1 min
Protect yourself: Scammed by a QR Code? It didn’t have to happen
QR codes are used everywhere nowadays – to pay for metered parking, to read menus at restaurants, to win a free cup of coffee. Cybercriminals are using them, too – redirecting users to harmful websites that harvest their data. The practice is known as “quishing,” derived from QR code phishing, and it is a fast-growing cybercrime. But it doesn’t have to be. University of Rochester engineers Gaurav Sharma and Irving Barron have devised a new form of QR code – called a self-authenticating dual-modulated QR (SDMQR) – that protects smartphone users from quishing attacks by signaling when users are being directed to a safe link or a potential scam. Gaurav is a professor of electrical and computer engineering, computer science, and biostatistics and computational biology. Barron is an assistant professor of instruction in electrical computer engineering. Their creation involves allowing companies to register their websites and embed a cryptographic signature in a QR code. When the code is scanned, the user is notified that the code is from an official source and safe. Gaurav and Barron recently wrote about their technology in the journal IEEE Security and Privacy, and spoke about their work on the National Science Foundation's Discovery Files podcast. They can be reached by email at gaurav.sharma@rochester.edu and ibarron@ur.rochester.edu.