September 13, 2022

EP 11 – Step Away From the QR Code and Listen to This w/ Len Noe, Technical Evangelist & White Hat Hacker at CyberArk

Len Noe – our favorite cyborg and CyberArk resident technical evangelist and white hat hacker – is back! On today’s episode, he’s talking with host David Puner about risky QR codes. On first blush it may seem like a simple subject, but attackers are having a field day with them and there seems to be a general lack of awareness about it. Help stop the havoc-wreaking and find out what you can do to protect yourself.

You’re listening to the Trust Issues podcast. I’m David Puner, a Senior Editorial Manager at CyberArk, the global leader in Identity Security.

Remember QR codes before COVID? They were a consumer novelty that never quite achieved long-lasting smart device liftoff. Just a few years ago, you still needed to use a third-party app on your smartphone to scan a QR code and get it to do its thing, which didn’t seem worth the hassle when you could just type in a URL. But maybe that was just me.

With the rise of the contactless era, the little black and white grids emerged from relative obscurity to replace everything from restaurant menus, to store discounts, to subway station ads. Governments around the world have embraced them to facilitate contact tracing and vaccination status verification.

They’ve become today’s business card, conference leave-behind, and virtual payment option. QR codes are accessible, easy to produce, and seemingly here to stay. They’re also a perfect way for cybercriminals to steal your personal information. And, as of now, it seems like there isn’t widespread understanding about that.

On today’s episode, we welcome back Len Noe. He’s CyberArks technical evangelist and white hat hacker, and if you listen to Trust Issues’ Episode 2, you’d know that he’s also our own resident cyborg—or transhuman, if that’s more your jam. You should check out the episode; it’s pretty enlightening.

Today, though, we’re talking about QR codes. Also enlightening. It seems pretty simple, but it also feels like most folks don’t know how QR codes are being used by criminals to wreak havoc. Innovation promotes innovation after all. So we talk about that. And we talk about what you can do to protect yourself. Here’s my talk with Len. I hope you enjoy it.

Thanks for coming on a second time. You’re our first repeat guest. Episode 2 was very popular. I got really carried away in that episode in that I was so excited to get going on transhumanism and AI and all that kind of stuff that I never had a chance to ask you what you do. You’re a technical evangelist and white hat hacker. What does that mean and what do you do?

What does that mean and what do I do? I do a lot of public speaking. I do a lot of research. It’s my job to show the attack landscape from a CyberArk perspective in real-world terms. I do a lot of real-life attacks, showing how those attacks would actually either be stopped, mitigated, or prevented based on the CyberArk stack technology.

I’m a very blessed person. It’s given me the opportunity to present a lot of information. I think I’m up to 29 different countries since starting at CyberArk. It’s been an amazing journey. Honestly, this is the first time I’ve ever not had a job because if you’ve ever heard that old expression, “If you love what you do, you never go to work.” So I feel very fortunate. I don’t go to work. I love what I do, and I love the company that I work for.

You mentioned the 29 countries since you’ve been working for CyberArk. I know you’ve just been on the road, as it were. Where have you been and where are you just back from? And why were you on the road?

Over the course of the last two months, let’s see. I’ve been in Paris, France. I’ve been in Rome, Italy. Was in Boston for our Impact. Did a South American tour in Mexico, Colombia, Argentina, and Brazil. And just got back from our APJ Mid-Year Kickoff in Bangkok, Thailand last Friday. It’s been a lot of travel and just an amazing journey.

To be honest, the reception that we’ve been getting post-lockdown has just been phenomenal. The attendees at all of the sessions have been so eager and just engaging. I think a lot of that has to do with the fact that we’ve been locked down for so long. But it’s been just awesome being back on the road and live and in person again. It’s not just great for us. We see the responses in the people that are attending our events, and it’s good to be getting back to normal again.

You’ve been on the road. Is a lot of what you’re talking about QR codes these days?

Yeah. The QR response has been just absolutely phenomenal. From the point that the blog was put up, this research has just taken on an entire life of its own. I know it got picked up by Forbes. We were picked up in the La Parisienne. I’m going to probably mispronounce this, but I think it’s called Nikkai or Nikkei newspaper in Japan. I just did two more interviews with the Thai media while I was in Bangkok. The QR code stuff has just been just blowing up. The fact is, it’s something that affects both consumers as well as enterprise. This is one of those threats that’s pretty much across the board in terms of who’s a target.

The blog post you’re referencing is on the CyberArk blog. Of course, it’s called Step Away From the QR Code and Read These 7 Safety Tips. A lot of what we’re going to talk about here, if folks want to do a little bit of a deeper dive, they can go to that blog post. There’s also a link in that blog post to a webinar that you’ve done on this subject.

To get to the meat of it with QR codes, as we know, over the course of the pandemic, the QR code seemed to have a little bit of an explosion in popularity prior to the pandemic. I think that I’m probably among the majority here, but I thought the QR code was just like a marketing gimmick, and it was set the pasture. When it was at its best, it was lame. Am I wrong?

Prior to the pandemic, no, you’re really not. Realistically, QR codes have been around for almost 30 years. They were originally designed by the Japanese automotive company Denso Wave. Prior, like you said, typically just a kitschy marketing thing outside of APJ, not a lot of heavy adoption in EMEA. But you hit the nail right on the head.

If you take a look at the blog post, there’s actually a slide where you can actually see the statistics of QR adoption prior to the COVID outbreak and then post-COVID outbreak. It just goes through the roof. The problem with that is we were in a situation where we needed to find some way of doing contactless transactions.

