Michael Cooney
Senior Editor

“Geeks” get tap on wrist for data security problems

Opinion
Feb 5, 20093 mins

Electronics company Compgeeks.com got a light upbraiding from the Federal Trade Commission today as it agreed to settle charges that it violated federal law by failing to provide reasonable security to protect sensitive customer data.

The settlement involves no fines but rather bars Compgeeks.com from making deceptive privacy and data security claims and requires them to implement and maintain a comprehensive information-security program that includes administrative, technical, and physical safeguards, the FTC said. It also requires the companies to obtain, every other year for 10 years, an audit from a qualified, independent, third-party professional to ensure that the security program meets the standards of the order. In addition, the proposed settlement contains standard record-keeping provisions to allow the FTC to monitor compliance.

The FTC complaint alleges that until at least December 2007, among other security failures, Compgeeks.com routinely stored sensitive information in unencrypted text on their corporate network. The complaint also charges that the company did not adequately assess whether their Web application and network were vulnerable to commonly known or reasonably foreseeable attacks, such as Structured Query Language (SQL) injection attacks. The respondents also did not implement simple, readily available defenses to these attacks; defenses that were free or inexpensive. And – from January 2007 or earlier through June 2007 or later – hackers repeatedly exploited these vulnerabilities by using SQL injection attacks on the www.geeks.com Web site, the complaint alleges. The company said it did not become aware of the breach until December 2007.

According to the FTC’s complaint, Compgeeks.com (Compgeeks), which operates the  www.geeks.com and its parent company, Genica Corporation (Genica), collect sensitive information from consumers to obtain authorization for credit card purchases. The respondents require each consumer to provide his or her first and last name; address; e-mail address; telephone number; and credit card number, expiration date, and security code. In January 2008, media reports revealed a data breach at the company. It was later confirmed that hackers accessed the sensitive information of hundreds of consumers, the FTC said.

Layer 8 in a box

Check out these other hot stories:

NASA fashions mountain climbing robot

Google, NASA, X Prize team to form “humanity’s grand challenges” university

FBI: On-line employment scams rising

911 fraudsters provoke, endanger public, law officers

“Magnetic tornado” spins data storage techniques

FBI: Digital billboards have helped capture 14 scoundrels

Web site turns up heat on hot cars

Machine machinations: Smart robot capable of hunting for its own “food”

VA to pay $20M to settle data theft case

FTC slaps Do Not Call Violators with $1.2 Million in penalties

Go fly yourself: Unmanned aircraft technology puts twist on self-flightFighting toxic chemicals to fixing cyber infrastructure: The government’s top 10 trials and tribulations