🎯 here's the thing

you just scanned a random QR code. maybe it was on a flyer by novack? a bulletin board in brittle or topliff? posted up by collis or foco, stuck on a meter in downtown hanover, or slapped on a laptop at a library study table.

real talk: you had no idea where it would take you. could've been:

  • a fake netid page stealing your credentials
  • a spoofed parking payment site harvesting card details
  • a tracking link fingerprinting your device
  • or just... some rando's link farm

this isn't about you being careless. it's about QR codes being opaque by design. attackers live for that opacity.

since it's cybersecurity awareness month, let's pop the hood and show what your phone actually does when it "just scans."

🔍 primitives: what is a QR code?

a QR code is just text encoded as squares. your camera decodes pixels → text. that text might be a URL (most common), plain text, a vCard, or wifi credentials.

the anatomy

📊 capacity

up to ~4,296 alphanumeric chars (plenty to hide shenanigans)

🔄 error correction

qr codes can recover up to ~30% damage at the highest error correction level

📱 universal decode

iphone & android cameras natively read and preview link targets

notice what's missing: authenticity. QR codes don't ship with trust baked in. no signature, no identity. just data.

⚠️ qrishing: the campus threat model

"qrishing" = QR code + phishing. the move is simple: stick a malicious code somewhere you already trust.

why it lands:

  1. trust transfer: legit-looking spaces (library boards, collis posters, parking signage) make the code feel safe
  2. urgency: "scan to pay," "scan for tickets," "scan for wifi" = tap first, think later
  3. opacity: you can't eyeball a URL from a square; you have to scan to learn
  4. device handoff: you act on your phone, away from desktop protections and password-manager guardrails

realistic attack scenarios

  • wifi setup fake: a “set up eduroam” QR in a dorm points to a look‑alike site (not wifi.dartmouth.edu) asking for your NetID + password. what’s at stake: account lock + email/Canvas access to whoever grabbed it; weekend spent resetting passwords + re‑enrolling 2FA.
  • parking payment: a sticker on a Hanover meter or sign sends you to a look‑alike parking site to grab card + plate. what’s at stake: card charges to a scammer and a real ticket bc you didn’t actually pay.
  • menu here: at Collis or Foco, a QR opens a site that immediately pushes app installs or Apple ID login. hard pass. what’s at stake: malware on android via sideload, or apple‑id phish → locked account/charges.
  • club sign‑up form: a random Google Form asks for NetID, Duo codes, or payment. forms are fine for headcounts; never for passwords or payments. what’s at stake: identity/credential theft; doxx‑y data leakage; “membership fees” that never existed.

google forms/docs: the grey zone

  • lots of orgs use Google Forms. that’s fine for headcounts. it’s not how dartmouth logs you in.
  • safe use: names, NetIDs (as an identifier), dietary notes. red flags: passwords, Duo codes, credit card fields, “re-enter your email password.”
  • look for the footer note like “never submit passwords…” and the report abuse link. when in doubt, ask the org to post the same info on a dartmouth.edu page or an official channel.

physical placement short-circuits skepticism. bulletin boards feel official; stickers are cheap.

🛠️ under the hood

attacker playbook (abridged)

1) craft the lure

  1. register a sneaky domain (dartm0uth‑wifi.com).
  2. print a nice‑looking QR and stick it where trust leaks (baker‑berry doors, dorm entries, parking signs).
  3. land you on a familiar‑looking page and nudge you to type creds or card.

2) your phone's part

  • system camera shows a preview banner of the URL; tapping opens it in browser
  • mobile safebrowsing/fraud warnings help, but they can be bypassed or ignored
  • once in the browser, it's just a web page—the usual phishing rules apply

3) common payloads

  • pixel-perfect fake dartmouth login (css [website visuals*] theft is trivial)
  • obscured domains (dartmouth.secure-wifi[.]site)
  • android-only prompts to sideload apps; ios prompts for apple id or profiles
  • fingerprinting (device, ip, locale) to tune the scam

the preview trap: you got a banner preview from your camera. did you actually read it? habituation kills vigilance.

🛡️ how not to get got (≈3 seconds)

practical habits (ranked)

🔍 use the system camera

it shows a link preview. avoid 3rd‑party scanners that auto‑open links.

🏢 verify the source

"official dartmouth" links live on dartmouth.edu. wifi setup starts at wifi.dartmouth.edu.

🧰 turn on protections

enable safari's fraudulent site warning & chrome's enhanced safe browsing.

red flags checklist

ask yourself 3 quick things

the golden rule

treat every QR like a link from a stranger. preview → verify → then act.

for the extra‑paranoid

nerd corner (optional)
  • long‑press the preview banner → copy link → paste in notes to read the full domain without opening.
  • for payments or wifi, type known addresses: wifi.dartmouth.edu, o365.dartmouth.edu.
  • sketchy Google Form? use the report abuse link at the bottom; don’t enter passwords or cards.

🌐 beyond QR codes

the shared weakness: you must trust before you can verify. that's true for QR, short links, rogue bluetooth, and tap‑to‑pay shims.

security theater vs reality: you skim phishing emails, but you scan bathroom‑stall QR codes without blinking. attackers exploit that mismatch.

friction is a feature. the extra second to read the URL is your perimeter.

who would actually target me (for real)?

it’s not ego; it’s math. most attacks are indiscriminate. your best defense is a 2‑second pause before tapping.

✅ takeaways

QR = data, not trust

pixels encode text. authenticity isn't included.

physical ≠ legit

anyone can print & stick. location proves nothing.

preview → verify → act

read domains; type them manually for payments/wifi.

see something sketchy?

  • email phish/spam: forward to phishing@dartmouth.edu
  • physical tampering / suspicious QR on campus: call safety & security: 603‑646‑4000 (non‑emergency)
  • wifi setup: start at wifi.dartmouth.edu (eduroam installer)

stay curious. stay safe. 🌲

built for cybersecurity awareness month with ai slop and a bored '29. not affiliated with Dartmouth College or any student organizations.

click stat