HT TECH wants to start sending you push notifications. Click allow to subscribe

McDonald’s India app ‘leaks’ 2.2mn addresses, phone numbers; card details safe

Fastfood giant McDonald’s said on twitter that their Mobile App – McDelivery – did not store financial data of customers. This was after the technology blog hackernoon reported on Saturday that the app was found to be “leaking” user data for more than 2.2 million users.

By: HT CORRESPONDENT
Updated on: Mar 20 2017, 18:00 IST
Fastfood giant McDonald’s said on twitter that their Mobile App – McDelivery – did not store financial data of customers. This was after the technology blog hackernoon (AP File Photo)

Fastfood giant McDonald's said on twitter that their Mobile App - McDelivery - did not store financial data of customers. This was after the technology blog hackernoon reported on Saturday that the app was found to be "leaking" user data for more than 2.2 million users.

According to a report published on the website by cybersecurity firm Fallible, 'The McDonald's India app, McDelivery is leaking personal data for more than 2.2 million of its users which includes name, email address, phone number, home address, accurate home co-ordinates and social profile links.'

You may be interested in

Mobiles Tablets Laptops
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Vivo X100 Pro 5G
  • Asteroid Black
  • 16 GB RAM
  • 512 GB Storage
₹89,999
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹34,990
Check details
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,380₹51,990
Buy now
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,498
Check details
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,674₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

The report blames an unprotected publicly accessible API endpoint that can be coupled with a series of numbers that act as customer IDs that can be used to obtain access to all users' personal information. The post reported that a curl request to the http://services.mcdelivery.co.in/ProcessUser.svc/GetUserProfile API endpoint served up user data without authentication.

Also read: Looking for a smartphone? To check mobile finder click here.

The writers report that they sent this information to McDonald's in early February and even received an acknowledgement from a Senior IT Manager; but the 'leak' had not been fixed when the report was published.

The official response from McDonald's was posted on their twitter page, "Our website and app do not store any sensitive financial data of users like credit card details, wallet passwords or bank account information." "The website and app has always been safe to use, and we update security measure on regular basis," the tweet said.

However, there was no mention of the security breach of personal data such as phone numbers, home addresses, and social profile links.

In an update to the report on hackernoon, Fallible has reported that McDonalds replied to them that the issue had been fixed; but they said, "he McDonald's fix is incomplete and the endpoint is still leaking data."

They report that they have communicated this opinion to McDonald's again, and are waiting for their response.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 20 Mar, 15:08 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,590₹89,900
Buy now
38% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹34,000
Buy now
31% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹28,999
Buy now
57% OFF
Honor Pad X8
  • Blue Hour
  • 3 GB RAM
  • 32 GB Storage
₹10,498₹24,294
Buy now
18% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹92,939₹112,898
Buy now
38% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹32,790₹52,999
Buy now
28% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹21,490₹29,990
Buy now
36% OFF
Infinix INBook X1 Pro Laptop
  • Black
  • 8 GB RAM
  • 256 GB SSD
₹44,990₹69,999
Buy now
29% OFF
Asus VivoBook 15 X515JA EJ522TS Laptop
  • Grey
  • 8 GB RAM
  • 512 GB SSD
₹44,689₹62,889
Buy now