Home > Insights > Blogs 

CA Community

This Blog

Managemyhome.com: Another privacy issue for Sears

Published: January 03 2008, 07:33 PM
by Stefan Berteau

 

"Hey Dad, did you guys by any chance buy a new sewing machine from Sears on September 30th?"

 

"We did.  How did you know that?"

 

"I just found it listed on a Sears web site.  It looks like they have another privacy problem."

 

We were informed about managemyhome.com by Heather, who left the following comment on Benjamin Googins' last blog entry:

 

OMG.  It gets worse!  check out a sears site managemyhome.com.  Once you register, you can look up major purchases for ANY address.  All you need to do is enter a name address and phone number and if the person attached to that info has made a major purchase at sears you get that info!!  They have no real controls in place -- you have to enter an onscreen code and they say that keeps your info safe, but that does not stop someone from entering other people's contact info to see their product purchases.  This brings casing someone's house to a whole new level.

I contacted the compliance e-mail listed on the site, and never got a response, which confirms that Sears does not care about the customer or customer privacy.  If anyone has any ideas about how to get in contact with someone over there that might care about customer privacy, I'd welcome the ideas.  That service should really be off the site.

What do you have to say to that Rob?

 

I checked this out, and sure enough, in about 2 minutes I was looking at every purchase my parents had made since 1989.  What's worse, I had used no more info than is publicly listed in the phone book: their name, address, and telephone number.  Once you have an account at http://www.managemyhome.com/ and have logged in, select the first option (Home Profile) from the "Home" pull-down menu on the main page.  In the upper right corner of the page, you should see a "Sears Purchase History", with a button

labeled "Find my Products". 

 


 

This was obviously introduced to let me look at my own purchase history, but unfortunately the only information they asked for when I followed that button was a name, phone number, and address.  To test this out, I put in my parents' information-I want to stress that this is the exact same info listed under their name in the phone book-and was rewarded with a list of their major Sears purchases running back almost two decades to when they first moved in to that house.

 


 

With their consent we have tested this technique with other individuals and have received reliable results every time. If they'd had major dealings with Sears, that information is now available to the public, from a television bought in 1978 to a stove which was purchased elsewhere but had been repaired by a Sears technician.

 

Heather's original comment was right...among numerous other potentially invasive or harmful uses for this information, a potential burglar or scam artist could quite easily sit at home with a  phonebook, checking to see what people in a given neighborhood had purchased, complete with date of purchase, make, model, and warranty information, everything they'd need to bluff their way through picking it up for a "recall".

 

Customers have not consented to the release of this information online.  While Sears is attempting to provide it to the original purchasers as a convenience, the poor security measures which were put in place allow literally anyone with an internet connection to look at my purchase history.  This is a real and immediate threat to their customer's privacy, and it needs to be addressed.

Share this post:  EmailEmail

By: Stefan Berteau
Stefan Berteau is a senior research engineer with CA's Anti-Spyware Research team. He holds a B.S. in Multimedia Design and Development from American University, where his studies concentrated on machine learning and graphics programming. Stefan's research-related interests include automated...
Read More..

15 people have left comments:

Looks like they pulled the feature

Posted by: Rob | January 4, 2008 3:17 PM

They have disabled the feature... For now I guess

Posted by: Rob | January 4, 2008 3:19 PM

It looks like you've alerted the right people, as I no longer see the link for Sears Purchase History on the page.  Scary stuff!

Posted by: Sue H | January 4, 2008 3:46 PM

Score one for the power of the people!!!  I think the feature is off, but am not sure because the site is acting very choppy and I am having trouble loading pages.  I did get to a page where you could click a like to get to purchase history, but when I clicked the link, my computer froze.

Posted by: heatherh | January 4, 2008 6:01 PM

You just spoiled what could have been so much fun!

Ring Ring

Hello?

Is your Kenmore 21.8 cubic foot side-by-side refrigerator with ice and water filtration in the door running?

Yea?

Well you better catch it!

Posted by: Lawrence Tureaud | January 4, 2008 10:54 PM

Yes it appears to be disabled for the moment.  Wonder how many homes have been compromised because of this poor planning and judgement

Posted by: ken | January 5, 2008 12:22 AM

heatherh,

from I can tell, you were the first to report this problem.  thums up to you!

-Benjamin

Posted by: Benjamin Googins | January 5, 2008 12:48 PM

Thanks Ben!!

Check this out.  A class action has already been filed.

blog.washingtonpost.com/.../class_action_suit_alleges_sear.html

Posted by: Heather | January 5, 2008 3:47 PM

Thanks Ben!!  Take a look.  Kamber Edelson, the same firm that won the Sony class action filed one against Sears on Friday. They sure didn't hesitate on jumping on this one!  

blog.washingtonpost.com/.../class_action_suit_alleges_sear.html

What I would really like to know is how the people in charge of this website could be so stupid.  The 1st thing they should have done was create a secure way for people to access thier data.  They obviously know NOTHING about ecommerce sites.

Posted by: HeatherH | January 5, 2008 4:26 PM

Even if it is disabled, it shows that they have very poor planning, poor respect for privacy, and are inept at implementing security.  They're not to be trusted in the future.

Posted by: JRidley | January 7, 2008 3:24 PM

this is serious breach of privacy

Posted by: nathan | October 6, 2008 2:45 PM

Sears is living in the ancient history.  They have a LOT more than security issues going on.  They have let my mother, father, and daughter charge on my account in seven different states without ever asking for id.  What a joke they are.  This was all with my ok, but what if it weren't??

Posted by: KATIE | December 22, 2008 12:08 PM

As of 2/12/2009, there is an additional "security" questionnaire in a pop-up after initial and easily obtained questions on web page.  Now someone who has either known me along time or has my credit history might be able to answer these.  I hope not my credit history, for bovious reasons.

Posted by: Vickey | February 14, 2009 6:21 PM

I forgot to thank you for this.  It is great to see that some are still looking out for the many.  I bet your post had something to do with the web site's changes.

Posted by: Vickey | February 14, 2009 6:24 PM

 
 
Page Tools