QR codes hide destinations from casual inspection
You cannot read a QR code, so the usual advice to check the link before clicking simply does not apply.
That is inherent rather than a flaw. The practical substitute is checking the address after it loads and before entering anything, and being suspicious of codes on stickers in public places, which is now a common way of replacing a legitimate one.
More on Human factors
- Phishing exploits context, not stupidityIt fitted the gap
- A warning ignored every day stops being a warningThe bell nobody hears
- Security friction moves behaviour elsewhereSqueeze it here, it comes out there
- MFA fatigue weaponises repetitionAsk forty times
- Verify suspicious requests through a separate channelRing back on a line they never gave you
- People need a safe way to report mistakes quicklyThe shortest road back
