« Hidden Linux : Sexy boot screens | Main | Hidden Linux : Dailystrips »

Imagine a piece of software that;
  • Monitors and transmits a copy of all internet traffic going from and coming to the compromised system.
  • Monitors secure sessions (websites beginning with ‘https'), which may include shopping or banking sites.
  • Records and transmits "the pace and style with which you enter information online..."
  • Parses the header section of personal emails.
So is this the first malware bogey of 2008? Nope. It's what Sears -- one of the largest retailers in the US -- is giving its customers when they join the Sears "My SHC Community".

The CA Security Advisor Research Blog has all the details -- including a disturbing in-depth analysis of where the data's going -- and evidence of what appears to be deliberate obfuscation of the Privacy Policy. It's disturbing stuff -- more so because it comes from a Fortune 500 company.


Comments

Is the spyware recognised and removed by spyware removal tools yet?
If so, surely that would in turn list sears as a malware company?

What happens if you try to login with a linux box? :)

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Subscribe
Newsletter & SubscriptionsPC World is New Zealand’s top selling computing and technology magazine.

It provides up-to-the-minute editorial, insight and buying advice for personal computing, cell phones, game consoles, digital entertainment and broadband.
SIGN UP
PCWorldUpdate
PC World's weekly round-up of tech news, gear and game reviews, software selections, and handy How Tos.