QR codes – those little black and white square puzzles – are increasingly appearing on advertising posters and are meant to provide smartphone users with more information about products. But the trust consumers place in scanning these codes could pose security and privacy concerns.
There's no doubt that QR code usage is on the rise. Adoption of two-dimensional bar-code-scanning apps among smartphone owners has increased to 15% from 5% a year ago, according to Forrester Research, with Android and iPhone models being the most common smartphones in use.

However, experts say that all this hype could pose some security issues, and perhaps privacy concerns for unsuspecting users. The QR codes themselves could be linked to malicious text messages or malicious websites, said Tim Armstrong, a malware researcher at Kaspersky Lab.
“You can scan a barcode to download an app, but you don’t know the source of that app,” Armstrong said.
The fact that a QR code is cheap and easy to create makes it an ideal target for scammers who use them to create phishing. The codes don't just appear in expensive advertising campaigns, they can also be produced as stickers and illegally attached to legitimate posters and placards.
These cases may still be relatively rare, but they do happen, Armstrong said.
Another factor that consumers need to be aware of is the two types of QR codes: direct and indirect. A direct QR code contains all the product information you need to know directly, but an indirect code requires an app to reach an online server to look up the necessary information.
In the latter case, the QR code works in harmony with an app, which sometimes has to be purchased, to determine the app's destination from the database ,says Andrew Kinnear of Aimia Inc.
Indirect codes usually require the user to use a dedicated app to “decode” the QR Code, he says.
“Because of this, there are many opportunities for app developers to implement tracking systems,” Kinnear said.
While tracking can occur and privacy concerns can arise ,Kinnear said, in the payment model used by some indirect QR code users, there is no room for fraudsters.
And it's not all innocent on the side of instant QR Codes. Instant codes can use shortened URLs to take a user to an unknown website and potentially install malware on their phone.
In the future, there will be even more security pitfalls to watch out for as the QR code world evolves, experts say.
