Car-sharing and e-scooter users' data were left unprotected.

Car-sharing and e-scooter users' data were left unprotected.

      Specialists found more than 400 vulnerabilities in Russian carsharing and kickscooter services, 25 of which were deemed critical. This was reported by the newspaper Kommersant.

      The analysis was carried out on the 13 most popular applications. Experts did not disclose their names. It turned out that some services store passport photos, bank card data and users’ geolocation in plain view. In some applications there are no protection mechanisms at all when used on compromised devices.

      Appsec Solutions reminds that such services collect a huge amount of personal information. For carsharing this includes driving licences and payment data, while for kickscooter sharing it is personal information necessary for recording traffic violations.

      The companies themselves say there are no risks for customers. Thus, Delimobil stated that personal data are stored outside the mobile application and the service’s code is regularly checked. Citydrive also insists that information is stored on servers in encrypted form and no leaks have been recorded.

      At the same time, the press services of MTS Urent and Whoosh declined to comment.

Другие Новости Кирова (НЗК)

Car-sharing and e-scooter users' data were left unprotected.

The user data of car and scooter rental services are at risk — specialists have discovered more than 400 vulnerabilities in their apps.