Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Researcher says Sears downloads spyware

By Robert McMillan , IDG News Service , 01/01/2008

Sears and Kmart customers who sign up for a new marketing program may be giving up more private information than they'd bargained for, a prominent anti-spyware researcher claims.

According to Harvard Business School Assistant Professor Ben Edelman, Sears Holdings' My SHC Community program falls short of U.S. Federal Trade Commission (FTC) standards by failing to notify users exactly what happens when they download the company's marketing software.

And given the invasive nature of the product, Sears has an obligation to make its behavior clearer to users. "The software is not something you'd want on your computer or the computer of anyone you care about," Edelman said in an interview. "It tracks every site you go to, every search you make, every product you buy, and every product you look at but don't buy. It's just spooky."

Edelman has written up an analysis of Sears's software, set to be made public on Tuesday.

Problems with the retailer's My SHC Community program were first brought to light in late December, when CA senior engineer Benjamin Googins, wrote a blog entry criticizing the software, which was written by VoiceFive, a subsidiary of Internet measurement firm ComScore.

Sears launched the My SHC Community in March, intending it to be a vehicle for customers who want a voice in the company's direction. "It's still kind of in its early days," said Rob Harles, vice president of MY SHC Community, in an interview conducted prior to Edelman's post. "It's mainly used right now for research, but what we want to do is open it up so it's creating dialogue with our customers."

Sears Holdings, the owner of the Sears Roebuck and Kmart department stores is the third-largest retailer in the U.S.

Sears offers members $10, and a chance to win one of several sweepstakes as an extra incentive to join the program.

But in return, a small percentage of members must install extremely invasive software.

According to Googins, the product monitors not only all of the user's Web traffic, but also keeps track of secure sessions such as visits to bank sites, sniffs through e-mail headers, and then sends that information to a ComScore.

While Googins called the software "a significant threat to privacy," Harles doesn't see it that way. First off, he said that members can join the community with or without the tracking software and that less than 10 percent of the members have signed up for the tracking program.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (1)
Login
Forgot your account info?

RE: Researcher says Sears downloads spywareBy Z. on January 2, 2008, 3:13 pmSounds like Karl Rove is running Comscore.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.