Skip to main content

Felicia King opens by tearing down the myths around QR codes and taking listeners on a clear, human journey: from frustrated users mistyping long cryptographic secrets to the quiet heroism of modern multi-factor authentication.

Felicia King opens Breakfast Bytes by tearing down the myths around QR codes and taking listeners on a clear, human journey: from frustrated users mistyping long cryptographic secrets to the quiet heroism of modern multi-factor authentication. Through real examples—missed SMS messages with dangerous consequences, stolen mail, and the rise of passkeys—she shows why QR codes often solve real problems, not create them.

With an approachable analogy to paper mail, Felicia explains how context, intent, and the tool you scan with determine risk, and why refusing QR codes can cut you off from essential services. This episode is a short, urgent invitation to rethink convenience and security as partners, not enemies.

https://qpcsecurity.com/qr-codes-are-not-the-problem-understanding-the-difference-between-convenience-and-risk/

QR Code Misperceptions Discussion

Felicia discussed the importance of addressing misperceptions about QR codes, explaining that they are simply graphical encoding formats for storing information such as URLs, phone numbers, or complex data strings. She clarified that QR codes are not complex technology but rather standardized visual formats that can store various types of information.

QR Code Security Uses

Felicia explained that people use QR codes in two main categories: for facilitating security through multi-factor authentication and secure enrollment, or for malicious purposes. She emphasized that QR codes themselves are not inherently risky, comparing them to barcodes on products, where the risk comes from how they are used rather than the technology itself.

Multifactor Authentication User Experience Challenges

Felicia discussed the challenges of multifactor authentication, particularly the inconvenience of manually typing long security codes exceeding 256 characters. She emphasized that while security is important, the technology must remain user-friendly to prevent frustration and abandonment. Felicia noted that if users struggle too many times, they will give up, making the alternative solution unacceptable.

QR Code Security Concerns Discussion

Felicia discussed the security concerns surrounding QR codes, comparing them to receiving mail and emphasizing the need to differentiate between trusted and untrusted sources rather than avoiding them entirely. She explained that QR codes are commonly used for multi-factor authentication enrollment from reputable providers like Microsoft 365, Google, and Proton, and noted that SMS-based MFA mechanisms will be phased out starting Q4 2026. Felicia highlighted the unreliability of SMS delivery, particularly in urgent situations, using examples of elderly individuals trying to transmit time-sensitive medical information.

SMS Security Risks Discussion

Felicia discussed the security risks of SMS messaging, explaining that it cannot be verified who is sending messages or confirm their delivery, making it "atrociously insecure" and high-risk. She noted that many organizations have moved away from SMS-based authentication, including the Social Security Administration, which switched to the ID.me system with more intensive multi-factor authentication requirements. Felicia suggested that people who prefer not to use QR codes for authentication might need additional training, as digital interaction is increasingly common even for basic activities like email use.

Multi-Factor Authentication Evolution

Felicia discussed the evolution of SMS as multi-factor authentication, noting that it was implemented around 2014 but is being discontinued. She explained that modern systems, including those used by the state of Wisconsin, are moving toward more secure authentication methods such as 6-8 digit rolling codes and pass keys. Felicia highlighted that while Microsoft 365 offers sophisticated security features, these are exceptions rather than the standard in most systems, which typically rely on basic username-password combinations with multi-factor authentication.

QR Code Security Best Practices

Felicia explained the difference between safe and risky uses of QR codes, particularly in the context of multi-factor authentication (MFA) enrollment. She clarified that QR codes used for MFA enrollment are secure as they function as graphical representations of cryptographic keys, which should be scanned using authenticator applications like Microsoft Authenticator, Google Authenticator, or password managers. Felicia warned against scanning random QR codes found in advertisements or public places, as these could potentially lead to malicious websites. She also noted that the negative perception of QR codes stems from their association with control mechanisms used during COVID-19, such as contact tracing.

Security and Digital Authentication Models

Felicia discussed the importance of understanding shared responsibility models in security, particularly regarding QR codes and multi-factor authentication. She explained that completely avoiding digital systems, including QR codes, is not practical in today's world, as many essential services require digital verification. Felicia provided an example of a stolen tax refund check to illustrate how physical mail can be insecure, emphasizing that digital alternatives like direct deposit are more secure. She concluded by noting that QR codes themselves are not inherently problematic, but rather the source and context of use are important considerations.