Feeds

Sears sued for website that leaked customer purchases

Hackers get what they want

Reducing the cost and complexity of web vulnerability management

Sears Roebuck and Co. is taking more flack from privacy advocates who say the retailer's websites don't adequately protect customer privacy.

On Friday, a Sears customer filed a suit in Illinois state court alleging the retailer's Managemyhome.com website is "fatally flawed and was designed in such a way as to significantly compromise the private information of its customers." The complaint, which requests class-action status, seeks a court order requiring customer data be secured on the site and an award for damages.

The complaint was filed on behalf of Christine Desantis, a customer whose details about 10 purchases made over eight years was made available to anyone savvy enough to exploit the bug. She doesn't know if anyone actually accessed the information.

"At the most simple level, anyone can now access Sears’s customers private purchase history, meaning that a nosy person can find out how much his neighbor spent on a new washing machine or lawnmower," the complaint alleges. "More problematically, marketing companies can mine the Managemyhome website for data about Sears customers, in order to transmit detailed advertisements for additional products and/or warranties."

It goes on to say hackers could troll for information that could be used for identity theft and other "insidious" purposes.

The complaint was filed by the same law firm that successfully pursued Sony BMG over millions of compact disks that surreptitiously installed a rootkit on PCs. It was filed the same day that Harvard University researcher Ben Edelman documented how the Sears site violated its own privacy policy by exposing customer purchases. Sears says it has since disabled the ability to view a customer's purchase history on the site until it can implement a validation process that will restrict access by unauthorized third parties.

Edelman showed how it was possible for anyone with a user account on the Managemyhome site to view the purchases of other Sears customers by entering their name, street address and phone number.

The revelation came three days after Edelman documented how a separate Sears web property was installing software from ComScore that monitored all web activity on a user's computer. Sears only warned users of the privacy implications of the software on the tenth screen of a 54-screen license agreement, prompting criticism that the notice was inadequate.

"We've gotten a lot of positive response to the filing of our suit and a lot of people wanting to make sure that Sears fixes the problem sooner rather than later," said Jay Edelson, an attorney who filed Friday's lawsuit against Sears. He said his firm is considering filing a separate complaint over the installation of ComScore software.

Representatives from Sears declined to comment on the suit or the criticism of its privacy policies beyond a statement that said it had added the purchase history functionality to give customers easy access to useful information.

"We take our customers' privacy concerns very seriously," the statement read. "We appreciate the efforts of those who brought the issue to our attention." ®

Security and trust: The backbone of doing business over the internet

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
JINGS! Microsoft Bing called Scots indyref RIGHT!
Redmond sporran metrics get one in the ten ring
Driving with an Apple Watch could land you with a £100 FINE
Bad news for tech-addicted fanbois behind the wheel
Murdoch to Europe: Inflict MORE PAIN on Google, please
'Platform for piracy' must be punished, or it'll kill us in FIVE YEARS
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
Sony says year's losses will be FOUR TIMES DEEPER than thought
Losses of more than $2 BILLION loom over troubled Japanese corp
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.