{"id":638842,"date":"2025-02-11T09:05:12","date_gmt":"2025-02-11T14:05:12","guid":{"rendered":"https:\/\/www.rochester.edu\/newscenter\/?p=638842"},"modified":"2025-02-11T16:42:52","modified_gmt":"2025-02-11T21:42:52","slug":"qr-code-phishing-definition-quishing-638842","status":"publish","type":"post","link":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/","title":{"rendered":"New technology could quash QR code phishing attacks"},"content":{"rendered":"<h2><strong>The improved QR code format would let smartphone users know if they\u2019re heading to a secure website\u2014or wading into a potential \u2018quishing\u2019 scam.<\/strong><\/h2>\n<p>The ubiquitous QR (quick response) codes that appear on everything from parking pay stations to soda cans and promotional flyers have become an increasingly popular target for cybercriminals to exploit through QR code\u2013based phishing attacks, also known as \u201cquishing.\u201d Bad actors will place phony QR codes that direct smartphone users to enter their sensitive private information in fake websites masquerading as bank websites, parking enforcement offices, or other seemingly official sources.<\/p>\n<p>Researchers at the <a href=\"http:\/\/www.rochester.edu\/\">University of Rochester<\/a> have engineered a new form of QR codes\u2014called self-authenticating dual-modulated QR (SDMQR)\u2014that can protect smartphone users from these types of attacks by signaling if users are being directed to a safe link or a potential scam. The technology is outlined in a <a href=\"https:\/\/doi.org\/10.1109\/MSEC.2025.3530487\">new study<\/a> published in the journal <em>IEEE Security &amp; Privacy<\/em>.<\/p>\n<p>The SDMQR codes provide an added layer of security by allowing an official source such as a company to pre-register its URLs and embed a cryptographic signature in a QR code. When a code is scanned by a user, the QR code decoder can signal to the user whether the link is from a verified source and can be safely followed, or if it is from an unverified source for which users should exert caution in following the link and in sharing sensitive personal information.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-639532 alignright\" src=\"https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/inline-SDMQR-code-quishing_ece_spiritR_blue.jpg\" alt=\"A new kind of QR code that is an SDMQR code meant to thwart quishing attempts.\" width=\"350\" height=\"350\" srcset=\"https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/inline-SDMQR-code-quishing_ece_spiritR_blue.jpg 1280w, https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/inline-SDMQR-code-quishing_ece_spiritR_blue-630x630.jpg 630w, https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/inline-SDMQR-code-quishing_ece_spiritR_blue-768x768.jpg 768w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/>Importantly, the added layer of security with SDMQR codes comes transparently, without any interference with the existing functionality of a QR code. \u201cRetrofitting security is always a key challenge because once you&#8217;ve got existing players in the game, and an existing workflow, changes that do not maintain backward compatibility are just too disruptive,\u201d says <a href=\"https:\/\/www.hajim.rochester.edu\/ece\/people\/faculty\/sharma_gaurav\/index.html\">Gaurav Sharma<\/a>, a professor of <a href=\"https:\/\/www.hajim.rochester.edu\/ece\/index.html\">electrical and computer engineering<\/a>, <a href=\"https:\/\/www.cs.rochester.edu\/\">computer science<\/a>, and <a href=\"https:\/\/www.urmc.rochester.edu\/biostat\">biostatistics and computational biology<\/a>.<\/p>\n<p>SDMQR codes look much like traditional QR codes, but they use elongated ellipses instead of the traditional black and white squares. Today\u2019s smartphone cameras have such a high resolution that they can differentiate the more complex shapes and, as a result, embed more information in each code.<\/p>\n<p>Sharma and his coauthor <a href=\"https:\/\/www.hajim.rochester.edu\/ece\/people\/faculty\/barron_irving\/index.html\">Irving Barron<\/a>, an assistant professor of instruction in electrical and computer engineering, have been exploring opportunities to commercialize the technology. They worked with <a href=\"https:\/\/www.rochester.edu\/ventures\/\">UR Ventures<\/a> to file a patent for SDMQR codes and secured a <a href=\"https:\/\/www.nsf.gov\/awardsearch\/showAward?AWD_ID=2438156&amp;HistoricalAwards=false\">National Science Foundation I-Corps grant<\/a> to explore industry applications, such as replacing traditional UPC barcodes\u2014the 12-digit code and series of bars that typically identify a product\u2014with these more sophisticated QR codes.