Potential security breach story of the week, but apparently Sears has responded...according to the article all you needed was a name and address and you were able to locate anyone's purchases...all the way back to 1978..they violated their own security policy...sometimes in a rush I wonder if some of the services are deployed without a full security check in order to meet competition and gain additional marketing and sales...happens in every industry including health care.  BD

San Francisco - Sears Holdings has come under fire from privacy advocates for making the purchase history of its customers publicly available on its Managemyhome.com Web site. This is a violation of Sears' own online privacy policy, which does not allow the company to share users' purchase history with the general public, Edelman said.

In fact, Sears has noticed the problem. "We take our customers' privacy concerns very seriously," the company said in an e-mailed statement. "As a result, we have turned off the ability to view a customer's purchase history on Manage My Home until we can implement a validation process that will restrict access by unauthorized third parties."

Sears puts customers' buying histories on the Web - Yahoo! News

0 comments :

Post a Comment

 
Top
Google Analytics Alternative