Slide 30
Slide 30 text
AEROEXPRESS
• Locally stored data [Android: Plaintext/Protected], [iOS: Strong Protected]
• Tickets + QR code, Email, Phone, Password, Screenshot of any app windows (iOS only)
• Network data [Weak]
• Email, Phone, Password, Unique UserID, Last Login Time, email & phone confirmed, DeviceID,
• OrderID, Base64(hash of Order), Order URL, Order date, Trip date, cost of order,
• TicketID, Route Info, ticket GUID, token, ticket QR Code
• Bank Card info (number, cvv, name, expiration), tokens, *aeroexpress.ru, *ruru, *bank (AlfaBank)
• According to release notes & PCI DSS, App doesn’t store bank card info (payment data).
You can’t input that data type manually. However,
• iOS: Doesn’t store data after successful payment
• Android: Stores data after successful payment
• Both: Continue stores data after update - if previous version wasn’t removed and data not wiped
2013 2014 2015 2016
Weak Weak Weak Weak, Expect to remove
local card info but fail