<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QR Codes in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51935#M3590</link>
    <description>&lt;P&gt;The QR code is most likely just a URL encoded into teh graphic. You said you are logged ini, presumably to yoru company's internal network. Use a QR reader that shows you the URL without automatically going there, and inspect it.&lt;/P&gt;&lt;P&gt;Is the survey on an internal server in the company, or on an external survey host like SurveyMonkey? If on an external service server, you are at the mercy of the survey service's practices adn contracts.&lt;/P&gt;&lt;P&gt;Does teh URL appear to have a token that uniquely identifies you? You can tell by sharing the URL with a a co-worker's and comparing them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even though a unique URL ID for you does impact your privacy, unless they tell you the survey is anonymous, I would expect them to knwo how each employee completes the survey.&lt;/P&gt;&lt;P&gt;Good luck on the detective work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jul 2022 02:36:53 GMT</pubDate>
    <dc:creator>CraginS</dc:creator>
    <dc:date>2022-07-11T02:36:53Z</dc:date>
    <item>
      <title>QR Codes</title>
      <link>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51932#M3588</link>
      <description>&lt;P&gt;HI all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Just curious of the danger of using QR codes.&amp;nbsp; My current company has a survey.... I am already authenticated by a login but am required to scan a QR code to get to the survey.&amp;nbsp; Should this be a privacy / security concern on my part?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2022 18:56:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51932#M3588</guid>
      <dc:creator>dheff</dc:creator>
      <dc:date>2022-07-10T18:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: QR Codes</title>
      <link>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51934#M3589</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/461084629"&gt;@dheff&lt;/a&gt;&amp;nbsp;&amp;nbsp; I have found some links, which maybe useful to you on the issues with QR codes:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; &lt;A href="https://blog.1password.com/qr-codes-cybersecurity-risks/?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=17490153303&amp;amp;utm_content=&amp;amp;utm_term=&amp;amp;gclid=Cj0KCQjw8amWBhCYARIsADqZJoWYRisAW_MZFo1F_vJp61e9hIJXcc8z13VBvBAv_-gRlR-5JGfm5OkaAqbAEALw_wcB&amp;amp;gclsrc=aw.ds" target="_blank"&gt;https://blog.1password.com/qr-codes-cybersecurity-risks/?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=17490153303&amp;amp;utm_content=&amp;amp;utm_term=&amp;amp;gclid=Cj0KCQjw8amWBhCYARIsADqZJoWYRisAW_MZFo1F_vJp61e9hIJXcc8z13VBvBAv_-gRlR-5JGfm5OkaAqbAEALw_wcB&amp;amp;gclsrc=aw.ds&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; &lt;A href="https://www.computer.org/publications/tech-news/trends/qr-code-risks" target="_blank"&gt;https://www.computer.org/publications/tech-news/trends/qr-code-risks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3)&amp;nbsp; &lt;A href="https://www.washingtonpost.com/technology/2021/10/07/are-qr-codes-safe/" target="_blank"&gt;https://www.washingtonpost.com/technology/2021/10/07/are-qr-codes-safe/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4)&amp;nbsp; &lt;A href="https://www.wxii12.com/article/fbi-and-cybersecurity-experts-warn-about-qr-code-privacy-and-security-concerns/39003110" target="_blank"&gt;https://www.wxii12.com/article/fbi-and-cybersecurity-experts-warn-about-qr-code-privacy-and-security-concerns/39003110&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5)&amp;nbsp; &lt;A href="https://www.fastcompany.com/90740485/how-qr-codes-work-and-what-makes-them-dangerous" target="_blank"&gt;https://www.fastcompany.com/90740485/how-qr-codes-work-and-what-makes-them-dangerous&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These resources should give you a reasonable assessment of the issues whether they are security or privacy issues or not and what guidance you need to provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2022 23:59:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51934#M3589</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-07-10T23:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: QR Codes</title>
      <link>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51935#M3590</link>
      <description>&lt;P&gt;The QR code is most likely just a URL encoded into teh graphic. You said you are logged ini, presumably to yoru company's internal network. Use a QR reader that shows you the URL without automatically going there, and inspect it.&lt;/P&gt;&lt;P&gt;Is the survey on an internal server in the company, or on an external survey host like SurveyMonkey? If on an external service server, you are at the mercy of the survey service's practices adn contracts.&lt;/P&gt;&lt;P&gt;Does teh URL appear to have a token that uniquely identifies you? You can tell by sharing the URL with a a co-worker's and comparing them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even though a unique URL ID for you does impact your privacy, unless they tell you the survey is anonymous, I would expect them to knwo how each employee completes the survey.&lt;/P&gt;&lt;P&gt;Good luck on the detective work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 02:36:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51935#M3590</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2022-07-11T02:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: QR Codes</title>
      <link>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51966#M3594</link>
      <description>&lt;P&gt;Yes, QR codes are completely free to use and can be generated in any QR code software available online, as long as the QR solution is generated as a static QR code.&amp;nbsp;&lt;A href="https://www.hca-rewards.net/" target="_blank" rel="noopener"&gt;&lt;FONT color="#FFFFFF"&gt;&amp;nbsp;HCA Rewards 401k&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 03:56:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51966#M3594</guid>
      <dc:creator>Cynthia859</dc:creator>
      <dc:date>2022-07-13T03:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: QR Codes</title>
      <link>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51986#M3596</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/659915877"&gt;@Cynthia859&lt;/a&gt;It does not help certainly during the pandemic, that certain governments created QR code based passports, and then went and released all the details including the encoding within public accessible Github repositories.&amp;nbsp; From a privacy perspective, open to modification, and certainly not dependable at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Therefore infinitely open to modification and fraud.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautiim&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 22:52:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/QR-Codes/m-p/51986#M3596</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-07-13T22:52:03Z</dc:date>
    </item>
  </channel>
</rss>

