Wednesday, October 28, 2009

Surprise Logout from our secure payment page

The recent upgrade to SSL has an unexpected result.

I won’t attempt to explain the magic by which the calan code dogs were able to create a secure site within an ASP structure, with hundreds of GO2Show URLs in use. I’ll just state that while your client does not know it they have been moved inside the calancom.com domain for their secure transaction.

However, this means that if they Logout form this one secure payment page they are actually signing out of calancom.com, not your site. As such instead of being placed on your site’s Login screen they are placed on the Login screen for calancom.com.

To address this fact, for the occasional odd ball customer who may chose this moment to Logout in the middle of a secure transaction, we have removed all of the identity from our site and replaced it with a simple message.

For security purposes please completely close your browser before continuing.