Your boarding pass just before take-off, the concert ticket that has just landed in your inbox, the card with the Wi-Fi details of the flat you’re renting for the weekend. These are photos people post without a second thought, and for an understandable reason: a QR code looks like an abstract pattern, meaningless to anyone who glances at it.
To a person, it is. To a phone camera, it isn’t. A QR code — the square of tiny black and white modules you read by pointing a camera at it — is text written in a form that machines decode in an instant, even from a posted photo or a screenshot. How QR codes work is explained in a separate post; here one point is enough: what’s inside isn’t protected, it’s simply written in another language.
So the useful question isn’t “who would bother scanning my photo?” but rather: if someone did scan it, what would they get?
This post answers it by looking at the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they help you see that the damage from an exposed code is never of just one kind.
It expands on the recommendation about posting photos with QR codes.
Three questions to measure an impact
Before you post a photo with a code in it, these are the questions worth asking:
- What could someone who scans this code read? — this is the confidentiality question.
- What could they change, use or duplicate in my name? — this is the integrity question.
- What might I no longer be able to do if someone used it before me? — this is the availability question.
Applied to the QR code on a poster, they produce an answer close to nothing: it points to a public website, the same for everyone. Applied to a boarding pass or a named ticket, the answer changes. This is the rule of thumb: a code weighs as much as what it opens, and personal codes open something that belongs only to you.
1. Confidentiality: information stays with the people entitled to see it
Confidentiality is the guarantee that information can be read only by those who are authorised to read it. A personal QR code in a public photo weakens it quietly: it extends permission to read to anyone who sees the post, including later on, if the image is saved or shared again.
A practical example
You post your boarding pass with the caption “Off we go”. The code — a QR code or a similar two-dimensional barcode — usually holds your full name, booking reference, flight number, date and seat. With your surname and booking reference, in many cases, anyone can reach the airline’s “manage my booking” area, the same page you use to pick your seat.
What the incident looks like
That page may show information that wasn’t visible in the photo: the phone number and email address you gave when booking, your return flight, the names of the people travelling with you and, on some international routes, the passport or ID details entered at check-in. Something similar applies to other codes: a Wi-Fi code holds the network name and password in plain text; the QR code on a badge may carry a personal identifier. Nobody had to break anything: the code simply handed over what it contained.
What to watch for
- emails or text messages confirming access to, or changes in, a booking that you didn’t make;
- messages that mention your exact flight, event or order, from senders you don’t know;
- unknown devices connected to your home Wi-Fi;
- comments or private messages that repeat details found only in the code.
The signs someone used your QR code are gathered together in a dedicated post.
What to do
Before posting, look at the photo the way a camera would: if there’s a code, cover all of it with a solid block, and cover the booking reference and the numbers printed next to it too, since they often repeat the same content in plain text. If the photo is already online, taking it down reduces future exposure; the Wi-Fi password is worth changing.
2. Integrity: information stays correct
Integrity is the guarantee that data isn’t altered by anyone without the right to do so. Here an exposed code matters in a different way: it’s no longer about what someone can see, but about what they can change or reproduce in your name.
A practical example
With the surname and booking reference taken from your boarding pass, someone opens the flight booking and changes your seat, removes an extra you paid for, edits the contact email or, where the website allows it, cancels the trip. The system isn’t under attack: it is carrying out an instruction that looks like yours, because it comes with your details.
What the incident looks like
For a concert ticket the mechanism is even more direct: the QR code is the ticket. Anyone with the photo can reprint it or show it on a screen, and from that moment there are two identical copies that the scanner at the gate can’t tell apart.
There’s also a less visible effect: the details read from the code can be used to write very convincing messages — “your flight has been rescheduled, confirm here” — that lead to fake pages. That’s how an exposed detail turns into an invitation to a harmful website: your code isn’t dangerous in itself, but it makes the next request believable. The ways QR codes are used to deceive people are described in the post on QR code attacks.
What to watch for
- confirmations of seat changes, cancellations or new contact details that you didn’t request;
- the ticket showing as “transferred” or “reissued” in the organiser’s account area;
- messages about a change of plan that ask you to click a link or pay a difference.
What to do
If a booking has been exposed, open it from the official website or app — never from links you’ve received — and check contact details, extras and seats. Many organisers can reissue a ticket, which makes the old code useless: it’s worth asking.
3. Availability: you can get in when you need to
Availability is the guarantee that you can use a service at the moment you need it. With QR codes it’s the most tangible impact: it shows up at a turnstile or a parcel locker.
A practical example
You reach the stadium entrance, show your ticket and the scanner makes an unfamiliar sound: the code has already been used. Someone got in before you with the copy taken from your photo.
What the incident looks like
Entry systems generally accept the first scan and reject any after it. Whoever arrives second, even the rightful ticket holder, stays outside until they can prove it. The same pattern applies to the collection code for a parcel locker, to a prepaid voucher, or to an online check-in that has been cancelled and has to be redone at the airport. The damage isn’t only the service you miss: it’s the time, the stress and sometimes a ticket you have to buy again.
What to watch for
- the code shows as “already validated” or “already used” when you present it;
- the parcel shows as collected although you never went to the locker;
- your check-in has been cancelled or your seat reassigned;
- you can no longer get into your account area because the contact email has changed.