<\/p>\n<p>In addition to using new shapes for QR codes, the researchers are developing QR codes that can use color to embed more information and allow a single code to drive people to up to three destinations. Sharma says that their customer discovery research through the NSF I-Corps has shown that companies are interested in the technology because it allows for branded codes that could be used on packaging to replace both the modern black-and-white codes and the UPC codes scanned at checkout aisles.<\/p>\n<p>\u201cSomething that has been repeatedly brought up to us is that companies want to move away from having a traditional UPC barcode on their packaging and are increasingly moving to QR codes and other 2D barcodes because of their robustness,\u201d says Sharma. \u201cThe footprint is a concern because they want to have as much information in as small an area as possible. Our technology can help them achieve that.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The improved QR code format would let smartphone users know if they\u2019re heading to a secure website\u2014or wading into a potential \u2018quishing\u2019 scam.<\/p>\n","protected":false},"author":1242,"featured_media":638872,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[116],"tags":[18802,19382,18632,18572],"class_list":["post-638842","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sci-tech","tag-department-of-computer-science","tag-department-of-electrical-and-computer-engineering","tag-hajim-school-of-engineering-and-applied-sciences","tag-research-finding"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New technology could quash QR code phishing attacks<\/title>\n<meta name=\"description\" content=\"The improved QR code format would let smartphone users know if they\u2019re heading to a secure website\u2014or wading into a potential \u2018quishing\u2019 scam.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New technology could quash QR code phishing attacks\" \/>\n<meta property=\"og:description\" content=\"The improved QR code format would let smartphone users know if they\u2019re heading to a secure website\u2014or wading into a potential \u2018quishing\u2019 scam.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/\" \/>\n<meta property=\"og:site_name\" content=\"News Center\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-11T14:05:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-11T21:42:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/fea-qr-code-phishing-quishing-1200x630.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Luke Auburn\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Luke Auburn\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/\"},\"author\":{\"name\":\"Luke Auburn\",\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/#\\\/schema\\\/person\\\/e928dc2863b53a89ece6d40c7992a4e1\"},\"headline\":\"New technology could quash QR code phishing attacks\",\"datePublished\":\"2025-02-11T14:05:12+00:00\",\"dateModified\":\"2025-02-11T21:42:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/\"},\"wordCount\":593,\"image\":{\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/fea-qr-code-phishing-quishing.jpg\",\"keywords\":[\"Department of Computer Science\",\"Department of Electrical and Computer Engineering\",\"Hajim School of Engineering and Applied Sciences\",\"research finding\"],\"articleSection\":[\"Science &amp; Technology\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/\",\"url\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/\",\"name\":\"New technology could quash QR code phishing attacks\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/fea-qr-code-phishing-quishing.jpg\",\"datePublished\":\"2025-02-11T14:05:12+00:00\",\"dateModified\":\"2025-02-11T21:42:52+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/#\\\/schema\\\/person\\\/e928dc2863b53a89ece6d40c7992a4e1\"},\"description\":\"The improved QR code format would let smartphone users know if they\u2019re heading to a secure website\u2014or wading into a potential \u2018quishing\u2019 scam.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/fea-qr-code-phishing-quishing.jpg\",\"contentUrl\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/fea-qr-code-phishing-quishing.jpg\",\"width\":2002,\"height\":1200,\"caption\":\"How many quishes could a QR code quash if a QR code could quash quishes? (University of Rochester photo \\\/ J. Adam Fenster)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/qr-code-phishing-definition-quishing-638842\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New technology could quash QR code phishing attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/#website\",\"url\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/\",\"name\":\"News Center\",\"description\":\"University of Rochester\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/#\\\/schema\\\/person\\\/e928dc2863b53a89ece6d40c7992a4e1\",\"name\":\"Luke Auburn\",\"url\":\"https:\\\/\\\/www.rochester.edu\\\/newscenter\\\/author\\\/lauburn\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New technology could quash QR code phishing attacks","description":"The improved QR code format would let smartphone users know if they\u2019re heading to a secure website\u2014or wading into a potential \u2018quishing\u2019 scam.