Уровень 0 · материалов: 6
В кластер включаются документы, посвященные анализу механизмов сбора данных, записи экрана и безопасности платежной информации в мобильном приложении Burger King.
Общие признаки: мобильное приложение Burger King, сбор персональных данных, запись экрана через AppSee, безопасность данных банковских карт, нарушение закона 152-ФЗ
Группа выше: Нарушения приватности конкретными продуктами
Смысл: The main idea is to expose a severe privacy violation in the Burger King app, where a third-party tool (AppSee) was used to record user screens, including sensitive credit card information, contrary to the company's public assurances.
A security researcher discovered that the Burger King app secretly records user screens and uploads the video—including credit card entries—to a third-party service.
Смысл: The text is a follow-up investigation proving that the Burger King mobile app secretly records user screens, potentially capturing credit card info, despite company denials and claims of compliance with privacy laws.
The author provides technical evidence proving that the Burger King app records user screens and captures sensitive credit card data, debunking the company's denials.
Смысл: The main idea is to investigate and report on the conflicting claims regarding the Burger King app's use of Appsee for screen recording and user behavior analysis, highlighting the gap between corporate assurances of privacy and the actual terms of the user agreement.
Burger King and Appsee defend their use of screen recording for analytics, claiming sensitive data is hidden, while critics point to extensive personal data collection in the user agreement.
Смысл: The main idea is to verify if the Burger King app compromises user credit card data via screen recording. While the author finds the screen recording (Appsee) to be safe due to masking, they discover that the app's internal logs unintentionally collect and transmit partial credit card details to Burger King's servers.
The Burger King app doesn't steal cards via screen recording, but it does unintentionally log partial card details to its own servers.
Смысл: The main idea is to debunk allegations that the Burger King app steals bank card data by explaining how the AppSee analytics SDK works to mask sensitive information locally on the device before transmission.
e-Legion explains that the Burger King app's screen recording is for analytics and automatically masks sensitive bank data before it is sent to servers.
Смысл: The main idea is that the Burger King mobile app and its operator, OOO 'Burger Rus', commit numerous violations of the Russian Personal Data Law (152-FZ) through lack of transparency, improper consent mechanisms, and unfair user agreement terms.
RosKomSvoboda analyzes the Burger King app and finds systemic violations of Russian data protection laws, ranging from missing privacy policies to illegal data retention practices.