Krombholz, K., Frühwirt, P., Kieseberg, P., Kapsalis, I., Huber, M., & Weippl, E. (2014). QR Code Security: A Survey of Attacks and Challenges for Usable Security. In Human Aspects of Information Security, Privacy, and Trust (pp. 79–90). Springer. https://doi.org/10.1007/978-3-319-07620-1_8
Second International Conference, HAS 2014, Held as Part of HCI International 2014
-
Event date:
22-Jun-2014 - 27-Jun-2014
-
Event place:
Heraklion, Greece
-
Number of Pages:
12
-
Publisher:
Springer
-
Peer reviewed:
Yes
-
Abstract:
QR (Quick Response) codes are two-dimensional barcodes
with the ability to encode di erent types of information. Because of their
high information density and robustness, QR codes have gained popularity
in various elds of application. Even though they o er a broad range
of advantages, QR codes pose signi cant security risks. Attackers can encode
malicious links that lead e.g. to phishing sites. Such malicious QR
codes can be printed on small stickers and replace benign ones on billboard
advertisements. Although many real world examples of QR code
based attacks have been reported in the media, only little research has
been conducted in this eld and almost no attention has been paid on
the interplay of security and human-computer interaction. In this work,
we describe the manifold use cases of QR codes. Furthermore, we analyze
the most signi cant attack scenarios with respect to the speci c
use cases. Additionally, we systemize the research that has already been
conducted and identi ed usable security and security awareness as the
main research challenges. Finally we propose design requirements with
respect to the QR code itself, the reader application and usability aspects
in order to support further research into to making QR code processing
both secure and usable.
de
QR (Quick Response) codes are two-dimensional barcodes
with the ability to encode di erent types of information. Because of their
high information density and robustness, QR codes have gained popularity
in various elds of application. Even though they o er a broad range
of advantages, QR codes pose signi cant security risks. Attackers can encode
malicious links that lead e.g. to phishing sites. Such malicious QR
codes can be printed on small stickers and replace benign ones on billboard
advertisements. Although many real world examples of QR code
based attacks have been reported in the media, only little research has
been conducted in this eld and almost no attention has been paid on
the interplay of security and human-computer interaction. In this work,
we describe the manifold use cases of QR codes. Furthermore, we analyze
the most signi cant attack scenarios with respect to the speci c
use cases. Additionally, we systemize the research that has already been
conducted and identi ed usable security and security awareness as the
main research challenges. Finally we propose design requirements with
respect to the QR code itself, the reader application and usability aspects
in order to support further research into to making QR code processing
both secure and usable.