Privacy & Security Violations at Buy.com

In October 2000, I noticed that buy.com‘s product return system allowed any Internet user to view prepaid UPS return labels intended for use by some 45,000+ Buy.com customers. Labels included customers’ names, addresses, and phone numbers. Buy.com has since fixed the problem, replacing the information with an error message, but I kept a sample of the data that was temporarily publicly accessible. See coverage of the story in major media.