Security and Privacy of QR Code Applications: A Comprehensive Study, General Guidelines and Solutions

Author:

Wahsheh Heider A. M.,Luccio Flaminia L.

Abstract

The widespread use of smartphones is boosting the market take-up of dedicated applications and among them, barcode scanning applications. Several barcodes scanners are available but show security and privacy weaknesses. In this paper, we provide a comprehensive security and privacy analysis of 100 barcode scanner applications. According to our analysis, there are some apps that provide security services including checking URLs and adopting cryptographic solutions, and other apps that guarantee user privacy by supporting least privilege permission lists. However, there are also apps that deceive the users by providing security and privacy protections that are weaker than what is claimed. We analyzed 100 barcode scanner applications and we categorized them based on the real security features they provide, or on their popularity. From the analysis, we extracted a set of recommendations that developers should follow in order to build usable, secure and privacy-friendly barcode scanning applications. Based on them, we also implemented BarSec Droid, a proof of concept Android application for barcode scanning. We then conducted a user experience test on our app and we compared it with DroidLa, the most popular/secure QR code reader app. The results show that our app has nice features, such as ease of use, provides security trust, is effective and efficient.

Publisher

MDPI AG

Subject

Information Systems

Reference128 articles.

1. QRcode.com DENSO WAVEhttp://www.qrcode.com/en

2. Do People Use QR Codes in 2017? The Answer Will Definitely Surprise Youhttps://scanova.io/blog/blog/2017/08/04/do-people-use-qr-codes/

3. Beautified QR code with high storage capacity using sequential module modulation

4. The Evolution and Emergence of QR Codes;Akta,2017

Cited by 31 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Detection of QR Code-based Cyberattacks using a Lightweight Deep Learning Model;Engineering, Technology & Applied Science Research;2024-08-02

2. University of Cape Coast Doctoral Students’ Use of Mobile Devices to Seek Information;New Review of Academic Librarianship;2024-07-23

3. QR Codes: From a Survey of the State of the Art to Executable eQR Codes for the Internet of Things;IEEE Internet of Things Journal;2024-07-01

4. An Online QR Code Scanner for Real-Time User Feedback and Ratings Collection with Local Web Server;2024 11th International Conference on Computing for Sustainable Global Development (INDIACom);2024-02-28

5. QR codes and automated decision-making in the COVID-19 pandemic;New Media & Society;2024-02-26

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3