NEWS Mac users who bank with Egg are up in arms about a serious flaw in the site that left the security of their credit card details in doubt. A silicon.com reader and Mac user experienced problems when he tried to log-on to the egg.com website with the latest version of the Macintosh operating system, OSX. When he attempted to make a secure connection, a dialog box appeared informing him that his browser was unable to do so. The problem recurred with all the versions of Internet Explorer and Netscape browsers he used. Egg customer services told him to go ahead and make the connection and assured him that the connection would be secure, despite the fact that a dialog box said the contrary. The customer service representative also told him not to worry about the fact that there was no padlock graphic in the corner of his browser window - directly conflicting advice displayed elsewhere on the Egg website. The reader told silicon.com: "I am, along with many friends and family, now closing my account because this company obviously does not care about the security or integrity of data for its Apple Macintosh users." Egg told silicon.com that the problem was due to an error of communication with its certificate vendor, Verisign. An update to the site means that Mac browsers can't recognise the digital certificate that normally guarantees a secure connection. The company said in a written statement: "Egg can confirm that a small number of its customers using Apple Mackintosh [sic] computers have recently experienced difficulties accessing Egg's website. "Egg can confirm that this message was displayed in error and at no time was any part of the Egg website insecure." However, security experts said that while traffic between the Egg site and the user may have been encrypted, digital certificates are an integral part of securing a website that cannot be ignored. Lee Ferman, CTO at software-testing company Tescom, said: "The user doesn't know whether it is secure or not, so that could leave it open to spoofing or other attacks." Egg apologised to the affected users and added: "Egg has worked with its certificate providers to ensure that the message is not displayed erroneously again. Egg is of course very concerned about its customers being unable to access their accounts at any time and it has taken steps to ensure this will not happen again." Egg claims it has now rectified the fault.
Egg's security leaves Mac users shell-shocked
First Passport, now this...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Latest Networks stories
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
WAN Optimization for Today and Tomorrow.
It was only a few years ago when the idea of mobile computing seemed like a distant reality. Many could see it coming,...
-
Six iPad tests for multimedia-grade Wi-Fi
Along with most companies, the University of Ottawa has seen a massive increase in the numbers of highly mobile...
-
Solution Brief: Top 5 Reasons to Choose Blue Coat WAN Optimization
There's a pretty good chance your wide area network (WAN) looks like a mess right now. The rapid adoption of new...
Popular Networks stories
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Architect Java, J2EE, Oracle, Spring London £55-65K
Java, J2EE, Oracle, PL/SQL, SQL, Spring, Struts, Maven, Swing Java, J2EE, Oracle My client a premiere...
-
Business Analyst ( ISEB, CBAP, BA, Analyst)
Business Analyst ( ISEB, CBAP, BA, Analyst) £31,000-£42,000 + excellent benefits We take the best Business...
-
Embedded C / MISRA C / DO178B - SouthCoast
I have just received instruction from a key client of mine for an Electronic Design Engineer in the Gloucestershire...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




