Advertisement
Promo

Online business Toolkit

Tower Records exposes customer data

Declan McCullagh GameSpot Europe

Published: 06 Dec 2002 10:49 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security hole on Tower Records' Website exposed data on millions of US and UK customers until it was closed late on Wednesday

The glitch allowed anyone to peruse Tower Records' Website to view its database of customer orders dating from 1996 through this week, including home and email addresses, phone numbers and what music or video products were purchased. More than 3 million such records were exposed.

"It was a technical error, and when we discovered it we were fairly horrified and we fixed it in a matter of hours," a Tower representative said on Thursday. No credit card numbers appear to have been revealed, the company said.

Stephanie Wilbanks of Jonesboro, Ark., had her personal information exposed after she ordered a CD as a gift from Tower Records this week.

"I'm shocked and disappointed," Wilbanks said. "I will no longer do online business with Tower Records."

But another affected customer, Ivor Colwill of Haywards Heath, England, said he wasn't as concerned.

"I doubt it'll affect my shopping at Tower," Colwill said. "I honestly can't think of another site that covers so many of my musical needs in one spot or with the same quality of service. At worst, I'll telephone my orders to them."

The security leak arose out of a programming error in a script called "orderStatus.asp." When customers requested information on their order via the Tower site, the script called up the record, displaying the order number as part of the URL of the resulting page.

But the script allowed customers to type a different order number into the URL and call up a different record. In the change made Wednesday, Tower now requires customers to log in with their email address and password before they can view information about their order.

The programming error, which existed for an unknown length of time, appears to have conflicted with Tower Records' posted privacy policy, which says: "Your TowerRecords.com Account information is password-protected. You and only you have access to this information...TowerRecords.com takes steps to ensure that your information is treated securely..."

Founded in 1960 in Sacramento, California, Tower Records operates about 200 retail stores and opened its online store in November 1996.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
49 out of 89 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters