QR Scanners Beware
A recent article on Dark Reading[1] by Ericka Chickowski discusses some potential for malware in those square QR barcodes that are becoming popular. Because the scanner software you’ve loaded on your droid or iPhone often takes you straight to the website encoded in the QR barcode, attackers are using this technology to load malware on your smartphone.
Ideally you’d like your scanner application to show you the encoded link and give you the option to cancel the action before taking you to the new location.
A real financial problem is also on the horizon because PayPal and other mobile payment systems are looking at QR Barcodes for making payments more convenient.
The last paragraph is the real take-away from the article:
“Only use QR code reader software that allows the user to confirm the action to be taken — i.e. visit a website link,” Henry says. “If you do not know and trust the link, cancel the action.”
As Sgt. Phil Esterhaus use to say on Hill Street Blues: “Let’s be careful out there“[2]
Links in this post:
[1] http://www.darkreading.com/mobile-security/167901113/security/news/232301147/qr-code-malware-picks-up-steam.html
[2] http://www.youtube.com/watch?v=T2QApwtE8zQ