<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Arrrre QR codes threats? in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39315#M91</link>
    <description>&lt;P&gt;Aye, matey, there be QR codes that can tear the VPN out of your firewall like a shark going after a bucket o' guts!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've taken to posting my details in a QR code on the first slide of my presentations, as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Rob Slade qrcode.png" style="width: 200px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4703iAC90A98E5B36FD32/image-size/large?v=v2&amp;amp;px=999" role="button" title="Rob Slade qrcode.png" alt="Rob Slade qrcode.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oddly, when people find out I am a malware researcher, nobody actually scans the code ...&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2020 21:51:22 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2020-09-15T21:51:22Z</dc:date>
    <item>
      <title>Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39311#M90</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is an interesting topic, everyone uses QR codes - can they be malicious?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatpost.com/qr-codes-menu-security-concerns/159275/" target="_blank" rel="noopener"&gt;https://threatpost.com/qr-codes-menu-security-concerns/159275/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute-cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:38:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39311#M90</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T09:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Arrrre QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39315#M91</link>
      <description>&lt;P&gt;Aye, matey, there be QR codes that can tear the VPN out of your firewall like a shark going after a bucket o' guts!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've taken to posting my details in a QR code on the first slide of my presentations, as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Rob Slade qrcode.png" style="width: 200px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4703iAC90A98E5B36FD32/image-size/large?v=v2&amp;amp;px=999" role="button" title="Rob Slade qrcode.png" alt="Rob Slade qrcode.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oddly, when people find out I am a malware researcher, nobody actually scans the code ...&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 21:51:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39315#M91</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-09-15T21:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: Arrrre QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39316#M92</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;they could be a little cautious - especially I wonder that COVID-19 code will take me when I register at a shop?&amp;nbsp; Does your QR code take people's devices to /dev/null or to the Dark Web to an obscure place?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we verify a QR safely without compromise?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there tools available in portable mode, so one does not compromise oneself?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 22:05:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39316#M92</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-09-15T22:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39318#M93</link>
      <description>&lt;P&gt;The biggest issue I have seen with QR codes and for that matter link shorteners like bit.ly is that today they could go to a legitimate site and tomorrow they could point you to malware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Be very careful....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 01:24:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39318#M93</guid>
      <dc:creator>Radioteacher</dc:creator>
      <dc:date>2020-09-16T01:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39319#M94</link>
      <description>&lt;P&gt;I read recently that you can add a + sign to the end of a bit.ly link, and it will preview the link safely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://bit.ly/1sNZMwL+" target="_blank" rel="noopener"&gt;https://bit.ly/1sNZMwL+&lt;/A&gt;, for example (and it should point to the Bitly Wikipedia article)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can't say the same for QR codes, however...&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 02:20:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/39319#M94</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2020-09-16T02:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/48924#M443</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This subject has come up previously, now they are being used to entice people to scan for their parking meters, what is next Vaccine passports?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bitdefender.com/blog/hotforsecurity/us-police-parking-meters-phishing-qr-codes" target="_blank"&gt;https://www.bitdefender.com/blog/hotforsecurity/us-police-parking-meters-phishing-qr-codes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 22:37:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/48924#M443</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-01-05T22:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49100#M454</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well time has caught up and now QR codes are used for verification purposes on COVID-19 vaccine passports and many other items these days.&amp;nbsp; They are now being exploited, so perhaps some practical ways to identify whether it is safe or not to scan?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cnet.com/tech/services-and-software/qr-code-scams-are-on-the-rise-heres-how-to-avoid-getting-duped/?ServiceType=linked_in_page&amp;amp;ftag=COS-05-10aaa0d&amp;amp;UniqueID=16BCAA0C-7478-11EC-8344-1DF115F31EAE&amp;amp;PostType=link&amp;amp;TheTime=2022-01-13T13:52:46" target="_blank"&gt;https://www.cnet.com/tech/services-and-software/qr-code-scams-are-on-the-rise-heres-how-to-avoid-getting-duped/?ServiceType=linked_in_page&amp;amp;ftag=COS-05-10aaa0d&amp;amp;UniqueID=16BCAA0C-7478-11EC-8344-1DF115F31EAE&amp;amp;PostType=link&amp;amp;TheTime=2022-01-13T13:52:46&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think we are going to avoid, this unless better means of verification and ensuring the QR Code is strictly limited and authorised via key management for instance and digital identity systems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 04:07:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49100#M454</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-01-14T04:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49115#M455</link>