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/","og_locale":"en_US","og_type":"article","og_title":"New technology could quash QR code phishing attacks","og_description":"The improved QR code format would let smartphone users know if they\u2019re heading to a secure website\u2014or wading into a potential \u2018quishing\u2019 scam.","og_url":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/","og_site_name":"News Center","article_published_time":"2025-02-11T14:05:12+00:00","article_modified_time":"2025-02-11T21:42:52+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/fea-qr-code-phishing-quishing-1200x630.jpg","type":"image\/jpeg"}],"author":"Luke Auburn","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Luke Auburn","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/#article","isPartOf":{"@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/"},"author":{"name":"Luke Auburn","@id":"https:\/\/www.rochester.edu\/newscenter\/#\/schema\/person\/e928dc2863b53a89ece6d40c7992a4e1"},"headline":"New technology could quash QR code phishing attacks","datePublished":"2025-02-11T14:05:12+00:00","dateModified":"2025-02-11T21:42:52+00:00","mainEntityOfPage":{"@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/"},"wordCount":593,"image":{"@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/fea-qr-code-phishing-quishing.jpg","keywords":["Department of Computer Science","Department of Electrical and Computer Engineering","Hajim School of Engineering and Applied Sciences","research finding"],"articleSection":["Science &amp; Technology"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/","url":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/","name":"New technology could quash QR code phishing attacks","isPartOf":{"@id":"https:\/\/www.rochester.edu\/newscenter\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/#primaryimage"},"image":{"@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/fea-qr-code-phishing-quishing.jpg","datePublished":"2025-02-11T14:05:12+00:00","dateModified":"2025-02-11T21:42:52+00:00","author":{"@id":"https:\/\/www.rochester.edu\/newscenter\/#\/schema\/person\/e928dc2863b53a89ece6d40c7992a4e1"},"description":"The improved QR code format would let smartphone users know if they\u2019re heading to a secure website\u2014or wading into a potential \u2018quishing\u2019 scam.","breadcrumb":{"@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/#primaryimage","url":"https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/fea-qr-code-phishing-quishing.jpg","contentUrl":"https:\/\/www.rochester.edu\/newscenter\/wp-content\/uploads\/2025\/02\/fea-qr-code-phishing-quishing.jpg","width":2002,"height":1200,"caption":"How many quishes could a QR code quash if a QR code could quash quishes? (University of Rochester photo \/ J. Adam Fenster)"},{"@type":"BreadcrumbList","@id":"https:\/\/www.rochester.edu\/newscenter\/qr-code-phishing-definition-quishing-638842\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.rochester.edu\/newscenter\/"},{"@type":"ListItem","position":2,"name":"New technology could quash QR code phishing attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.rochester.edu\/newscenter\/#website","url":"https:\/\/www.rochester.edu\/newscenter\/","name":"News Center","description":"University of Rochester","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rochester.edu\/newscenter\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.rochester.edu\/newscenter\/#\/schema\/person\/e928dc2863b53a89ece6d40c7992a4e1","name":"Luke Auburn","url":"https:\/\/www.rochester.edu\/newscenter\/author\/lauburn\/"}]}},"_links":{"self":[{"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/posts\/638842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/users\/1242"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/comments?post=638842"}],"version-history":[{"count":6,"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/posts\/638842\/revisions"}],"predecessor-version":[{"id":639642,"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/posts\/638842\/revisions\/639642"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/media\/638872"}],"wp:attachment":[{"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/media?parent=638842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/categories?post=638842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rochester.edu\/newscenter\/wp-json\/wp\/v2\/tags?post=638842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}