You are here: silicon.com > Networks > WebWatch

WebWatch

Egg's security leaves Mac users shell-shocked

First Passport, now this...

By Ben King

Published: 5 January 2002 00:30 GMT

Mac users who bank with Egg are up in arms about a serious flaw in the site that left the security of their credit card details in doubt.

A silicon.com reader and Mac user experienced problems when he tried to log-on to the egg.com website with the latest version of the Macintosh operating system, OSX.

When he attempted to make a secure connection, a dialog box appeared informing him that his browser was unable to do so. The problem recurred with all the versions of Internet Explorer and Netscape browsers he used.

Egg customer services told him to go ahead and make the connection and assured him that the connection would be secure, despite the fact that a dialog box said the contrary.

The customer service representative also told him not to worry about the fact that there was no padlock graphic in the corner of his browser window - directly conflicting advice displayed elsewhere on the Egg website.

The reader told silicon.com: "I am, along with many friends and family, now closing my account because this company obviously does not care about the security or integrity of data for its Apple Macintosh users."

Egg told silicon.com that the problem was due to an error of communication with its certificate vendor, Verisign. An update to the site means that Mac browsers can't recognise the digital certificate that normally guarantees a secure connection.

The company said in a written statement: "Egg can confirm that a small number of its customers using Apple Mackintosh [sic] computers have recently experienced difficulties accessing Egg's website.

"Egg can confirm that this message was displayed in error and at no time was any part of the Egg website insecure."

However, security experts said that while traffic between the Egg site and the user may have been encrypted, digital certificates are an integral part of securing a website that cannot be ignored.

Lee Ferman, CTO at software-testing company Tescom, said: "The user doesn't know whether it is secure or not, so that could leave it open to spoofing or other attacks."

Egg apologised to the affected users and added: "Egg has worked with its certificate providers to ensure that the message is not displayed erroneously again. Egg is of course very concerned about its customers being unable to access their accounts at any time and it has taken steps to ensure this will not happen again."

Egg claims it has now rectified the fault.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Read and write about internet access at the airports of the world at atlarge.com. Rate airports, and see what others have to say...

Natasha Lomas Exclusive: Jimmy Wales on what's next for Wikipedia Why Wikipedia needs geeks and why a life unplugged is unthinkable

Peter Cochrane Peter Cochrane's Blog: United breaks guitars? Customer service has changed forever


  • Jobs
Remote Access Engineer- Investment banking- London 6 month contract

VPN LINUX IPHONE APPLE Macintosh Exchange Active Sync DIRECTORY SERVICES - LDAP and AD Termination devices - Cisco, Aventail (or equivalent) Java & ...

Front-end and SEO Developer Macclesfield 30,000

To apply my client is looking for proven skills in JavaScript, using it for basic animation, form validation XHTML, writing XHTML to a hand-coding ...

ASP.NET Web Developer Kent to 35k

The successful candidate must have solid experience in ASP.NET V2.0 (C#), Microsoft AJAX programming patterns, JavaScript, CSS design and layout, ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: