ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Online business Toolkit

Egg admits to flaw in security measures

Will Knight ZDNet.co.uk

Published: 10 Dec 1999 17:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Online banking service Egg has admitted to a flaw in its software that allowed credit-card accounts to be accessed without authorisation until yesterday.

The defect, which arose from software actually designed to improve security, meant that people could still access a user's account even after they thought they had signed off. The defect only affected Netscape 4.6 browsers, and could only be worked around by closing the browser. The problem was fixed Thursday, according to Egg.

Two weeks ago Egg introduced a log-out button on its site designed to automatically remove the security cookies from a user's computer. Unfortunately a problem with the software enabling this feature led to the security hole.

Although this is just the latest in a long line of concerns over Egg's security measures, Pete Marsden, director of information technology at Egg, does not see this problem as a major concern. "There were absolutely no instances of anyone exploiting this," he says. "We have no concerns about it at all. As soon as it was brought to our attention, we fixed it."

Marsden also promises that the situation has been entirely remedied adding, "It is now browser independent as we don't want to be at the behest of browser manufacturers. We are always in the process of updating our security."

Egg has in fact introduced a "browser health check" service to ensure that there browser are entirely compliant with Egg's security measures.

Egg's dubious security record does not seem to have affected its prosperity. The online arm of the Prudential, Egg has issued more than 150,000 cards to customers and receives approximately 3,500 applications each day.

What do you think? Tell the Mailroom. And read what others have said.

See also: the e-commerce special.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
44 out of 89 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

Toshiba touts Quantum Key Distribution

Toshiba research scientists have developed a method of distributing quantum keys more efficiently, the company has claimed in a statement: "[Quantum Key Distribution -- ] QKD --... More

Post a comment

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment