QR is also very easy to create through QR code generators which are vast across the web.
Protect Yourself
Check the Link
You must always check the link the QR code is sending you before going to the website. Android Smartphones tend to show the URL and get you to click on it manually. However, if it’s done automatically, please be extra careful and consider turning this feature off for your safety, if possible.
It may also be worth checking the company independent from the URL shown on the barcode to find out if it’s a legitimate business. If still unsure, ask somebody you trust to look at the URL for you for a second opinion.
Keep Anti-Viruses and Software Updated
Similarly, having up-to-date software and antivirus protection can go a long way. Consider installing a mobile-based antivirus to gain another layer of defence. Further protection can also be achieved by using a secure and recognised mobile browser, like Edge, Firefox or Chrome.
Oops, I scanned it!
If you do happen to visit a malicious QR code page, be sure to scan your mobile/computer device for potential malware through an antivirus. Be sure to ask for help from someone you trust if you don’t know how to do this. Similarly, if you work in an office, make sure to report it immediately to a team you know can assist you with malware or security issues.
Report the URL
As with phishing websites, make others aware of the link by reporting it to the NCSC and of course, don’t enter your details into a website, unless you know it’s genuine and safe. Make sure to get a second look otherwise you may be out of luck!
Stay Vigilant
Always remember to stay vigilant of URLs before clicking or visiting them, especially if from an unexpected source. When in doubt, always make sure to ask for a second opinion, whether from a relative or a friend you work with.
I hope you enjoyed today’s post – my aim with these posts is to give you the best advice on how to protect yourself. While I try to cover the advice in as much detail as possible, I may have missed something. If you feel it needs to be mentioned, please don’t hesitate to post them in the comments below!
Please also consider donating to my blog via the BuyMeACoffee button at the bottom of the page – all donations are highly appreciated and all funds go towards supporting what I do.