21 August 2012

Listen to your Customers

Tesco plc has been in the news in the last couple of weeks regarding security of its ecommerce web site and how this has now escalated into an investigation by the ICO.

Passwords are stored in a secure way. They're only copied into plain text when pasted automatically into a password reminded mail.

Troy Hunt, security expert and generous contributor to application security community, reported his concerns at the end of July. The issue seems to have rolled on, and on, and and on. So it looks like there are at least password storage and cross-site scripting problems — two of the bare minimum OWASP Top Ten.

It appears Tesco has not taken application security seriously, and it has also managed to make matters worse by how it responded to valid enquiries from its customers and feedback via Twitter. Were these enquiries dealt with under an incident response plan? It seems unlikely. But this type of disregard for application security and failure to recognise valid feedback from customers is common. And, it is not limited to the UK retail sector. This isn't good enough.

Listen to your customers. Some of them might actually be trying to help you. For free. And they're not all muppets, whatever your corporate culture believes.

Posted on: 21 August 2012 at 07:57 hrs

Comments Comments (1) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Techweek reports that Tesco are in the process of making changes:

http://www.techweekeurope.co.uk/news/tesco-securit...
1 Added by Clerkendweller Posted on 28 August 2012 at 07:17 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Listen to your Customers
http://www.clerkendweller.com/2012/8/21/Listen-to-your-Customers
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2012/8/21/Listen-to-your-Customers
Requested by 107.22.25.119 on Thursday, 20 June 2013 at 13:35 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2012-2013 clerkendweller.com