The growing abuse of QR codes in malware and payment scams prompts FTC warning

Lee Duna@lemmy.nz to Technology@lemmy.world – 156 points –
The growing abuse of QR codes in malware and payment scams prompts FTC warning
arstechnica.com
15

You are viewing a single comment

QR is just image to text, most QR reading apps I have used, show you the QR content before going to the website (or let you disable opening the link directly) so you should be able to check the URL or content and see if the link is legit or not.

But let's be honest most people don't know or don't even bother and that's the real problem.

It's also pretty easy to disguise the malicious part. For instance, hxxp://LegitimateBusiness.com@ScamMyAss.com

(Hoping that didn't get blocked as spam)

On many apps, that would truncate somewhere around the .com

Or just legitbusiness-online-order[.]com

But let’s be honest most people don’t know or don’t even bother and that’s the real problem.

100% they see the code and assume it can't be mean.