
To get a ticket on one of China’s new fleet of 300+ km/h bullet trains locals need to show their ID card, and foreigners must produce their passport, in a move to prevent ticket scalping. Trouble is, your name and ID/passport number is then stored in the QR code that’s printed on the ticket – and is thereby readable by anyone who picks up your old, discarded ticket.
All it takes is a QR code reader app on any smartphone to ‘read’ the info contained in the QR code, which then spills out your name and number, for anyone to see. That’s why, in the photo above, I’ve obscured half of the QR code with my thumb on an old ticket of mine.
People in China are now being advised by Railway Police to rip up their tickets after each train ride – or, more specifically – rip the QR code itself into several pieces, as the rest of the ticket contains no data.
A quick browse through the Android Market reveals a number of apps that can read QR codes (pictured below) – and of course lots can do on iPhone and Symbian devices too.

The Android app developer shows off business card reading & importing from a QR code.
Most of their uses are perfectly innocuous and practical – such as for downloading apps with one click, importing contact data from a business card’s QR code, or social media promotions – but the surfeit of personal data stored in these bullet train tickets now brings this unexpected data leak issue.
Downloading one of these apps, I was indeed able to read my own personal info after scanning the QR code, although amusingly my name was mis-typed, presumably by the lady at the ticket office, since input at point-of-sale is done manually before the tickets are printed.
It seems that no official agencies foresaw this personal data problem when real-name identification for tickets became mandatory, even though QR codes have been in common usage for years.
[Hat-tip: Shanghai Daily]
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.






