📜 ⬆️ ⬇️

What threatens burger king

For those who have not yet read the news about how Burger King integrated the unwanted AppSee software into their mobile application, I publish brief information:


Even if you believe that both statements are correct, all the same, Burger King violates the security standard by sending a video file to AppSee: you can’t transfer the expiration date and owner name with the card number (PAN). About the phone, I generally keep quiet. This is a direct violation of PCI DSS in particular and common sense in general. Normal MITM in public WiFi to organize a leak DK, and the phone number is generally the easiest way to get a duplicate sim card in any office using the name of the owner and basic skills of the graphic editor.

The Burger King company itself has passed the test of standards , which means it falls under all punitive measures, namely:

  1. Heavy fines
  2. QSA re-audits
  3. Lower certification level

In conclusion, I would like to add that such standards as GDPR or 152-FZ, to which they appeal, act on certain geopolitical areas, while PCI DSS is an international standard of payment systems and cannot be violated anywhere.

')

Source: https://habr.com/ru/post/417165/


All Articles