funsec mailing list archives

Re: [privacy] Sears Exposes Customer Purchase History in Violation of Its Privacy Policy


From: "Dude VanWinkle" <dudevanwinkle () gmail com>
Date: Mon, 7 Jan 2008 20:49:15 -0500

On Jan 7, 2008 6:31 PM, Juha-Matti Laurio <juha-matti.laurio () netti fi> wrote:
From Ben Edelman's Web site:
<snip>
1) Go to the Sears "Manage My Home" site, www.managemyhome.com . Create an account and sign in. [Screenshot.]
2) On the Home menu, choose Home Profile. In the Search Purchase History section, choose Find Your Products. 
[Screenshot.]
3) Enter the name, phone number, and street address of the customer whose purchases you wish to view. Press Find 
Products. [Screenshot.]
Sears then displays all purchases its database associates with the specific customer -- typically major appliances 
and other large purchases."
---clip--
Later on Friday the post was updated
'Update (January 4, 5pm): Sears has disabled the search feature described above.'
---clip--
http://www.theregister.co.uk/2008/01/07/sears_privacy_classaction/


Its nice to know that idiocy, when not involved with government, can
actually have repercussions.

Thanks "Yoo Ha",

-JP
_______________________________________________
privacy mailing list
privacy () whitestar linuxbox org
http://www.whitestar.linuxbox.org/mailman/listinfo/privacy


Current thread: