Web Security Flaw Settlement
FTC charges that Petco Web site left customer data exposed.
By Robert McMillan,IDG News Service
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
The U.S. Federal Trade Commission (FTC) has reached a settlement with pet food retailer Petco Animal Supplies of charges that the company's Web site violated federal law by making deceptive security claims.
A security flaw in Petco's Web site left customers' credit card numbers exposed to attackers. The FTC alleges that Petco did not take reasonable measures to protect its Web site and made deceptive claims in stating that customers' credit card numbers would be "shielded from unauthorized access."
This flaw was exploited in a June 2003 attack on Petco.com in which a visitor was able to read customer data stored in Petco's database. According to Petco, the attack was perpetrated by an independent security consultant named Jeremiah Jacks, who immediately informed Petco of the vulnerability.
The vulnerability exposed only a limited amount of customer information, a Petco spokesman said. "What he got was credit card numbers, but there was no other customer information accompanying those numbers," he said.
Settlement Terms
Under the terms of the settlement, Petco is prohibited from misrepresenting the security of its Web site and must establish a comprehensive security information program, which will be subject to independent audits for the next 20 years, said Alain Sheer, an attorney in the FTC's Division of Financial Practices.
Petco could be held in contempt of court if it violates the agreement, Sheer said. It should help to deter other companies from ignoring and misrepresenting security vulnerabilities on their Web sites, he added. "Obviously there's some pretty bad publicity here," Sheer said. "We think that should be a deterrent."
The FTC has reached similar settlements with Eli Lilly, Microsoft, and Tower Direct, Sheer said.
"Petco is committed to keeping all customer information obtained through our Web site and stores private and secure," the Petco spokesman said.
Laptop Showcase
CDW Virtualization Center
Related Security Articles
- Alphabet Decides Who Gets Most Spam Those whose names begin with A are more likely to receive spam that those who start with Z, according to research.
- Apple Promises September Fix for IPhone Security Flaw A recently discovered security flaw that would allow access to a locked iPhone will be fixed next month, Apple said on...
- Four Quick Tips for Choosing an IM Security Product Four simple steps from a Forrester analyst can help your company choose the best instant messaging security product for its needs--from plugging data leaks for compliance and preventing IP theft to virus scanning and preventing SpIM.
- Best Western Downplays Data Breach Breach compromised a dozen records, not 8 million, hotel insists.
- When to Worry About Security Holes--and When Not To Annoyed by all the computerese that litters security stories? Here's your guide.
Best Prices on Security Software
Norton Internet Security 2008Price: $19.40
Internet Security 2008 - 3-User (Full Product, PC)Price: $12.99
Norton 360Price: $32.99
Norton 360 2.0 ( PC)Price: $40.00
Internet Security Suite 2008 - 3-UserPrice: $18.95
Internet Security 7.0 - 3-UsersPrice: $19.95
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- The Future Sales Force - A Consultative Approach This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ in today's evolving market.




