Universiti Teknologi Malaysia Institutional Repository

A evaluating security and privacy features of quick response code scanners a comparative study.

Kamaruddin, Norshaliza and Mohd. Azmi, Nurulhuda Firdaus and Sjarif, Nilam Nur Amir and Mohd. Rusli, Hazlifah and Maarop, Nurazean and Rafsanjani, Ahmad Sahban (2022) A evaluating security and privacy features of quick response code scanners a comparative study. Open International Journal Of Informatics (OIJI), 10 (2). pp. 197-207. ISSN 2289-2370

[img] PDF
260kB

Official URL: https://oiji.utm.my/index.php/oiji/article/view/20...

Abstract

Quick Response (QR) codes have become popular in recent years and are extensively utilized in a variety of sectors due to their large capacity, readability speed, and ease of generation and distribution. Besides a broad range of QR code advantages, it attracts the attention of cyberattackers. QR codes may be exploited to distribute harmful information by inserting malicious URLs into QR codes. The security hardening of QR code scanners is the most effective method for detecting and preventing QR code-based attacks. However, the security features of QR code scanners have received little attention in the literature and market. This paper provides a comprehensive evaluation of QR code scanner applications from a security and privacy perspective. We presented the possible attack scenarios on the QR code scanners and reviewed the security mechanisms provided by the scanners. We evaluate secure QR code scanner applications by phishing and malware QR codes. Also, we focus on the potential threats to the privacy of Android QR code scanner applications and assess the permission that is requested during installation. Finally, we have provided recommendations for designing a secure, usable, and privacy-friendly QR code scanner.

Item Type:Article
Uncontrolled Keywords:QR code scanner, Android security, QR code security, malicious URL, QR code privacy
Subjects:Q Science > QA Mathematics > QA75 Electronic computers. Computer science
T Technology > T Technology (General) > T58.6-58.62 Management information systems
Divisions:Advanced Informatics School
ID Code:104603
Deposited By: Muhamad Idham Sulong
Deposited On:21 Feb 2024 08:26
Last Modified:21 Feb 2024 08:26

Repository Staff Only: item control page