You are here: silicon.com > Hardware > PDAs

PDAs

Is this the biggest digital blunder ever?

Tower Records exposes three million shoppers' details...

By Declan McCullagh

Published: 6 December 2002 10:25 GMT

Music retail giant Tower Records has exposed the personal data of millions of US and UK shoppers at its online store - including email addresses, phone numbers and past purchases.

A glitch on the company's website allowed anyone to view its database of customer orders dating back to 1996, including home addresses, email addresses, phone numbers and what music or video products were purchased. More than three million such records were exposed.

A Tower Records representative said: "It was a technical error, and when we discovered it we were fairly horrified and we fixed it in a matter of hours."

The company said no credit card numbers appear to have been revealed, but the news will do little more the reputation of ecommerce, which has persistently been dogged by security fears.

One Tower Records customer contacted said: "I'm shocked and disappointed. I will no longer do online business with Tower Records."

The security leak arose out of a programming error in a script called "orderStatus.asp." When customers requested information on their order via the Tower Records site, the script called up the record, displaying the order number as part of the URL of the resulting page.

But the script allowed customers to type a different order number into the URL and call up a different record. In the change made Wednesday, Tower Records now requires customers to log in with their email address and password before they can view information about their order.

The blunder is made all the more embarrassing by the company's privacy policy, which says: "Your TowerRecords.com Account information is password-protected. You and only you have access to this information. TowerRecords.com takes steps to ensure that your information is treated securely."

Declan McCullagh writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Seb Janacek Minority Report: Here come the iPhone competitors Should Apple be afraid?

Peter Cochrane Peter Cochrane's Blog: Screen time Will the smaller screen take over - just as the PC eclipsed TV?


  • Jobs
1st Line Support / Helpdesk - 3 MONTH CONTRACT - IMMEDIATE START

Essential skills: Windows 2003 MS Office TCP/IP MS Outlook Desirable: MS Exchange 2003 MITEL Telephony Telephone interviews will take place Monday ...

SAP Senior SD Analyst West Midlands - 45-50,000 + car +benefits

The company are looking to upgrade onto the SAP ECC 6.0 system and your role would not only be to get involved on this from a technical point of ...

LEAD .NET DEVELOPER, C# / ASP.NET - Reading - 35-40k

Reporting to the Technical Director and working in a large team of creative designers and developers, the role will involve leading a team of 3 .NET ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: