In April 14th, Chen Jinghong provided 5000 takeaway orders for personal information, including hotels and other public places. File screenshot In April 14th, Chen Jing Hong sent 5000 forms of information, including name, telephone and address. Shootme A user order from the takeaway rider Li Defa. Shootme Too many harassing phones make people feel uncomfortable. Xu Xin, a citizen, reflected that he had been given a takeaway at a takeaway platform, and his hotel address, room number, telephone number and other privacy information were leaked. And Xu Xins information is just one of thousands of takeaway information that journalists get. Every time a customer takes a takeaway, he means to upload his information once. But are these privacy information secure enough? Recently, the Beijing News reporters undercover several telephone sales group found that there are sellers specially sell takeaway ordering customers information. The price of each message is less than 10 Fen, including telephone name and reservation address. There are also Internet operators who use software to collect subscribers subscription information, and then sell them to telephone sales companies, and even a number of takeaway riders have been selling business for customer information. Reporters random online survey found that in some QQ group, someone Hawking hungry, Baidu takeaway, the United States and other takeaway platform customer information. A customer service staff member of the network reservation platform, said that the management of information in the United States is very strict, but the user order information involves many links, such as merchants and riders, and does not exclude other factors that lead to information disclosure. Some experts said that commercial companies should improve the information management mechanism, update information protection means in time, and establish a deep protection mechanism. Tens of thousands of messages sell for 800 yuan Chen Jinghongs data is a citizens privacy information, including telephone and address. The Beijing News reporter contacted Chen Jinghong in a telephone sales group. In the chat, Chen Jinghong revealed that his own hands were Beijing, Shanghai, Guangzhou and other first-line cities, from the takeout platform, customer data, 10000 prices 800 yuan, 5000 sales, an average of less than 10 Fen. Chen Jinghong then sent out a screenshot showing a large number of names, contact details and addresses. Chen Jinghong called the data the last three days, but could not extract the specific order date. When the reporter wanted to look at the data, Chen Jing launched a WeChat groups two-dimensional code, and after the scan was the only reporter and his two WeChat group. Chen Jinghong message: 15 minutes to sort out the data to you. In less than 15 minutes, Chen Jinghong sent a Excel form to reporters through QQ, which contained 5000 messages. Like the screenshots, this form includes name, phone number, gender and address, but no date for ordering. Including Chaoyang, Miyun and other districts, data from 16 districts of Beijing are involved. The reporter randomly selected 100 phone numbers from the form to verify. Among them, 61 valid numbers, 33 owners confirm that the information in the form is accurate, and confirm that they have ordered a meal in a takeaway platform in the past one or two months. Yes, thats the address, Ms. Yang, whose address was displayed as CBDs apartment, said she had ordered a dinner at a barbecue shop on a takeaway platform the night before, after hearing the address of the reporter. Reporters rough statistics, in this list of 5000 people, part of it comes from hotels, hotels, shopping malls and other public places. Ms. Zhou, a five star hotel in Fangshan District, recalled that she had used a takeout platform in April 13th when she stayed in the hotel, but she did not remember the contents of the reservation and the specific business. It was too much. Chen Jinghong disclosed that these data will be updated every day at noon, and it will definitely be sold out in the evening. In fact, Chen Jinghong is not the only one who sells customer information. Reporters at the bottom of a number of telephone sales groups found that at least three sellers said they had takeaway customer data. QQ, nicknamed the Rainbow seller, says it has national data, with a price of 600 yuan per 10000, including subscribers name and telephone address, and the reservation information. The Beijing News reporter found that some sellers said there were American groups, hungry, Baidu takeaway customer information, the price of 10000 yuan from 700 yuan to 2000 yuan. Software automatic pick up customer information In addition to selling information directly to the seller, a more covert takeaway customer information access channel emerges. The Beijing News reporter found that some agents operated takeaway outlets were also selling information. A staff member of a network operation company, Qin Huas business is responsible for helping to open (operation) take away shops. He also said that he could find ways to get customer information from a takeaway platform in Chengdu. Name, sex, phone number, address, the number of meals ordered, but how many specific items I need to check to know. Qin Hua said. The price he gave was several times more expensive than the previous seller, 5 cents per item. Qin Hua later explained that the