To: Ex-INTCfan who wrote (50876 ) 5/29/2002 3:54:34 PM From: Sully- Respond to of 65232 Were you peeking? Associated Press Glitch Exposes Fidelity Accounts By ANICK JESDANUN AP Internet Writer Glitch at Fidelity's Canadian Web Site Exposed Accounts NEW YORK (AP) -- A design flaw at a Fidelity Investments online service accessible to 300,000 people allowed Canadian account holders to view other customers' account activity. The problem was discovered over the weekend by Ian Allen, a computer studies professor at Algonquin College in Ottawa. Fidelity said it had fixed the problem and was offering customers the option of changing account numbers. Allen accessed at least 30 account statements, which contained names, addresses, account numbers and transaction histories, then reported the flaw to Fidelity. Fidelity spokeswoman Kimberly Flood said Wednesday that the company fixed the breach once it got Allen's message Monday. She said that based on a review of Internet logs, only Allen is believed to have accessed other accounts. Allen discovered the glitch Saturday after signing up for online access to his mutual fund accounts. He requested a summary of his account and got back a Web page ending in "799.pdf." He then started changing numbers to see what would happen and found that he could access other accounts. Allen said he didn't have enough money in the accounts to be bothered that others could have viewed it, but the error will make him check statements more carefully in the future. "If they make a simple mistake like that, what else is wrong?" he said. "I did have the naive assumption that a big corporation would take big precautions. It doesn't seem to be true." The glitch did not affect U.S. customers, nor did it permit anyone to make unauthorized transactions, Flood said. Flood said Fidelity shut down that portion of the Web site while it investigated the flaw, fixed the application and restored service on Tuesday. During the outage, customers were able to access their accounts through other applications on the site. "We are in the process of notifying individuals and providing the option of changing account numbers," Flood said. She said Fidelity routinely conducts security audits using internal and external experts and uses encryption and other methods to protect data. The glitch in question appeared to result from recent programming changes, she said, but the company is still investigating. biz.yahoo.com