Attack vectors against 2D barcode tickets

Supervisor(s)Markus Riek, MSc


2D barcodes, printed on paper or displayed on smartphones, are increasingly used as a replacement for various travel or entertainment tickets. This thesis should analyze the practical security of these ticketing systems by investigating scenarios of “barcode theft”. The student should outline attack scenarios, investigate one attack in detail, and discuss different protection measures.


  • Kieseberg, P., Leithner, M., Mulazzani, M., et al. QR Code Security. In Proceedings of the 8th International Conference on Advances in Mobile Computing and Multimedia. ACM, New York, NY, USA, 2010, pp. 430–435.
  • Krombholz, K., Frühwirt, P., Kieseberg, P., Kapsalis, I., Huber, M., and Weippl, E. QR Code Security: A Survey of Attacks and Challenges for Usable Security. In T. Tryfonas and I. Askoxylakis, eds., Human Aspects of Information Security, Privacy, and Trust. Lecture Notes in Computer Science 8533, Springer, Berlin Heidelberg, 2014, pp. 79–90.