Due to that, we saw a lot of heavy pushes from regulatory agencies; governments saying, “Use this. Use this. Use this.” The problem is, is they didn’t really look at the fact that these particular little funny boxes have the exact same capabilities and characteristics of a hyperlink in a spam e-mail. I’ve been saying all along, when it comes to advertisements with QR codes, these are physical forms of spam e-mail. You didn’t ask for it.

I really think if people try to frame it in the same way that we’ve framed the context of our e-mail training campaigns, if this particular advertisement showed up in your spam inbox, would you click it? That’s the link that we really need to try to make.

I guess a prime example—and you can probably tell me some other prime examples if we get into it—but we get back to restaurants. You sit down at a table, and you’ve got the QR code on the table to order. How can that go wrong and what should you be looking for? Because this experience obviously is only getting more popular as time goes by.

Well, before we get into the restaurant, the one that I’d like to showcase before that is our Super Bowl a couple of years ago. That one was the one that really started me thinking about this whole concept.

This was that advertisement where there was just a QR code in the screen-

You got it.

-It was bouncing around, and nobody knew what it was for.

Nobody knew what it was. That QR code, which happened to be for a cryptocurrency broker, was hit 20 million times in one minute.

Nobody knew where it was going. When it comes to the idea of the menus, that has been something that’s been going on since the pandemic started. In my actual blog post, I actually threw up two menus side by side, and the words on the deck slide are, “Can you tell the difference? Which one’s safe?”

The truth is, by looking at them, you really can’t tell. Personally, I will not scan them. One of the things that I’ve been really trying to push is we need to start asking and demanding more accountability from marketing departments around the world. We live in a zero-trust world. If we break down what zero trust means, it’s trust but verify.

How am I supposed to verify when you’re just giving me a QR code? I’m not anti-QR; I’m anti-irresponsible QR. So if you give me a QR code, and then you give me the link that I’m supposed to be getting redirected to, so that way, if I scan it, I can validate that I’m going where I’m supposed to, that’s something different. I’m not saying that all QR codes are bad by any means.

One of the other things that I wanted to point out is the fact that when it comes to this particular concept, I’m strictly trying to focus around the redirection aspects of QR codes, not tokenization or authentication. But from an advertising perspective, we really do need to start demanding that point of reference for a source of truth.

One other example is over…I don’t know if it was either in Hong Kong, or it might have been in Bangkok, but somewhere over in APJ, within the last month—and if you’d like, I can get you the reference so we can include this in the subnotes—there was a drone swarm that was actually utilized to create a giant three-dimensional QR code in the air. Once again, we were back to another situation where everybody that was close was scanning this thing and being redirected somewhere with no idea where they were going. We would never do that in an e-mail situation or any type of corporate environment that we’ve been accustomed to.

So why are people so comfortable doing this? Why is there such little awareness for this issue? Is there ever a time when somebody would be okay to actually scan a QR code where there isn’t a URL listed below it?

[00:11:55.560] – Len Noe
[00:12:28.890] – Len Noe
I think just through the use and the circumstance, we’ve been led to falsely believe that these particular pieces of technology are safe. But anyone who’s deep into security is going to realize you’re just basically activating a hyperlink redirect.

At some point, we’re going to get into what people should be on the lookout for and what they can do to keep themselves safe and best practices around QR codes. What are some of the things that are happening when people scan QR codes that are, I guess, rigged QR codes or whatever you may call them-

[00:13:09.930] – Len Noe
[00:13:09.930] – David Puner
[00:13:11.370] – Len Noe
[00:13:34.320] – Len Noe
[00:13:48.840] – David Puner
[00:13:54.880] – Len Noe
[00:14:24.680] – Len Noe
[00:14:56.070] – David Puner
[00:15:18.540] – Len Noe
[00:15:42.470] – Len Noe
[00:15:58.420] – Len Noe
[00:16:28.200] – David Puner
[00:16:42.090] – David Puner
[00:16:43.330] – Len Noe
[00:17:05.160] – David Puner
[00:17:13.600] – Len Noe
[00:17:51.380] – Len Noe
[00:18:20.820] – David Puner
[00:18:29.690] – Len Noe
[00:18:51.030] – Len Noe
[00:19:27.060] – Len Noe
[00:20:01.040] – David Puner
[00:20:15.290] – Len Noe
[00:20:41.380] – Len Noe
[00:21:02.320] – Len Noe
[00:21:34.000] – Len Noe
[00:21:59.850] – Len Noe
[00:22:26.780] – David Puner
[00:22:42.420] – Len Noe
[00:23:19.710] – David Puner
[00:23:27.180] – Len Noe
[00:23:49.550] – Len Noe
[00:24:02.800] – David Puner
[00:24:16.960] – Len Noe
[00:24:46.820] – Len Noe
[00:25:09.270] – Len Noe
[00:25:33.810] – Len Noe
[00:25:50.120] – Len Noe
[00:26:15.630] – David Puner
[00:26:41.580] – Len Noe
[00:26:58.870] – Len Noe
[00:27:24.460] – Len Noe
[00:27:54.030] – Len Noe
[00:28:18.400] – Len Noe
[00:28:37.630] – David Puner
[00:28:50.940] – Len Noe
[00:29:14.390] – Len Noe
[00:29:58.470] – Len Noe
[00:30:11.010] – David Puner
[00:30:12.170] – Len Noe
[00:30:42.500] – Len Noe
[00:31:04.690] – David Puner
[00:31:18.490] – Len Noe
[00:31:27.890] – David Puner
[00:31:26.970] – Len Noe
[00:32:03.720] – David Puner
[00:32:13.280] – Len Noe
[00:32:22.840] – David Puner
