QR Code Scanning
QR code scanning is the decoding of a two-dimensional barcode into the data it encodes. The technology is mature, standardized and reliable. What has changed is the security position: because a QR code is unreadable to a human, it moves a link past every instinct people have developed for inspecting one — which is why it has become a phishing delivery mechanism.
| What it is | A two-dimensional matrix barcode, standardized under ISO/IEC 18004 |
| Capacity | Far more than a linear barcode — thousands of characters |
| Error correction | Built in, at four selectable levels; damaged codes still decode |
| Why it scans from any angle | Position detection patterns in three corners |
| Identity document use | Present on some national ID cards and certificates, often carrying signed data |
| Payment use | Widespread, and dominant in several markets |
| Security property | None inherent — the format carries no authentication of the encoder |
| Fraud use | Quishing — phishing delivered by QR code |
What the format does and does not provide
The engineering is good. Error correction means a code decodes even when partly obscured or damaged. Position detection patterns let a scanner find and orient a code at any rotation. Capacity is high enough to carry a meaningful payload rather than just an identifier.
What the format provides no part of is trust. A QR code is a container. It carries whatever was encoded, by whoever encoded it, and nothing in the standard authenticates the encoder or protects the content from substitution. A sticker placed over a genuine code is a complete attack, requiring no technical skill at all.
This is the same property as any barcode — PDF417 on a driver’s license carries no authentication either. The difference is context. A PDF417 is read by a system that also examines the document carrying it. A QR code is read by a person’s phone, which then acts on the contents.
Why it became a phishing channel
Quishing works because the QR code defeats inspection at every stage people are used to.
The destination is invisible before scanning. A link in an email can be read. A QR code cannot — the human sees a pattern of squares and has no way to evaluate it.
The preview arrives too late. Phones show the URL after the scan, at the moment the user has already decided to proceed, and it is frequently shortened or lengthy enough to be unhelpful.
The image bypasses link filtering. A QR code in an email attachment is an image. Security tooling that rewrites and inspects URLs does not see a link at all, which is the property that made the technique attractive to attackers.
The scan usually happens on a personal device. The user photographs the code with their phone, moving the interaction onto hardware the organization does not manage and cannot see — the same visibility gap described under smishing.
The physical variant needs no infrastructure whatsoever: a printed sticker over the code on a parking meter, a restaurant table or a payment terminal redirects payments to the attacker, and the genuine code underneath is the thing that made the fake one plausible.
Why this matters for identity verification
Two connections, in opposite directions.
As a document feature, QR codes appear on national identity cards, residence permits, vaccination records and various certificates, and in the better implementations they carry cryptographically signed data. That changes their status entirely: a signed payload can be verified against the issuer’s certificate, which makes the code evidence rather than a convenience. The same logic as digital certificates on a passport chip applies. Reading such a code and not verifying the signature discards the only part that mattered.
As an attack surface, quishing is one more route to the credentials and one-time codes described throughout this glossary, and it ends in the same place — account takeover, and the recovery path that follows.
For document work the practical requirement is that identity document verification decodes the code, validates any signature it carries, and cross-references its contents against the printed fields — the same discipline applied to any other encoding on a document. Identity verification that reads a QR code without checking what it should agree with has extracted data rather than verified anything.
What QR code scanning can’t do
It does not authenticate the encoder. The format carries no proof of who created the code, unless the payload itself is signed.
It cannot detect substitution. A sticker over a genuine code scans perfectly, because it is a perfectly valid code.
A visible URL preview is a weak control. It appears after the decision to scan, and shortened or long links defeat inspection anyway.
Reading a signed payload is not verifying it. Decoding returns the data; checking the signature against the issuer’s certificate is a separate step that is frequently skipped.
Frequently asked questions
Is QR code scanning secure?
The decoding is reliable and standardized, and the format provides no security of its own. A QR code is a container that carries whatever was encoded, with nothing in the standard authenticating who encoded it or preventing substitution. Security comes from the payload — a signed payload can be verified; a plain URL cannot.
What is quishing?
Phishing delivered by QR code. It works because the destination is invisible before scanning, the URL preview appears only after the user has decided to proceed, a code embedded in an image bypasses URL-rewriting security tools, and the scan usually happens on a personal device the organization cannot see.
Why do QR codes appear on identity documents?
To carry machine-readable data, and in the better implementations that data is cryptographically signed by the issuing authority. A signed payload can be verified against the issuer’s certificate, which makes the code genuine evidence rather than a convenience — provided the verifying system actually checks the signature.
Can a QR code be tampered with?
The code itself has error correction and is difficult to alter meaningfully. The practical attack is replacement rather than alteration — a sticker placed over a legitimate code scans perfectly because it is a perfectly valid code pointing somewhere else.
Related reading
- PDF417 — the barcode on U.S. driver’s licenses, and the same container property
- Digital certificate — what makes a signed payload verifiable rather than merely readable
- Phishing — the parent technique quishing is one delivery route for
- Data extraction — why decoding an encoding is not the same as verifying it