      <description>&lt;P&gt;No, the code itself is not a threat.&amp;nbsp; However, the QR app on your phone may be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see little risk in&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;*scanning&lt;/STRONG&gt;&lt;/EM&gt;* the code.&amp;nbsp; Fundamentally, a QR code is just a text string with a funky encoding. I can read anything without dying (buffer overflows not withstanding).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The danger comes about when the QR app decides to automatically take action after the scan... be that interpreting the text as HTML, opening a URL in a browser or passing it off to the WiFi Settings page.&amp;nbsp; Before doing anything with the "input", it needs to perform a series of validation checks (highlighting oddball/risky characters, checking cert authenticity, showing the text to the user, etc.), only if everything looks OK and after the user authorizes the action should the input be passed anywhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Also merchants need to earn the customer's trust by using URLs with official hostnames and clear/concise/meaningful arguments.&amp;nbsp; &amp;nbsp;For example:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Trustworthy:&amp;nbsp;&amp;nbsp;&lt;A href="https://parking.austin.tx/payments?meter=78342" target="_blank" rel="noopener"&gt;https://parking.austin.tx/payments?meter=78342&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Questionable: &lt;A href="https://payments-r-us.com/austin/78342" target="_blank" rel="noopener"&gt;https://payments-r-us.com/austin/78342&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Not gonna do it: &lt;A href="https://bit.ly/DeeFXR6t3" target="_blank" rel="noopener"&gt;https://bit.ly/DeeFXR6t3&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 14 Jan 2022 20:38:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49115#M455</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2022-01-14T20:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49119#M456</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;Interesting point of view - however the action of scanning the code, most people automatically assume it will take them to the destination expected.&amp;nbsp; We are lulled into a false sense of security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it comes down to the developers again, with good SDLC with security &amp;amp; privacy by design principles?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Who verifies and checks the developers or as most assume it is secure and trusted - security awareness to the fore again?&amp;nbsp; There is no legislation to support this approach, although USA is thinking about it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trust, but verify - but often these are rushed out the door by the requestor i.e. organisation, government etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jan 2022 05:31:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49119#M456</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-01-15T05:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49125#M457</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;... the action of scanning the code, most people automatically assume it will take them to the destination expected....&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Agreed.&amp;nbsp; Pretty much the same problem as "homonym" URLS (e.g. chase-bank.com instead of chase.com). The first defense may be slowing bad actors from doing bad things, but that is not enough.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I see it, the next step is Linus' Law -- "Many eyes make all bugs shallow".&amp;nbsp; &amp;nbsp;Omnibar search helps because it is curated (even if just crowdsourced).&amp;nbsp; As I type a URL, it continually guides me to the popular (and presumably correct) site.&amp;nbsp; We need similar "3rd-party" feedback during the critical moments after scanning a QR.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Beyond that, we can take&amp;nbsp;&lt;SPAN&gt;steps to protect creds from homonym sites. P&lt;/SPAN&gt;&lt;SPAN&gt;assword managers are a great defense because they use the URL to look up the creds.&amp;nbsp; If the URL is in its database, they autofill*.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Since a homonym is not in the DB, it does not autofill. This altered workflow hopefully triggers that oh-so-important spidey-sense.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* "autotype" is a bit generous.&amp;nbsp; I do have to click the little shield and potentially unlock the manager.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 20:04:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49125#M457</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2022-01-16T20:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49145#M458</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;I agree, however it appears there is great faith and face put behind QR codes both by the private sector and public sector.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A case in hand, New Zealand Vaccine Passport - issued centrally, fine, but guess what the PDF they issue is editable - dub.....&amp;nbsp; So this opens it directly up for fraudulent practices and in fact fake passports are available for $10 per pot on the black market already.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Plus there is no means to verify that it is fake or real, unless the outlet insists on seeing a valid identity card or drivers license or passport.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, it comes down to the adage "Trust, but Verify", however some people have a tendency to violence, when cornered which puts off outlets from actually doing the right thing i.e. verifying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 19:09:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49145#M458</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-01-17T19:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49151#M459</link>
