🎯 here's the thing
you just scanned a random QR code. maybe it was on a flyer by novack? a bulletin board in brittle or topliff? posted up by collis or foco, stuck on a meter in downtown hanover, or slapped on a laptop at a library study table.
real talk: you had no idea where it would take you. could've been:
- a fake netid page stealing your credentials
- a spoofed parking payment site harvesting card details
- a tracking link fingerprinting your device
- or just... some rando's link farm
this isn't about you being careless. it's about QR codes being opaque by design. attackers live for that opacity.
since it's cybersecurity awareness month, let's pop the hood and show what your phone actually does when it "just scans."
🔍 primitives: what is a QR code?
a QR code is just text encoded as squares. your camera decodes pixels → text. that text might be a URL (most common), plain text, a vCard, or wifi credentials.
the anatomy
📊 capacity
up to ~4,296 alphanumeric chars (plenty to hide shenanigans)
🔄 error correction
qr codes can recover up to ~30% damage at the highest error correction level
📱 universal decode
iphone & android cameras natively read and preview link targets
notice what's missing: authenticity. QR codes don't ship with trust baked in. no signature, no identity. just data.
⚠️ qrishing: the campus threat model
"qrishing" = QR code + phishing. the move is simple: stick a malicious code somewhere you already trust.
why it lands:
- trust transfer: legit-looking spaces (library boards, collis posters, parking signage) make the code feel safe
- urgency: "scan to pay," "scan for tickets," "scan for wifi" = tap first, think later
- opacity: you can't eyeball a URL from a square; you have to scan to learn
- device handoff: you act on your phone, away from desktop protections and password-manager guardrails
realistic attack scenarios
- wifi setup fake: a “set up eduroam” QR in a dorm points to a look‑alike site (not wifi.dartmouth.edu) asking for your NetID + password. what’s at stake: account lock + email/Canvas access to whoever grabbed it; weekend spent resetting passwords + re‑enrolling 2FA.
- parking payment: a sticker on a Hanover meter or sign sends you to a look‑alike parking site to grab card + plate. what’s at stake: card charges to a scammer and a real ticket bc you didn’t actually pay.
- menu here: at Collis or Foco, a QR opens a site that immediately pushes app installs or Apple ID login. hard pass. what’s at stake: malware on android via sideload, or apple‑id phish → locked account/charges.
- club sign‑up form: a random Google Form asks for NetID, Duo codes, or payment. forms are fine for headcounts; never for passwords or payments. what’s at stake: identity/credential theft; doxx‑y data leakage; “membership fees” that never existed.
google forms/docs: the grey zone
- lots of orgs use Google Forms. that’s fine for headcounts. it’s not how dartmouth logs you in.
- safe use: names, NetIDs (as an identifier), dietary notes. red flags: passwords, Duo codes, credit card fields, “re-enter your email password.”
- look for the footer note like “never submit passwords…” and the report abuse link. when in doubt, ask the org to post the same info on a dartmouth.edu page or an official channel.
physical placement short-circuits skepticism. bulletin boards feel official; stickers are cheap.
🛠️ under the hood
attacker playbook (abridged)
1) craft the lure
- register a sneaky domain (
dartm0uth‑wifi.com). - print a nice‑looking QR and stick it where trust leaks (baker‑berry doors, dorm entries, parking signs).
- land you on a familiar‑looking page and nudge you to type creds or card.
2) your phone's part
- system camera shows a preview banner of the URL; tapping opens it in browser
- mobile safebrowsing/fraud warnings help, but they can be bypassed or ignored
- once in the browser, it's just a web page—the usual phishing rules apply
3) common payloads
- pixel-perfect fake dartmouth login (css [website visuals*] theft is trivial)
- obscured domains (
dartmouth.secure-wifi[.]site) - android-only prompts to sideload apps; ios prompts for apple id or profiles
- fingerprinting (device, ip, locale) to tune the scam
the preview trap: you got a banner preview from your camera. did you actually read it? habituation kills vigilance.
🛡️ how not to get got (≈3 seconds)
practical habits (ranked)
🔍 use the system camera
it shows a link preview. avoid 3rd‑party scanners that auto‑open links.
🏢 verify the source
"official dartmouth" links live on dartmouth.edu. wifi setup starts at wifi.dartmouth.edu.
🧰 turn on protections
enable safari's fraudulent site warning & chrome's enhanced safe browsing.
red flags checklist
- 🚩 a sticker covering an original code (tampered signage).
- 🚩 shortened links (bit.ly/tinyurl) hiding the destination.
- 🚩 weird endings or typos (dartm0uth.io vs dartmouth.edu).
- 🚩 immediate urge to pay or log in on first click.
- 🚩 forms asking for passwords, Duo codes, or card info.
ask yourself 3 quick things
- who put this here?
- what are they asking me to type or pay?
- can i get this from dartmouth.edu or an official source instead?
the golden rule
treat every QR like a link from a stranger. preview → verify → then act.
for the extra‑paranoid
nerd corner (optional)
- long‑press the preview banner → copy link → paste in notes to read the full domain without opening.
- for payments or wifi, type known addresses: wifi.dartmouth.edu, o365.dartmouth.edu.
- sketchy Google Form? use the report abuse link at the bottom; don’t enter passwords or cards.
🌐 beyond QR codes
the shared weakness: you must trust before you can verify. that's true for QR, short links, rogue bluetooth, and tap‑to‑pay shims.
security theater vs reality: you skim phishing emails, but you scan bathroom‑stall QR codes without blinking. attackers exploit that mismatch.
friction is a feature. the extra second to read the URL is your perimeter.
who would actually target me (for real)?
- drive‑by scammers: people who sticker codes around college towns. they don’t know you; they want a small % of taps to pay off.payoff: a few stolen logins/cards scaled over hundreds of scans.
- credential resellers: .edu logins are valuable (student discounts, cloud credits). your NetID can be abused even without “hacking the college.”payoff: resale + access to your campus resources/email.
- ticket/parking grifters: fake event sign‑ups and parking portals. payoff: your card + your plate; you still get a real ticket.
- lazy phishers using forms: google forms that ask for passwords/Duo or fees. payoff: quick creds or instant “dues” from many students.
- clout/growth spammers: not always malicious, just harvesting followers/emails. payoff: you get spammed; your data spreads.
it’s not ego; it’s math. most attacks are indiscriminate. your best defense is a 2‑second pause before tapping.
✅ takeaways
QR = data, not trust
pixels encode text. authenticity isn't included.
physical ≠ legit
anyone can print & stick. location proves nothing.
preview → verify → act
read domains; type them manually for payments/wifi.
see something sketchy?
- email phish/spam: forward to phishing@dartmouth.edu
- physical tampering / suspicious QR on campus: call safety & security: 603‑646‑4000 (non‑emergency)
- wifi setup: start at wifi.dartmouth.edu (eduroam installer)
stay curious. stay safe. 🌲
built for cybersecurity awareness month with ai slop and a bored '29. not affiliated with Dartmouth College or any student organizations.