Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner
Authors
Paper Title
Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner
Publication Info
- Topic area: Usable security for QR code scanning and phishing prevention.
- Keywords: QRishing, phishing, QR code scanner, usable security, SEQR, mobile security, systematic review, MITRE ATT&CK®, user study, open source.
Background and Problem
- Problem / challenge: QR codes are increasingly used as phishing vectors (QRishing), but existing QR code scanners lack adequate user support to detect and prevent phishing attacks.
- Significance: QRishing poses risks such as account compromise, malware dissemination, financial theft, and IT system disruption. Addressing this threat is critical for protecting users.
- Motivation and related work: Previous works on phishing focused on email and SMS contexts, neglecting QR codes. Existing QR code scanners fail to provide effective security features or user involvement, leaving users vulnerable to QRishing attacks.
Solution
- Proposed approach: SEQR (Security Enhanced QR code scanner), a secure QR code scanner designed to thwart phishing attacks through technology and user involvement.
- Novelty:
- Systematic categorization of QRishing attacks using academic literature and MITRE ATT&CK® Mobile repository.
- Development of SEQR with risk levels, enhanced URL visualization, and user tutorials.
- Evaluation showing SEQR significantly outperforms default QR code scanners (Apple iOS and Samsung Android) and the Privacy Friendly QR Scanner.
- Open-source implementation of SEQR for Android, enabling widespread adoption and further development.
- Procedure and key techniques:
- Categorized QRishing attacks into 60 techniques based on systematic reviews.
- Designed SEQR to address attacks through risk levels (low-risk, unknown-risk, high-risk), domain-only URL visualization, kerning, and a tutorial.
- Implemented SEQR as an Android app, integrating features like PhishTank checks, redirect resolution, and user feedback dialogs.
- Conducted two user studies to evaluate SEQR 1.0 and SEQR 2.0 against baselines.
Results
- Concrete findings:
- SEQR achieved 93.35% correct answers in distinguishing phishing QR codes from legitimate ones, compared to 75.24% for Apple iOS and 65.11% for Samsung Android.
- SEQR 2.0 achieved 94.18% correct answers, outperforming the Privacy Friendly QR Scanner (76.26%).
- Advantage over baselines:
- SEQR significantly improved phishing detection rates compared to default QR scanners and the baseline app, with large effect sizes in user studies.
- Features like risk levels and tutorials enhanced user effectiveness.
- Experiments / evaluation:
- Two between-subjects online studies with 556 participants (SEQR 1.0) and 417 participants (SEQR 2.0).
- Tested scenarios with legitimate and phishing URLs using obfuscation techniques (e.g., mangle, mislead, obfuscate).
- Metrics included correct answers, false positives, and false negatives.
- Limitations and future work:
- SEQR currently supports only URLs and phone numbers; other QR code formats (e.g., vCards) need implementation.
- Reliance on online services like PhishTank may cause issues if services are unreachable.
- Further studies needed to evaluate long-term effectiveness, accessibility, and iOS implementation.
Summary
SEQR is a secure QR code scanner designed to address QRishing threats through systematic categorization, user involvement, and technological features. Evaluations demonstrated its significant effectiveness over default QR scanners and the Privacy Friendly QR Scanner. SEQR’s open-source implementation provides a foundation for improving QR code security and usability. Future work should expand its functionality, address reliance on online services, and conduct real-world and longitudinal studies to ensure widespread adoption and effectiveness.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 86%
"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
CHI '22· Privacy by Design & User Control +2
- 71%
Security During Application Development: an Application Security Expert Perspective
CHI '18· Privacy by Design & User Control +1
- 71%
Evaluating Attack and Defense Strategies for Smartphone PIN Shoulder Surfing
CHI '18· Passwords & Authentication +1
- 71%
A Promise Is A Promise: The Effect of Commitment Devices on Computer Security Intentions
CHI '19· Privacy by Design & User Control +2
- 71%
'Think secure from the beginning': A Survey with Software Developers
CHI '19· Privacy by Design & User Control +2
- 71%
Understanding Privacy-Related Questions on Stack Overflow
CHI '20· Privacy by Design & User Control +1
- 71%
I Was Told to Install the Antivirus App, but I'm Not Sure I Need It: Understanding Smartphone Antivirus Software Adoption and User Perceptions
CHI '25· Privacy by Design & User Control +1
- 71%
The TaPSI Research Framework - A Systematization of Knowledge on Tangible Privacy and Security Interfaces
CHI '25· Privacy by Design & User Control +2
- 63%
SIGCHI Outstanding Dissertation Award – Supporting Password Decisions with Data
CHI '18· Explainable AI (XAI) +2
- 63%
"Pretty Close to a Must-Have:" Balancing Usability Desire and Security Concern in Biometric Adoption
CHI '19· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)