Earthwebnews.com   Earthweb  
Images Events Jobs Premium Services Media Kit Network Map E-mail Offers Vendor Solutions Webcasts
   sections:
Search EarthWeb Network

internet.commerce
Be a Commerce Partner
Computer Deals
Shop
Laptops
Phone Cards
Promotional Gifts
Televisions
Best Price
Corporate Awards
Compare Prices
Memory
PDA Phones & Cases
Promotional Pens
Cell Phones
Compare Prices

Untitled table test
Register here for your free Internet.com membership to download your Justifying and Funding Infrastructure Investments report.

This independent report will help you make the case for your IT investments. Topics covered include:

Measuring Infrastructure Value
Justifying New Investments
Establishing an Infrastructure Value Chain and More.
Register now for your free Internet.com membership to download your complimentary Forrester report.
Limited Time Offer!
Related Articles
House Panel Approves Data Breach Bill
Commentary
Linux File Systems: You Get What You Pay For
By Henry Newman
Linux file systems have a number of limitations that make them a poor choice for large and high-performance computing environments.
Special Reports
Down Yahoo's Transition Road

[ more ]
Hot Topics
Return of The Browser Wars
A Patent Battle on eBay Territory
SaaS in The Market
Ads And Their Influence
FREE Tech Newsletters

Download: IBM Data Studio v1.1. Effectively design, develop, deploy and manage your data, databases, and database applications throughout the data management life.

Security
December 2, 2005
DSW Decides FTC Security Shoe Fits
By Roy Mark

The other shoe fell today for DSW, the national footwear discounter that admitted in March that hackers accessed more than three months' worth of customer data.

In a settlement with the Federal Trade Commission (FTC), DSW agreed to implement a comprehensive security plan and to obtain independent audits by a third-party security firm every other year for 20 years.

The security program must include administrative, technical and physical safeguards.

Until at least March of this year, the FTC claims, DSW engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for sensitive customer information.

The FTC said DSW's failure to secure customers' sensitive data constituted an unfair trade practice, because it caused substantial injury that was not unreasonably avoidable by consumers. The FTC further charged that offsetting benefits to consumers, such as credit, debit and check approvals, did not outweigh the consumer injuries.

According to the FTC, the DSW security lapse compromised 1.4 million customer credit and debit cards and 96,000 checking accounts. The FTC said that there have been fraudulent charges on some of the compromised accounts.

The FTC said DSW's exposure for losses related to the breach ranges from $6.5 million to $9.5 million.

As outlined in the FTC complaint, DSW uses computer networks to obtain authorization for credit card, debit card and check purchases at its stores and to track inventory. Columbus, Ohio-based DSW operates approximately 190 stores in 32 states. In 2004, the company generated $961 million in net sales and sold approximately 23.7 million pairs of shoes.

For credit and debit card purchases, DSW collects information including the name, card number and expiration date from the magnetic stripe on the back of the cards. This magnetic stripe information is a particularly sensitive security matter, because it contains a code that can be used to create counterfeit cards that appear genuine in the authorization process.

For check purchases, DSW collects information such as the routing number, account number, check number and the consumer's driver's license number and state. In each case, the information was wirelessly transmitted to a computer network located in the store.

From there, the data was sent to the appropriate bank or check processor.

The poor security procedures the FTC claims DSW practiced included creating unnecessary risks to sensitive information by storing it in multiple files when it no longer had a business need to keep the information, and storing the data in unencrypted files that could be easily accessed using a commonly known user ID and password.

Among other lax practices cited by the FTC was failing to use readily available security measures to limit access to its computer networks through wireless access points on the networks.

Tools:
Add news.earthweb.com to your favorites
Add news.earthweb.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

Security Archives

eBook: Evaluating Software as a Service for Your Business. Sponsored by Webroot
Increase your reach with unlimited Webinars for one low rate. Try GoToWebinar FREE.
Data Sheet: IBM Information Server Blade
What's The Future Of IT? Find Out By Reading "IT in 2018" Now. Free Registration Required.
Is secure, available data a challenge? Try Symantec Online Backup free for 30 days.


Current Headlines
Breaking News
What's Microsoft's Play in Icahn-Yahoo Spat?
Yahoo, WPP in Multiyear Partnership on Ad Trading
Indictment in MySpace Hoax that Led to Suicide

Business
Stocks End Strong Week Flat
Yahoo Parries Icahn's Jab
Icahn Prepares For War With Yahoo

Developer
Apple Details iPhone/Mac Developer Event
RIM Ups Ante With Mobile Software Push
Novell Readies Silverlight Clone for Linux

E-Commerce
Yahoo Parries Icahn's Jab
Small Business Has a New Online Calling Card
MySpace Wins Record $230M Suit Against Spammer

Enterprise
Greenplum Sees BI As Sweet Market
Autonomy 'Discovers' Virtualization
HP Targets Telecoms' Customer Data Needs

Government
All Talk, Little Action on 'Net Neutrality Front?
SEC Mandates XBRL on All Documents
House Democrats Try Again With Net Neutrality Bill

Hardware
One Laptop Per Child's Controversial Support for XP
Apple Details iPhone/Mac Developer Event
Why Are AMD Systems Prone to SP3 Problems?

Networking
Enterprise Spending On Virtualization To Rise
Asterisk Going Carrier-Grade?
Apeer Has an Eye for Media Collaboration

Mobility
One Laptop Per Child's Controversial Support for XP
WiMAX's Backers Bet Big, Dream Bigger
Microsoft Hones Mobile Search, Services Strategy

Search
Yahoo Pitches The 'Next Generation of Search'
Google's Enterprise Search Gets a Helping Hand
Is Microsoft Weaker After Failed Takeover Bid?

Security
Compliance Issues Still Bedevil IT
Debian, Ubuntu SSH Under Attack
BlackBerry Becomes Security Token Device

Software
Informatica's End-to-End Data Integration
Enterprise Spending On Virtualization To Rise
Gates Provides More Windows 7 Details

Storage
Seagate Disk Gets NSA's Security Seal of Approval
Dedupe Player Stakes Out New Domain
IBM Seeks Greater Slice of Virtual Tape Library Pie

Web Content
Is CNET The Right Fit For CBS?
CBS to Acquire CNET Networks For $1.8B
Google to Spread Social Tool Across The Web

Wireless
Apple's iPhone SDK Off to The Races
Sales Data, New Challengers Don't Bode Well For Moto
iPhone Grabs Market Share, But Not Yet in The Enterprise

xSP
IDC: Microsoft's Yahoo Deal Could be a Big Hit
Ballmer Fills in 'Software-Plus-Services' Plan
Report: Enterprise Search Will Top $1 Billion by 2010

EarthWeb is a division of Jupitermedia Corporation.


JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES