You are here: silicon.com > Networks > WebWatch

WebWatch

Egg's security leaves Mac users shell-shocked

First Passport, now this...

By Ben King

Published: 5 January 2002 00:30 GMT

Mac users who bank with Egg are up in arms about a serious flaw in the site that left the security of their credit card details in doubt.

A silicon.com reader and Mac user experienced problems when he tried to log-on to the egg.com website with the latest version of the Macintosh operating system, OSX.

When he attempted to make a secure connection, a dialog box appeared informing him that his browser was unable to do so. The problem recurred with all the versions of Internet Explorer and Netscape browsers he used.

Egg customer services told him to go ahead and make the connection and assured him that the connection would be secure, despite the fact that a dialog box said the contrary.

The customer service representative also told him not to worry about the fact that there was no padlock graphic in the corner of his browser window - directly conflicting advice displayed elsewhere on the Egg website.

The reader told silicon.com: "I am, along with many friends and family, now closing my account because this company obviously does not care about the security or integrity of data for its Apple Macintosh users."

Egg told silicon.com that the problem was due to an error of communication with its certificate vendor, Verisign. An update to the site means that Mac browsers can't recognise the digital certificate that normally guarantees a secure connection.

The company said in a written statement: "Egg can confirm that a small number of its customers using Apple Mackintosh [sic] computers have recently experienced difficulties accessing Egg's website.

"Egg can confirm that this message was displayed in error and at no time was any part of the Egg website insecure."

However, security experts said that while traffic between the Egg site and the user may have been encrypted, digital certificates are an integral part of securing a website that cannot be ignored.

Lee Ferman, CTO at software-testing company Tescom, said: "The user doesn't know whether it is secure or not, so that could leave it open to spoofing or other attacks."

Egg apologised to the affected users and added: "Egg has worked with its certificate providers to ensure that the message is not displayed erroneously again. Egg is of course very concerned about its customers being unable to access their accounts at any time and it has taken steps to ensure this will not happen again."

Egg claims it has now rectified the fault.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Read and write about internet access at the airports of the world at atlarge.com. Rate airports, and see what others have to say...

Rob Bamforth Seeking memorable mobile apps Quocirca's Straight Talking: Why are there so few?

Stewart Baines How much SEO is too much? Net Effect: Plus 10 tips on boosting your site's profile


  • Jobs
Developer - Win / Web - to 50k - London

Experience of Apple Mac development Senior Developer - Win / Web - to 50k - London Key skills: At least 3 years C# experience Experience writing ...

Web Applications Developer (JavaScript, ASP.Net)

You will also possess a good understanding of DOM, CSS, W3C standards and programming issues for various browsers. Software House who develop a ...

Web Developer/ .NET Programmer

Managing the transfer of the security certificate. Incorporate a drop down box for counties in the registration form for UK clients A Web Developer ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: