ordering at erodvd.nl is _not_ secure, although at first it seems that they are using an https connection.
[big snip]
So you might think twice about ordering your dvds there...
------------------------------
edited - I don't think we really need the details of any store's (in)security issues posted to a public forum. If you want to make it useful, please email the details to erodvd but I won't have security details for any store posted here.
Since I'm not exactly a net security expert, I emailed Aline with the information provided in the original of philosopher's post (first and only post on ADT, too...).
If I use Mozilla Firefox to order from EroDVD I get a warning message essentially the same as philosopher's. Don't get a warning if I use Internet Explorer.
I therefore figured it was a glitch. Now philosopher has me worried. Maybe more people don't notice as Internet Explorer is the most popular browser.
I didn't say philosopher's post was incorrect, just that I didn't want the details posted here. As I said, I've passed the information onto erodvd, so we'll see what happens.
I'm not sure what details philosopher gave, but IE shows it to be secure (SSL Secured 128 bit). I am not, however, a security expert, so I don't know how reliable or otherwise this IE indication is. Anyone clarify?
Erodvd have had some security issues in the past. (see my old posting). At that time I emailed Aline who flat out denied the issue. So I ended up mailing the company who made their Erodvd shopping solution, and made them take at look at it. And it turned out that I was right, the setup Erodvd was insecure!
At the moment I don't see any security issues at Erodvd, but since you removed the post it is hard to check any of the claims made by philosopher.
I think the issue is the same as the one referenced in the previous thread. As I pointed out before (twice unfortunately), Mozilla Firefox identifies the secutiry lapse, but Internet Explorer does not.
Says as much about Bill Gate$' attutude to security as EroDVD's (potential) lack of it.
The way I see it the current ordering form is secure, and the old issue I pointed to are solved. Would somebody please elaborate on the current security issue. Some fuzzy claims about lack of security doesn't really help anybody solve the problem.
I've just tried out the ordering process at Erodvd. In the Erodvd ordering process there is no page displaying the completed order with credit card information. In the Erodvd check out process there are three steps:
1. step: overview of the order with no personal information 2. step: secure order form to be filled out (nane, adress, credit card no….) 3. step: secure generic "thank you" page with no personal or order information
That’s it, and I still don't see the problem using Internet Explorer.
That's right. There is no warning or sign of any problem with Internet Explorer. However, Mozilla Firefox warns you that whilst the current page is secure, the details will be sent without encryption to the destination server.
It might be worth your while downloading Firefox from www.mozilla.org and having a go. Anyway, it's a better browser than IE. :)
OK I believe you and Firefox. Maybe you should drop the company (http://www.uburst.com) behind the shopping solution a mail and make them have a look at the issue. Based on my last experience with security at Erodvd Aline is not able to identify nor fix the issue. Last time she just ignored the problem.
Sounds like they have a simple HTML coding mistake. The checkout process might start out as secure, ie. the URL is HTTPS:// which causes IE to display the lock icon for a secure page. It looks like there's a redirect somewhere in the ordering process that points to an insecure page. Another oddity, I was able to submit a completely blank order form.
Probably not connected directly but worth mentioning here. I rang them a couple of weeks ago to check something and was told that they hadn't replied to an email I sent them and couldn't check it as at that exact time they were having problems with their computer system and it had just been hacked - alittle worrying too.
Here is the reply I received from uburst:That's reassuring to me, but in the light of philosopher's original message I'm not sure if it clears things up completely.