Share

Related Links

  • McAfee
  • Symantec
  • Elsevier Ltd is not responsible for the content of external websites.

Related Stories

  • Information security in China: A license to print money
    With 200 million internet users in China, and a predicted annual growth rate of 17% for the information security market until 2013, why would security vendors want to go anywhere else? William Knight investigates
  • Online news senior slams Android – and its users – for sloppy security
    The president emeritus of the ONA – the Online News Association – has slammed the Android operating system for its inherent insecurity.
  • The Rise and Fall of Online Credit Fraud
    While Chip and Pin technology has certainly decreased in-store fraud, it has also re-directed criminals’ attention to online banks and shoppers. Stephen Pritchard investigates what methods cybercriminals are using to steal credit card data, and reports on how the finance sector is fighting back
  • DLP technology unplugged
    Data loss prevention (DLP) technology has become something of a buzzword amongst security analysts, but where has it come from, where does it sit in the market as a whole and what does the future hold? Davey Winder investigates
  • Tightening the purse strings on information security
    As the recession continues to chew into information security budgets, and cyber criminals see increased opportunity for looting, CIOs must ensure that defenses remain strong and affordable, even if this means a little bargaining. Stephen Pritchard looks at how organizations can negotiate the rough seas ahead.

Top 5 Stories

News

Symantec and McAfee under fire for auto-renewing subscriptions

12 June 2009

The perils of giving companies your payment card details and failing to realise the likelihood of those details being used when subscription renewal times comes around have raised their ugly head again, with Symantec and McAfee being ordered to pay $375,000 each to the New York Attorney General to resolve complaints about the issue from customers.

Symantec and McAfee have been told to pay these monies to clear up accusations that they charged subscriptions against customers' payment cards without the customers' knowledge or authorisation.

The IT security firms have also agreed to make detailed disclosures of any automatic subscription fees and renewals to authorities, as well as operate a more transparent procedure for customers to opt out of an auto-renewal option.

Andrew Cuomo, New York's Attorney General Andrew Cuomo described the practice as "hide the ball", saying that customers have a right to know what they are paying, especially when they are unwittingly agreeing to renewal fees that will not appear on their credit card bill for months.

Cuomo added that the fees were "hidden at the bottom of long web pages or in the fine print of license agreements."

As a result of their actions, both Symantec and McAfee are now required to notify customers before - and after - the renewal deadlines and must provide refunds to those who request them within 60 days of being charged.

The settlement also asks that the IT security vendors are open about the length of time that they will continue to provide support and updates for their software.

One solution to the problem of recurring subscriptions that are only payable by card is to use a prepaid debit card such as the Paypal Topupcard,Infosecurity notes.

In return for £4.95, users get a payment card that can be loaded - ironically using a regular credit or debit card - each time a potentially recurring payment is required.

Since it not possible to `overdraw' the card, if a merchant attempts to repeat the subscription at a later date without permission, the transaction will not go through.

This article is featured in:
Compliance and Policy  • Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.