December 31, 2007

Researcher says Sears downloads spyware

Sears and Kmart customers who sign up for the My SHC marketing program could, in essence, be stuck with spyware without notification, a Harvard professor says

Sears and Kmart customers who sign up for a new marketing program may be giving up more private information than they'd bargained for, a prominent anti-spyware researcher claims.

According to Harvard Business School Assistant Professor Ben Edelman, Sears Holdings' My SHC Community program falls short of U.S. Federal Trade Commission (FTC) standards by failing to notify users exactly what happens when they download the company's marketing software.

And given the invasive nature of the product, Sears has an obligation to make its behavior clearer to users. "The software is not something you'd want on your computer or the computer of anyone you care about," Edelman said in an interview. "It tracks every site you go to, every search you make, every product you buy, and every product you look at but don't buy. It's just spooky."

Edelman has written up an analysis of Sears's software, set to be made public on Tuesday.

Problems with the retailer's My SHC Community program were first brought to light in late December, when CA senior engineer Benjamin Googins, wrote a blog entry criticizing the software, which was written by VoiceFive, a subsidiary of Internet measurement firm ComScore.

Sears launched the My SHC Community in March, intending it to be a vehicle for customers who want a voice in the company's direction. "It's still kind of in its early days," said Rob Harles, vice president of MY SHC Community, in an interview conducted prior to Edelman's post. "It's mainly used right now for research, but what we want to do is open it up so it's creating dialogue with our customers."

Sears Holdings, the owner of the Sears Roebuck and Kmart department stores is the third-largest retailer in the U.S.

Sears offers members $10 and a chance to win one of several sweepstakes as an extra incentive to join the program.

But in return, a small percentage of members must install extremely invasive software.

According to Googins, the product monitors not only all of the user's Web traffic, but also keeps track of secure sessions like visits to bank sites, sniffs through e-mail headers, and then sends that information to a ComScore.

While Googins called the software "a significant threat to privacy," Harles doesn't see it that way. First off, he said that members can join the community with or without the tracking software and that less than 10 percent of the members have signed up for the tracking program.

And those who get the tracking software installed have all personally identifying information scrubbed by ComScore and are informed of exactly what's going on, he added.

Harles sent Googlins a detailed rebuttal to his claims, which the CA researcher has published on his blog.

Edelman said Monday the Sears executive is simply wrong. "The comments from ... Rob Harles are remarkable," he said. "Exactly contrary to actual facts as best I can tell."

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.