What to do
Keep your purchase confirmation and allow a little extra time at entrances. If a personal code has been posted, contact the organiser before the event: a calm reissue is far simpler than an argument at the turnstile.
| Aspect | What someone who scans the photo can do | Why it matters |
|---|---|---|
| Confidentiality | Read your name, booking details, contact details, Wi-Fi password, identifiers | The harm happens even if you never notice |
| Integrity | Change or cancel bookings, duplicate tickets, use your details for convincing messages | What the systems record no longer matches what you chose |
| Availability | Use the code first, collect in your place, lock you out | You’re left out at exactly the moment you need access |
One scenario that brings them together
Mark is off to a conference. At the airport he photographs his boarding pass next to his coffee and posts it on his public profile.
Someone scans it. From the code they get his name and booking reference, open the flight booking and see the return flight three days later, his phone number and his email address (confidentiality). They change the contact email (integrity). Two days later Mark receives a text message that seems to come from the airline: his return flight has been cancelled, “rebook your seat here”. Official updates now go to the new address, and his return check-in no longer shows up (availability).
Three different impacts, one single cause: a photo taken in ten seconds, with a code nobody had covered. The consequences of posting a boarding pass follow this story beyond the technical level, to the effects on time, money and work.
The impacts that show up later
Not every effect appears straight away, which is why “the photo has been up for days and nothing has happened” isn’t a reliable check.
- Photos saved and shared again. A posted image can be saved or forwarded: removing it from your profile doesn’t recall the copies.
- Codes that stay valid. A booking can be looked up until the trip and often afterwards; a Wi-Fi password stays the same until you change it; a badge works until it’s replaced.
- Details used to make another request believable. Destination, dates and travel companions are ideal material for a message that looks legitimate.
- Information that adds up. The code says what and when; the caption, the comments and any location attached to the photo say where. Location is a topic of its own, covered in the recommendation on photos without your location: what matters here is that the two reinforce each other.
This isn’t a reason to stop sharing your trips. It’s the reason protection has to come first: covering the code before you post reduces all four of these effects, including the ones you’ll never see. Who sees your posts matters too: the recommendation on connecting only with people you know deals with that.
Not all QR codes weigh the same
The impact depends on what the code contains and what it lets someone do.
| Type of code | Main impact | Why |
|---|---|---|
| Boarding pass | All three | It opens the booking: personal details, changes, check-in |
| Ticket for concerts, matches, museums | Integrity and availability | The code is the ticket: it can be duplicated, and the first scan wins |
| Home or office Wi-Fi | Confidentiality | It holds the network password in plain text |
| Parcel collection, vouchers, top-ups | Availability | Whoever uses it first collects or spends in your place |
| Badges, cards, named season tickets | Confidentiality and integrity | Personal identifiers, sometimes reusable |
| Certificates and documents with a verification code | Confidentiality | They may lead to personal or health data |
| Public QR codes on menus, posters, websites | Low in itself | They point to content that’s the same for everyone |
The last row is the reassuring one: not every little square is a secret. The rule stays the same — a code tied to your name, your purchase or your home gets covered.
Why a half-covered code still matters
QR codes are designed to be readable even when damaged: part of their content is redundant, meaning it’s repeated as a built-in check, precisely so they survive folds, stains and scratches. For anyone posting a photo, this has a practical consequence: partial covering often isn’t enough.
| How it looks in the photo | Why it’s still risky |
|---|---|
| A small emoji in the middle of the code | The redundant part rebuilds what’s missing |
| A slightly blurred or grainy code | Many readers compensate and decode it anyway |
| Code covered, but booking reference printed next to it | The detail is right there, in plain text |
| Code reflected in a mirror or on another phone’s screen | A flipped or angled image can still be read |
| A story that disappears after 24 hours | Anyone watching can save it or photograph it first |
A solid block over the whole code and the details printed next to it is the dependable choice; how to hide a QR code in a photo explains how to do it on your phone.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that a personal QR code is readable data, not a pattern, and that exposing it has impacts on different levels |
| Skills | Being able to read confidentiality, integrity and availability as three questions to ask before posting a photo |
| Secure Behaviour | Fully covering codes and printed details before sharing, and having anything already exposed reissued |
Reference level: FL2 — Beginner. This is the level at which you move from “I know I shouldn’t post my boarding pass” to “I understand what happens if I do.” Awareness of the impacts is what keeps the behaviour steady over time. To see where you stand on your other digital habits, you can take the digital resilience self-assessment.
Summary
- Confidentiality is about what the code hands over: name, booking details, contact details, documents, Wi-Fi password.
- Integrity is about what gets done in your name: bookings changed or cancelled, tickets duplicated, messages built from your details.
- Availability is about what gets taken from you: entry refused because the ticket shows as already used, a parcel collected by someone else, a cancelled check-in.
A personal QR code in a public photo doesn’t produce just one impact: it opens the door to all three.
One thing to do today. Scroll through the photos you’ve posted in recent months and look for tickets, boarding passes, Wi-Fi cards and shipping labels. For each one, decide: remove it, or replace it with a covered version. If it’s a booking that’s still active, check it from the official website; if it’s your network password, change it. It takes about ten minutes, and it covers all three impacts at once.
Related content
- Posting photos with QR codes — the recommendation this expands on
- Consequences of posting a boarding pass — from technical impacts to concrete effects on time, money and work
- Signs someone used your QR code — how to notice that one of these impacts is already under way
- How to hide a QR code in a photo — what to do before posting, and afterwards if the photo is already online
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- How to Recognise Phishing When It Is Built to Be Convincing
- Home Network Security: The Router Nobody Configures
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



