Web security glitch derails TheTrainline.com
TheTrainline.com, a UK website for buying train tickets, has a security bug, which means customers could be invited to submit credit card details over an insecure link. The bug kicks in only when users make an error with their credit card details, so it won't affect the majority of customers.
The bug remains unresolved more than three weeks after the issue was first flagged up to the firm.
Customers will see a confirmation that they are submitting information to a secure page as soon as they start the payments process. The site uses an Extended Validation SSL certificate, giving extra confidence that all is (seemingly) well.
However users who make an error at the final payment page when their payment card details are verified are bounced over to an insecure page, inviting them to submit corrected details over an unencrypted HTTP link. Inattentive users could be forgiving for missing the change. Although the https signifier in the URL is absent, a falsely reassuring padlock graphic remains in place, along with logos for Verified by Vista and MasterCard SecureCode.
The issue was first noted by Tim Anderson, a Reg Developer contributor, on 8 October.
Reg reader Dave experienced the same problems. "I recently attempted to purchase tickets on their secure, verified by visa, shop. To my horror, on the final page I was redirected to an insecure page with a form on containing the number of the credit card I had just typed in - passed in the source, not encrypted in any way," he told us.
Anderson and Dave both raised the issue with TheTrainline, but neither got a response. Our attempts to speak to someone on the phone about the problem proved similarly frustrating. Phoning up the 0870 number on the site and attempting to report a problem led to the suggestion that we ought to post a letter to its headquarters. The number of Trainline.com, the firm that runs the service, isn't published on the website and call centre staff we spoke to didn't have it.
When we tracked down the phone number of its Edinburgh HQ, staff invited us to ... ring in on the 0870 number on the site. Attempts to contact the firm via its website were more successful, alhough its webmaster is yet to reply to a direct email.
TheTrainline.com acknowledged there was a problem with the site but downplayed its significance.
"I can confirm that there is a temporary fault on our website and our technical team is working on resolving it as soon as possible," a representative of the firm wrote in response to our web query.
"However, our website is still secure to allow transactions to go through. When paying by credit/debit card on our Internet site you can be sure that any information you send us remains secure and protected."
The site is secure, up to a point, but only if you don't make any mistakes. As Anderson notes the chances of cybercrooks intercepting insecure internet traffic sent to and between the site at times when the glitch kicks in are low. That said, the risk on the coding error is real, if small and hard to quantify. So the failure of the high-profile merchant to deal with it in a more timely fashion is disappointing.
Reproduced from an article published by The Register
© The Register
The original article can be viewed here:
http://www.theregister.co.uk/2007/11/02/thetrainline_security_glitch/
Permalink Bookmark Digg this story