      <description>&lt;P&gt;I don't want to sound like "there's an app for that", but do any of you use apps which can sandbox or otherwise verify the safety of a URL?&amp;nbsp; As far as myself, it's easy to avoid scanning a QR code.&amp;nbsp; But I'm thinking about the average person, and whatever defenses they might use, given how widespread QR codes are.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 15:11:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49151#M459</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2022-01-18T15:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49156#M460</link>
      <description>&lt;P&gt;Veering slightly from QR codes and into verification....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;the PDF they issue is editable&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yea, that is a bit messed up....&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;Plus there is no means to verify that it is fake or real&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;... or perhaps completely messed up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not being in (or near) NZ I do not know how their passport works. Does the QR simply regurgitate the text on the PDF or is it a link to download the original PDF from the issuer?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sounds like there may be two problems.... verification of identity (e.g. showing the drivers license) and verification of authorization (ensuring it actually came from the issuer).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Forgery is always a problem when you let the subject man-in-the-middle you.&amp;nbsp; The only real answer is some sort of out-of-band communications channel... either for the doc itself or for the the public key if digitally signing.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 18:23:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49156#M460</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2022-01-18T18:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49157#M461</link>
      <description>&lt;P&gt;Like you I rarely scan QR codes.&amp;nbsp; The android app I use is "Barcode Scanner" by XY Labs.&amp;nbsp; I have had it on my phone "forever".&lt;SPAN&gt;&amp;nbsp; After scanning, it d&lt;/SPAN&gt;isplays the URL with&amp;nbsp; an "open in browser" button (and a product search button if UPC).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pros:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Prompts for next step after scanning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cons:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; No risk analysis.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Last update 2019; my phone warns of Android 11 compatibility concerns.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The last "con" is enough for me to withhold my recommendation and to merely report what I have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 18:27:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49157#M461</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2022-01-18T18:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49161#M462</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;Good thoughts, it is worst than that a)&amp;nbsp; the original source code is available via Github and b) the actual technical specification including the encryption technique used is available in public too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The mind simply boggles open source vs protecting people - it feels like a we did so well, we would like to commercialise it and make some money at the same time moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It uses the international standards, but what was the point give the above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 20:16:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49161#M462</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-01-18T20:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49192#M463</link>
      <description>&lt;P&gt;Here is the latest update and warning from the FBI:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.zdnet.com/article/fbi-warning-crooks-are-using-fake-qr-codes-to-steal-your-passwords-and-money/?ftag=TRE49e8aa0&amp;amp;bhid=%7B%24external_id%7D&amp;amp;mid=%7B%24MESSAGE_ID%7D&amp;amp;cid=%7B%24contact_id%7D&amp;amp;eh=%7B%24CF_emailHash%7D" target="_blank"&gt;https://www.zdnet.com/article/fbi-warning-crooks-are-using-fake-qr-codes-to-steal-your-passwords-and-money/?ftag=TRE49e8aa0&amp;amp;bhid=%7B%24external_id%7D&amp;amp;mid=%7B%24MESSAGE_ID%7D&amp;amp;cid=%7B%24contact_id%7D&amp;amp;eh=%7B%24CF_emailHash%7D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 20:05:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49192#M463</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-01-20T20:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Are QR codes threats?</title>
      <link>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49387#M466</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It has been proven you can create games and programs within QR Codes by using the largest format i.e. 3 Kilobytes with compression techniques applied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is fully demonstrated in the demonstration at the link provided below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://tinyurl.com/4ey9wzsp" target="_blank" rel="noopener"&gt;https://tinyurl.com/4ey9wzsp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A lot of developers and standards suddenly need to be adjusted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So how quickly will industry respond to this through encryption or other controls?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 22:32:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Are-QR-codes-threats/m-p/49387#M466</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-01-27T22:32:32Z</dc:date>
    </item>
  </channel>
</rss>

