For those who don’t know, it’s where someone takes a QR code like on a poster for a concert and puts a sticker with a different QR code on top to a fake website that looks like the concert website (or a Rick Roll).
The obvious answer is to scratch off the QR code if you notice it’s a sticker, but It’s not always acceptable -or legal- to start damaging stuff to check if it’s real or not. Also what if it’s out of reach on a sign or something?
You can’t put a little text under saying what the website is as a sort of checksum because the vandal can just write their own website under their sticker.
When my phone scans a QR code it shows what the URL text is without needing to go to the URL. Any time you’re thinking about going to a link you gotta consider the risks, but if it says restrauntname.com/menu I’ll feel better about it than if it’s a url shortener
And I could put up a poster that says restaurantname.net/menu