Feeds

Compaq leaves customer details open for all to see

Hits 7.5 out of 10 on the stupidometer

  • alert
  • submit to reddit

Protecting against web application threats using SSL

Compaq has outdone itself by leaving extensive customer details for anyone to see on the Internet. For some reason it has decided that everyone in the world ought to be able to see everyone who has bought a Pocket PC 2002 upgrade.

And that means name, address, customer number, order number - it only stops short of giving credit card details, although we suspect enough information is here for someone imaginative to come up with something. There are ten of thousands of people here. If you're a reseller, it's a dream come true.

We had a quick poll in the office and decided this was a 7 out of 10 on the online stupidometer. However the fact that the accessible Web pages actually sport a link to Compaq's privacy policy added another 0.5 to the score.

We had a quick check of the policy to see if "we may, at our discretion and when we deem relevant, leave your details on the Web for anyone in the world to view" but couldn't find it. Instead we found this: "We do not sell, trade, or rent to others the Personally Identifiable Information we collect online. Unless we have your permission, we will share the Personally Identifiable Information you provide online only with other Compaq entities and/or businesses that provide services to Compaq and only for the purposes described above. Where Compaq engages third parties to perform services on our behalf, we will require them to observe the intent of this Online Privacy Statement."

Doesn't quite gel does it? Anyway, if Compaq would like to get in touch, we'll tell it where the gaping hole is. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.