
Tower Records exposes three million shoppers' details...
Published: 6 December 2002 10:25 GMT
Music retail giant Tower Records has exposed the personal data of millions of US and UK shoppers at its online store - including email addresses, phone numbers and past purchases.
A glitch on the company's website allowed anyone to view its database of customer orders dating back to 1996, including home addresses, email addresses, phone numbers and what music or video products were purchased. More than three million such records were exposed.
A Tower Records representative said: "It was a technical error, and when we discovered it we were fairly horrified and we fixed it in a matter of hours."
The company said no credit card numbers appear to have been revealed, but the news will do little more the reputation of ecommerce, which has persistently been dogged by security fears.
One Tower Records customer contacted said: "I'm shocked and disappointed. I will no longer do online business with Tower Records."
The security leak arose out of a programming error in a script called "orderStatus.asp." When customers requested information on their order via the Tower Records site, the script called up the record, displaying the order number as part of the URL of the resulting page.
But the script allowed customers to type a different order number into the URL and call up a different record. In the change made Wednesday, Tower Records now requires customers to log in with their email address and password before they can view information about their order.
The blunder is made all the more embarrassing by the company's privacy policy, which says: "Your TowerRecords.com Account information is password-protected. You and only you have access to this information. TowerRecords.com takes steps to ensure that your information is treated securely."
Declan McCullagh writes for News.com
BUSINESS DEVELOPMENT MANAGER AUDIO VISUAL EQUIPMENT - 25-30k basic - 35k OTE Uncapped - MANCHESTER THE ROLE: Home based role selling the full range ...
Providing technical or administrative support for projects when requested. Ensuring that purchase requests for IT materials, are properly authorised ...
Respond when alerted to security events, whether in real time via monitoring tools or through log analysis.Work individually and with other incident ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Seb Janacek Magic Mouse - Apple's best ever? Minority Report: After years of disappointment, one Mac lover has hope
Bethan Jones Can I use a netbook as my everyday work machine? Why silicon.com's sub editor is ditching her laptop for a sprightly mini-laptop