accuracy rate can be guaranteed, and that is the two days. In April 20th, Qin Hua sent a computer screenshot showing a total of 2605 messages. Then another screenshot was sent, and the amount of information was changed to 2609. There are just four more guests ordering, the number will rise any time, Qin said. The mantissa is sent. In this information list, there are 16 addresses from the Internet bar. Many addresses are even accurate to the location of a certain Internet cafe. Reporters verified one by one, in addition to 4 of the main machine phone can not be connected, the other 12 hosts said they did use the address to book a meal. Generally do store operation will buy these information, conversion rate is very high. Qin Hua said that he got the information by crawling his software on the background of some takeaway platforms, and crawling away, the system can not be found. If the information of the merchant is better, anywhere in the country, I can get you all the information in a city one night, including the name of the owner, the name of the store, the address, the phone number. Qin Hua said. Reporter proposed whether will be monitored by the platform system, Qin Hua said that the monitoring is not, this thing you do not have to let businesses know, as long as there is a computer, in the home can operate. Qin Hua then sent a monitor to the reporter, from the list of the screenshots, you can see the name of the user, the phone, the date of registration, the latest consumption, the balance of the storage value and so on. 2800 yuan can be used for one year. Qin Hua said, but he refused to disclose the name of the software. Takeout rider selling orders In the survey of the Beijing News reporters, it was found that the data seller sent two shots of the information of the Wuhan and Beijing catering personnel, asking if they needed. In the subsequent investigation, the Beijing News reporter found that some of the terminal contacts, including some of the takeaway riders, were also used to make profit by using user information. In April 18th, the reporter found the takeaway rider Li De by phone and asked if he could sell the ordering information of the customers. The other party said yes, but the price was slightly higher, one yuan each. This information can be guaranteed on that day, and all the information on the order can be given to you, including the meals ordered from which. Li De said. After talking about the good price, Li De sent the 35 customers ordering information to reporters in April 18th. There are two kinds of information: one is the screenshot of the APP of the rider, and the other is the printed paper ticket. On the second day, Li De asked the reporter whether he needed order information and sent out 34 order sheets for takeaway. According to one of the orders, Ms. Zhang, a 3 term in a Chaoyang District District, ordered a meal at a salad shop, including four volumes including salmon rolls. Ms. Zhang confirmed to reporters that the order was exactly what she ordered. The reporter has verified 20 orders information, except 3 machine owners can not be confirmed, other owners have indicated that the order information is true. Dissension of divulging information on takeout I always receive some sales calls and advertising messages. I feel that my information has been leaked enough, and there is no way to change the phone. Xu Xin, a citizen, told reporters that the hotels address, room number, and phone calls were open secrets because of a takeout. Beijing News reporter combing found that many takeaway platform users have had information leakage experience, and even cause disputes. According to media reports, in December last year, Mr. Chai ordered a takeaway, totaling 31.8 yuan, through the hungry ordering platform. About 10 minutes later, a businessman claiming to be in touch with Mr. Chai said that he ordered the black pepper pork chop to be sold out, and that he needed to make up the difference of two yuan for changing vegetables. The information is very accurate, the information of my order, what food the businessman sells, exactly the same. Mr. Chai said. Then the other let Mr. Chai reported about Alipay digital to receive two dollar difference. After reporting the figures, Mr. Chai found that the other side had already transferred nearly 2000 yuan. The businessman said Mr. Chais meal was not sold out, nor did he call the staff in the store. Mr. Chai suspected that his reservation information was leaked. In addition, in March this year, Mr. Lee, who ordered a takeaway from Harbin, received frequent calls from strangers to find out how to find Miss. Mr. Li, who was overwhelmed by the trouble, finally found that his phone was leaked by a takeaway rider and renoted it as Miss door. Web site users time to stroll the brigade also posted, said he gave his boyfriend a beauty group takeaway, and then a stranger with WeChat. The other person knows his name and address, but he doesnt know him. After questioning several times, the other side admitted that the message was sent to a friend who had taken away the food, and the purpose was to help him out of the list. Beijing News reporter on the information leakage situation call the U. S. regiment customer service phone, a customer service personnel said that the management of information in the United States is very strict, will not disclose the privacy of users. However, user order information involves many links. Businessmen and riders will have user information, and do not include disturbing factors such as sending wrong meals and losing small order tickets. Personal information is still in a dangerous period Zhao Wu, a network security expert and founder of white hat sinks, said that information leaks are constantly occurring, but the corresponding technical safety standards and requirements are still not published, and the personal information of the citizens is still in a dangerous period. For the problem that the takeaway platform is suspected of disclosing customer privacy, Zhao Wu analyses that there may be loopholes in the takeout platform, such as API (Application Programming Interface) without authentication, and network invaders can crawl user information according to order sequence numbers. There have been many similar cases in history, such as the massive leaks of resumes on recruitment websites. The second possibility is to disclose information to third parties who cooperate with businesses. For example, some businesses will engage in some points, rebates, coupons and other activities, these activities are generally undertaken by third party companies. They collect users information in activities, and their data protection is not as tight as platform, so they are easy to be invaded. The previous 12306 website information leakage is such a situation. Zhao Wu said. Zhao Wu introduced that the network security law of China in June last year has been formally implemented, the general guidance requirements have been clear, but the corresponding specific technical safety standards have not yet been introduced, especially for the information supervision of commercial companies. How to prevent information leakage, Zhao Wu said that, on the one hand, the country should introduce specific detailed rules for network security protection as soon as possible, strict legislation requires enterprises to be responsible for security accidents, especially privacy related data disclosure must have a penalty and compensation mechanism, not allow enterprises to increase data leakage caused by black guest attacks do not bear responsibility. A similar exemption clause. At the same time, we must strictly control the utilization of data by the enterprise side, and punish once. On the other hand, the business company should update the means of information protection in time and establish the deep protection mechanism. In the data analysis and use, the sensitive information of the customer can be hidden and replaced by the virtual ID, and then the privacy information is protected by the means of encrypting the two times. In addition, Zhao Wu said that business companies should also improve information management mechanisms, such as what is the algorithm for technology encryption, what kind of people can contact user data and establish detailed technical standards. Pan Xiang, a partner of the Guangdong Zhong An law firm and arbitrator of the Shenzhen Arbitration Commission, introduced the amendment of the criminal law (seven) to make legislation on the crime of infringement of personal information of citizens, which stipulates that the staff of the state organs or financial, telecommunications, transportation, education, medical and other units are in violation of the state regulations to carry out their duties. Or to provide personal information obtained in the course of the service, sell or illegally provide to others, if the circumstances are serious, it is to be sentenced to fixed-term imprisonment of not more than three years or to be in criminal detention, and to be penalized or punished by a single penalty. Stealing or illegally obtaining such information by other means shall be punished in accordance with the provisions of the preceding paragraph if the circumstances are serious. In addition, the network security law is also clear that network operators should take technical measures and other necessary measures to ensure the security of their personal information, to prevent information leakage, damage, and loss. In cases where personal information is leaked, damaged or lost, remedial measures should be taken immediately, informing the user in time and reporting to the competent authorities in accordance with the regulations. (Xu Xin, Chen Jinghong, Tan Hua and Li De are aliases). The source of this article: Beijing News Editor: Bai Xin _NT4464 Pan Xiang, a partner of the Guangdong Zhong An law firm and arbitrator of the Shenzhen Arbitration Commission, introduced the amendment of the criminal law (seven) to make legislation on the crime of infringement of personal information of citizens, which stipulates that the staff of the state organs or financial, telecommunications, transportation, education, medical and other units are in violation of the state regulations to carry out their duties. Or to provide personal information obtained in the course of the service, sell or illegally provide to others, if the circumstances are serious, it is to be sentenced to fixed-term imprisonment of not more than three years or to be in criminal detention, and to be penalized or punished by a single penalty. Stealing or illegally obtaining such information by other means shall be punished in accordance with the provisions of the preceding paragraph if the circumstances are serious. (Xu Xin, Chen Jinghong, Tan Hua, Li De are aliases).