QR Codes: slightly better than SMS

Let’s talk about QR codes.

Just last weekend, I went to a new restaurant and, scanning the table for a menu, was handed a coaster with a pixelated square. Groaning, I pulled out my phone, held my breath, and scanned the code with my camera. While convenient, QR codes are risky. They can hide malicious links that lead to phishing sites or trigger unauthorized actions. Unlike traditional URLs, QR codes don’t reveal their destination, making it easier for bad actors to exploit them.

Cybercriminals have been abusing QR code-based authentication in apps like Signal, WhatsApp, and Discord. In Signal’s case, Russian-backed hackers have crafted malicious QR codes that, when scanned, link a victim’s account to an attacker-controlled device—allowing real-time message interception. WhatsApp users have also been targeted through phishing attacks with deceptive QR codes, compromising account security. Even Discord has seen scammers distribute fraudulent QR codes promising free perks, which, when scanned, grant attackers unauthorized access. These incidents underscore the vulnerabilities inherent in QR code-based authentication across platforms.

You’d forgive my double-take when I heard Google plans to replace SMS-based two-factor authentication with QR codes for Google sites. While I’m all for ending SMS-based 2FA, swapping one phish-prone system for another isn’t a clear win.

If Google is modeling their system after Steam, they are mitigating some of the most egregious flaws, but not all. Steam’s QR authentication uses dynamic codes that expire every 30 seconds to limit misuse. Still, concerns persist. Bypassing the traditional approve/deny prompt in the Steam Guard Mobile Authenticator could make unauthorized access easier if your phone is compromised, and weak encryption in some implementations might let attackers forge codes for phishing.

We’ll see what the future holds for QR-based authentication, but unless there’s a fundamental change in how these codes are generated, scanned, and secured, they won’t become the panacea for digital security.