Feeds

Sears sued for website that leaked customer purchases

Hackers get what they want

The Essential Guide to IT Transformation

Sears Roebuck and Co. is taking more flack from privacy advocates who say the retailer's websites don't adequately protect customer privacy.

On Friday, a Sears customer filed a suit in Illinois state court alleging the retailer's Managemyhome.com website is "fatally flawed and was designed in such a way as to significantly compromise the private information of its customers." The complaint, which requests class-action status, seeks a court order requiring customer data be secured on the site and an award for damages.

The complaint was filed on behalf of Christine Desantis, a customer whose details about 10 purchases made over eight years was made available to anyone savvy enough to exploit the bug. She doesn't know if anyone actually accessed the information.

"At the most simple level, anyone can now access Sears’s customers private purchase history, meaning that a nosy person can find out how much his neighbor spent on a new washing machine or lawnmower," the complaint alleges. "More problematically, marketing companies can mine the Managemyhome website for data about Sears customers, in order to transmit detailed advertisements for additional products and/or warranties."

It goes on to say hackers could troll for information that could be used for identity theft and other "insidious" purposes.

The complaint was filed by the same law firm that successfully pursued Sony BMG over millions of compact disks that surreptitiously installed a rootkit on PCs. It was filed the same day that Harvard University researcher Ben Edelman documented how the Sears site violated its own privacy policy by exposing customer purchases. Sears says it has since disabled the ability to view a customer's purchase history on the site until it can implement a validation process that will restrict access by unauthorized third parties.

Edelman showed how it was possible for anyone with a user account on the Managemyhome site to view the purchases of other Sears customers by entering their name, street address and phone number.

The revelation came three days after Edelman documented how a separate Sears web property was installing software from ComScore that monitored all web activity on a user's computer. Sears only warned users of the privacy implications of the software on the tenth screen of a 54-screen license agreement, prompting criticism that the notice was inadequate.

"We've gotten a lot of positive response to the filing of our suit and a lot of people wanting to make sure that Sears fixes the problem sooner rather than later," said Jay Edelson, an attorney who filed Friday's lawsuit against Sears. He said his firm is considering filing a separate complaint over the installation of ComScore software.

Representatives from Sears declined to comment on the suit or the criticism of its privacy policies beyond a statement that said it had added the purchase history functionality to give customers easy access to useful information.

"We take our customers' privacy concerns very seriously," the statement read. "We appreciate the efforts of those who brought the issue to our attention." ®

Build a business case: developing custom apps

More from The Register

next story
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
US judge: YES, cops or feds so can slurp an ENTIRE Gmail account
Crooks don't have folders labelled 'drug records', opines NY beak
ONE EMAIL costs mining company $300 MEEELION
Environmental activist walks free after hoax sent share price over a cliff
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.