I just started reading a little on QR code, so I'm not entirely familiar with QR Code capabilities, but a thought crossed my mind today.
I scanned a QR Code on a postcard I received, and it immediately took me to a website.
Just like URL shorteners, is there any protection from obscuring a malicious site in the QR code?
I also noticed you can use QR Code for multiple other things such as VCards, Youtube videos, etc...
Can you embed code that then gets executed on the client when scanned?
Again, I just started reading around, so my understanding of this technology is pretty feeble, but primarily what I'm looking for is some ideas of potential threats from scanning QR codes, as well as potential mitigation techniques.
This question was IT Security Question of the Week.
Read the May 4, 2012 blog entry for more details or submit your own Question of the Week.