- Recommend:
- 0 Comments
FTD.com Reports Security Glitch
Customer data briefly exposed, now repaired, flower retailer says.
Just as it was preparing for the busy Valentine's Day holiday today, flower retailer FTD's Web site had a security flaw that allowed some online customers to view information about other customers as they ordered on FTD.com.
Customers Notified
In a terse e-mail statement Friday, FTD acknowledged the problem and called it "a brief technical issue in which a limited number of customers may have been able to view a subset of another customer's data."
"The company immediately resolved the situation and we have added additional levels of security to our Web site," the statement said. "We take protecting the integrity and confidentiality of our customers' personal information very seriously and continue to work diligently to uphold the industry's highest privacy and security standards."
Despite those assurances, though, FTD as of midafternoon Friday hadn't posted an announcement about the security problem on its Web site to alert customers about it.
Spokesperson Lisa Witek said affected customers were contacted directly by FTD. "The very small amount of people...we have been in touch with," she said. She declined further comment about the incident.
FTD hasn't said how many customers were affected or what information was viewable on the Web site.
Bugtraq Alerted
The flaw was apparently discovered Wednesday by a systems security technician who posted a security advisory about the problem on the Windows NT Bugtraq mailing list.
In his security advisory, Gerald Quakenbush wrote that the flaw on the site allowed credit card information to be obtained by "any hacker with kindergarten-level skills."
"It is trivial to retrieve customer data, including credit card numbers, expiration dates, account names, shipping addresses, and anything else FTD knows about the consumer," Quakenbush wrote. The problem was due to "deeply flawed session-tracking logic" and server configuration flaws that allow users to connect without using Secure Sockets Layer protocols.
"These issues are independent of each other; however, the ability to connect without SSL simplifies the attack," he wrote. He directly notified FTD of the problem, he said in his posting. Quakenbush couldn't be reached for comment Friday.

For more enterprise computing news, visit Computerworld. Story copyright © 2011 Computerworld Inc. All rights reserved.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
Speed Up Everything!
PCWorld shows you the secrets to improve performance on all your hardware.
-
Lenovo IdeaPad
See why the IdeaPad tablet is optimized for ultimate entertainment.
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Zappos Hacked: What You Need to Know
- Hacker Collective Anonymous Strikes at Child Porn Sites
- Sony Hackers Claim to Have Credit Cards
- Dazzlepod Offers Stratfor Customers a Way to Check on Anonymous Hack
- I Emailed a Credit Card Number
- Congressman Still Has Privacy Concerns About Kindle Fire's Browser
- Four Safer Ways to Pay Online
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.




















