Feeds

Sears sued for website that leaked customer purchases

Hackers get what they want

Beginner's guide to SSL certificates

Sears Roebuck and Co. is taking more flack from privacy advocates who say the retailer's websites don't adequately protect customer privacy.

On Friday, a Sears customer filed a suit in Illinois state court alleging the retailer's Managemyhome.com website is "fatally flawed and was designed in such a way as to significantly compromise the private information of its customers." The complaint, which requests class-action status, seeks a court order requiring customer data be secured on the site and an award for damages.

The complaint was filed on behalf of Christine Desantis, a customer whose details about 10 purchases made over eight years was made available to anyone savvy enough to exploit the bug. She doesn't know if anyone actually accessed the information.

"At the most simple level, anyone can now access Sears’s customers private purchase history, meaning that a nosy person can find out how much his neighbor spent on a new washing machine or lawnmower," the complaint alleges. "More problematically, marketing companies can mine the Managemyhome website for data about Sears customers, in order to transmit detailed advertisements for additional products and/or warranties."

It goes on to say hackers could troll for information that could be used for identity theft and other "insidious" purposes.

The complaint was filed by the same law firm that successfully pursued Sony BMG over millions of compact disks that surreptitiously installed a rootkit on PCs. It was filed the same day that Harvard University researcher Ben Edelman documented how the Sears site violated its own privacy policy by exposing customer purchases. Sears says it has since disabled the ability to view a customer's purchase history on the site until it can implement a validation process that will restrict access by unauthorized third parties.

Edelman showed how it was possible for anyone with a user account on the Managemyhome site to view the purchases of other Sears customers by entering their name, street address and phone number.

The revelation came three days after Edelman documented how a separate Sears web property was installing software from ComScore that monitored all web activity on a user's computer. Sears only warned users of the privacy implications of the software on the tenth screen of a 54-screen license agreement, prompting criticism that the notice was inadequate.

"We've gotten a lot of positive response to the filing of our suit and a lot of people wanting to make sure that Sears fixes the problem sooner rather than later," said Jay Edelson, an attorney who filed Friday's lawsuit against Sears. He said his firm is considering filing a separate complaint over the installation of ComScore software.

Representatives from Sears declined to comment on the suit or the criticism of its privacy policies beyond a statement that said it had added the purchase history functionality to give customers easy access to useful information.

"We take our customers' privacy concerns very seriously," the statement read. "We appreciate the efforts of those who brought the issue to our attention." ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Lords take revenge on REVENGE PORN publishers
Jilted Johns and Jennies with busy fingers face two years inside
Yes, yes, Steve Jobs. Look what I'VE done for you lately – Tim Cook
New iPhone biz baron points to Apple's (his) greatest successes
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Facebook pays INFINITELY MORE UK corp tax than in 2012
Thanks for the £3k, Zuck. Doh! you're IN CREDIT. Guess not
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.