Feeds

Petco settles with FTC over cyber security gaffe

Sentenced to 20 years' maximum security

  • alert
  • submit to reddit

Boost IT visibility and business value

Pet supply retailer Petco Animal Supplies Inc. will be on a short cybersecurity leash for the next 20 years to settle a Federal Trade Commission action over a security hole on its e-commerce site that may have left as many as 500,000 customer credit card numbers exposed to hackers.

The settlement stems from an incident first reported by SecurityFocus in June of last year, when then 20-year-old independent programmer Jeremiah Jacks discovered that Petco.com suffered from an SQL injection vulnerability that left its database open to anyone able to construct a specially-crafted URL.

SecurityFocus notified Petco of Jacks' discovery, and the company immediately blocked access to the vulnerable web page. The company worked over a weekend to close the hole, and said it had hired a computer security consultant to assist in an audit of the site. Jacks also co-operated with Petco, which said at the time that it found no evidence that anyone previously exploited the hole, which, according to the FTC, had been present since the site's launch in February 2001.

The episode prompted an FTC investigation into alleged deceptive trade practices by Petco, based on the company's privacy policy, which was sprinkled with such reassurances as: "At PETCO.com, protecting your information is our number one priority, and your personal information is strictly shielded from unauthorized access." Under the terms of the settlement announced Wednesday, Petco is prohibited from misrepresenting the extent to which it protects the security of customers' personal information. The company must also establish and maintain a comprehensive information security program, certified by an independent professional every two years for the 20-year life of the order. Any violation can trigger an $11,000 fine.

"Petco is committed to keeping all customer information obtained through our website and stores private and secure, and we have taken - and will continue to take - necessary measures to achieve that goal," the company said in a statement Wednesday. "The agreement we've entered into with the Federal Trade Commission is neither an admission of any violation of law nor that facts in the FTC draft complaint are true."

Programmer's second case

The Petco probe is the FTC's fifth cybersecurity case, and the second for which Jacks can take credit. In February 2002 Jacks discovered a similar SQL injection hole at the website of fashion-retail Guess that exposed, at his count, over 200,000 credit card numbers with corresponding names and expiration dates. Jacks co-operated with the FTC in the resulting investigation, which settled last year under terms nearly identical to the Petco case.

Jacks found Petco vulnerable after a print journalist reporting on the Guess settlement asked him how prevalent SQL injection holes were on the Internet, prompting the young coder to check a few other large e-commerce sites for similar bugs, he says. He says the accessible Petco database contained 500,000 credit card entries. Neither Petco nor the FTC have commented on the number of cards that were at risk.

Jacks, now 22, lives in Orange County, California, working on programming projects for area internet firms and learning the ropes of e-commerce. "Eventually, I do want to fall into security, but I want to be well-rounded," he says. He believes SQL injection vulnerabilities remain widespread, but says he isn't interested in sparking any more federal investigations into Fortune 500 companies. "I don't want to have any legal trouble. I don't need that in my life right now."

Perhaps wary of appearing aligned with hackers, the FTC has not acknowledged Jacks' role in building the commission's cyber security caseload.

The FTC stepped into the business cyber security arena in 2002, when it won a consent decree against Eli Lilly for the inadvertent disclosure of the e-mail addresses of 669 Prozac users. Since then it's won settlements from Microsoft, Guess, and Tower Records, all based on security breaches that appeared at odds with claims made in company privacy policies.

FTC attorney Alan Sheer says the commission has no way to gauge if the cases are making a difference: "Certainly we hope that firms are paying attention to the actions that we're taking and are making appropriate changes to their practices."

Copyright © 2004, SecurityFocus logo

Related stories

FTC probes PetCo.com security hole
PetCo plugs credit card leak
Confusion reigns after FTC spam summit

Maximizing your infrastructure through virtualization

More from The Register

next story
Stick a 4K in them: Super high-res TVs are DONE
4,000 pixels is niche now... Don't say we didn't warn you
BBC goes offline in MASSIVE COCKUP: Stephen Fry partly muzzled
Auntie tight-lipped as major outage rolls on
Philip K Dick 'Nazi alternate reality' story to be made into TV series
Amazon Studios, Ridley Scott firm to produce The Man in the High Castle
iPad? More like iFAD: We reveal why Apple fell into IBM's arms
But never fear fanbois, you're still lapping up iPhones, Macs
Amazon Reveals One Weird Trick: A Loss On Almost $20bn In Sales
Investors really hate it: Share price plunge as growth SLOWS in key AWS division
Bose says today is F*** With Dre Day: Beats sued in patent battle
Music gear giant seeks some of that sweet, sweet Apple pie
There's NOTHING on TV in Europe – American video DOMINATES
Even France's mega subsidies don't stop US content onslaught
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
Too many IT conferences to cover? MICROSOFT to the RESCUE!
Yet more word of cuts emerges from Redmond
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.