Free cybersecurity awareness tool
CyberLab QR
A free, hands-on demonstration that shows any audience how much an ordinary web page can quietly learn, remember and persuade. Run it in a company or a classroom in minutes. Everyone uses their own phone, and nobody is hacked.
What your audience will learn
In one short, memorable session, a room of people sees for themselves how everyday online trust is quietly exploited.
What a web page can read the instant it loads, without anyone filling in a form.
How a website recognises a returning visitor with no name and no login.
How a tempting offer leads people to grant location, camera and microphone access.
Why a permission prompt deserves a second of thought before you tap allow.
That a page you leave open keeps talking to its server and can change on its own.
The real lesson: most attacks begin with ordinary trust, not clever code.
How the session flows
Three QR codes, each one a little more revealing than the last. This is what people see on their own phones.
You told me nothing.
Yet the browser already revealed the device, language, timezone and more.
Welcome back.
A new QR code. A new page. Yet the website recognises this browser. No name required.
A tempting offer.
A "free offer" asks for location, camera and microphone access, one small tap at a time. Fully customisable per session.
What the room sees
While everyone scans on their phones, a shared screen tells the story live, and lands the point at the end.
What to say at each moment
You do not need to be technical. Let the room's own numbers do the talking. Here is a simple script for each result as it appears on the screen.
QR1 What a page reads on load
- Nobody typed anything, yet the screen shows their device, browser, language and timezone.
- Every site receives this automatically, just by being opened. It is how you get profiled without agreeing to anything.
- Tracking networks combine these signals into a "fingerprint" that can recognise a browser with no cookie at all.
- Ask the room: did anyone agree to share this? No. It was sent simply by visiting.
QR2 Cookies and being remembered
- A new code and a new page, yet the site recognises the browser. This is cookies at work.
- Explain it simply: on the first visit the site stored a small tag in the browser, like a cloakroom ticket. The browser hands it back on the next visit, so the site knows it is you.
- No name, no login, no password. The same trick, used across many sites, is how adverts follow you around after one glance at a product.
- This is what "accept all" on a cookie banner is really agreeing to.
- The browsers that were not recognised had cookies cleared or used private mode. That is the everyday defence.
QR3 Persuasion and permissions
- Watch the funnel fall: how many still allowed location, camera and microphone, and even sent a photo, for a fake free offer.
- Nothing was hacked. Everyone tapped allow themselves. The reward and the sense of urgency did the work.
- This is exactly how phishing works: a tempting or urgent hook, then a small ask, then a bigger one. Free data, a parcel to reschedule, an account to verify.
- The lesson: pause at every permission prompt and ask, why does this need that?
Reveal Trust, not hacking
- The score measures trust, not intelligence. Keep it light and playful, never singling anyone out.
- Their page changed with no refresh, because it stayed connected to the server. A website cannot control a phone, but a page you leave open can keep talking and changing.
- Close on the core message: most attacks do not begin with clever code. They begin with ordinary trust.
Tip: pause after each results slide and let the numbers land. A show of hands works better than picking on individuals, and the tone should stay curious rather than critical.
Who it is for
Companies
Security awareness, staff onboarding and lunch-and-learn sessions that people actually remember.
Schools and universities
Digital literacy and online safety lessons for students, brought to life on their own phones.
Community groups
Libraries, youth programmes and parent evenings raising everyday cyber awareness.
Free to use, always
CyberLab QR is a public resource from The Goodwill Ledger. No account, no sign-up, no licence and no cost. Bring a screen and your audience's phones, and you are ready.
Start a sessionFrequently asked questions
Is it really free?
Yes. CyberLab QR is a free public resource from The Goodwill Ledger. There is no account, no licence and no payment, for a company or a school.
Do participants need to install anything?
No. Everyone scans a QR code with their phone camera and an ordinary web page opens. Nothing is downloaded or installed.
Is anyone actually hacked?
No. It is a controlled, honest demonstration. It reveals what a web page can read and what people choose to allow. It never breaks into a device or takes control of a phone.
What data does it collect?
Only what the demonstration needs to make its point: coarse device and browser details, the actions people take, and the outcome of permission prompts. It does not collect names, email addresses, phone numbers, passwords or precise location.
What happens with the camera photos?
The camera step is optional and set per session. Depending on the setting you choose, photos may never be stored, or stored only for a moderator to review, or shown on the projector. Stored photos are deleted on a short retention schedule.
Can I use it with students or minors?
Yes, with care. Pick a session setting that matches your consent situation, and secure the appropriate school or parental consent before capturing or displaying any photo. You can also switch the camera off entirely.
How many people can join one session?
It is designed for large rooms. A single session can handle a big group scanning and interacting at the same time.
What do I need to run a session?
A screen or projector to show the QR codes and the live results, plus your audience's own phones. That is all.
Do I need to sign in?
No. Anyone can start a session and present. Just open Start a session and go.
For educational use only. CyberLab QR is designed for controlled cybersecurity awareness demonstrations. It is not intended for surveillance, credential collection or unauthorised access.