We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

'Rapport' Security

Options
1101113151632

Comments

  • joe134
    joe134 Posts: 3,336 Forumite
    masonic wrote: »
    This is what I get when I click on the green bit at the left of the address bar...
    fdEV.jpg

    If you can't do that, you might want to think about upgrading your browser, if only to use for internet banking. If I click More Information, I can go through and view the actual certificate, but all the necessary information is in that window.

    What is happening on the HSBC page is that the page asking for the user ID is not secure. However, when you press the log in button, a secure connection is set up before the user ID is transmitted to HSBC. The problem with that is you don't know what is going to happen until after you click the button. Many sites used to do this when servers weren't very powerful and there was a big overhead involved with encrypting pages. Nowadays there really is no excuse - servers should easily be able to handle sites that are entirely encryped and leaving things as HSBC has just makes life difficult for users.

    Edit: As an aside, and bringing the thread vaguely back on topic, if I had Rapport installed, I don't think it would have let me take that screenshot because Rapport goes to even greater lengths to prevent any information on the site being eavesdropped.
    Hi, Got it. As you say, it,s browser. I tend to use aol,s. When I use IE, I can get cert, but only after I have entered IB number, so have to rely on Rapport or Wow, as I do anyway.Use IE, probably go back to Firefox, thanks for the lesson.caio
  • joe134
    joe134 Posts: 3,336 Forumite
    edited 5 February 2010 at 6:14PM
    joe134 wrote: »
    Hi, Got it. As you say, it,s browser. I tend to use aol,s. When I use IE, I can get cert, but only after I have entered IB number, so have to rely on Rapport or Wow, as I do anyway.Use IE, probably go back to Firefox, thanks for the lesson.caio
    ps It is browser, got firstdirect no probs on IE.Just tested screen capture using Rapport. I detected it straight away. Gave me the option to allow or deny. Fair enough
  • For a secure 'first page' for HSBC internet banking use https://www.hsbc.co.uk/1/2/ as your bookmark. And you should have a big green blob in your address bar showing the extended security. In Opera I can click on that, or on the security lock on the left and it shows me all the certificates. If your browser is not showing you any padlocks then you really ought to upgrade your browser..

    And I see they now have a Rapport nag screen on that page, UGHHHHHHH
  • joe134
    joe134 Posts: 3,336 Forumite
    edited 5 February 2010 at 7:17PM
    For a secure 'first page' for HSBC internet banking use https://www.hsbc.co.uk/1/2/ as your bookmark. And you should have a big green blob in your address bar showing the extended security. In Opera I can click on that, or on the security lock on the left and it shows me all the certificates. If your browser is not showing you any padlocks then you really ought to upgrade your browser..

    And I see they now have a Rapport nag screen on that page, UGHHHHHHH
    Whether I use IE or AOL browser, HSBC do not show a padlock until I enter DOB+PIN.page First page is always unsecure, no lock showing.Thanks for other log in details.I have IE8. PS, Just tried that tip, even works on AOL, however, on IE8. rapport puts it,s own padlock on browser instead, AOL padlock on bottom, even IB page., I will use your tip from now on though, thanks again,How come HSBC don,t use that as default?
  • masonic
    masonic Posts: 27,169 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    edited 5 February 2010 at 7:45PM
    For a secure 'first page' for HSBC internet banking use https://www.hsbc.co.uk/1/2/ as your bookmark. And you should have a big green blob in your address bar showing the extended security. In Opera I can click on that, or on the security lock on the left and it shows me all the certificates. If your browser is not showing you any padlocks then you really ought to upgrade your browser..
    That https page is only partially encrypted. Content is being received over http, hence Firefox and IE correctly identifying the page as only partially encrypted and not validating the security certificate. Maybe Opera behaves differently?

    Edit: Actually, it is slightly worrying if Opera really is showing partially encrypted pages as secure because it allows the possibility that a secure page could contain a non-secure web form and still validate.
  • atypical
    atypical Posts: 1,342 Forumite
    masonic wrote: »
    That https page is only partially encrypted. Content is being received over http, hence Firefox and IE correctly identifying the page as only partially encrypted and not validating the security certificate.

    Firefox & IE8 behaves in the same way to Opera on that page; they all validate the certificate and give a green address bar marking.
  • masonic
    masonic Posts: 27,169 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    atypical wrote: »
    Firefox & IE8 behaves in the same way to Opera on that page; they all validate the certificate and give a green address bar marking.
    Aha! That is indeed the case... when you turn on javascript. Oops! :o
  • joe134
    joe134 Posts: 3,336 Forumite
    edited 7 February 2010 at 3:08PM
    masonic wrote: »
    Aha! That is indeed the case... when you turn on javascript. Oops! :o
    Just out of curiousity, being as this is not open source software but freeware paid for by the banks, if one stops using the bank or banks supplying the download free, does one have to pay for it?or even uninstal it? If so how much and from where?:p
  • masonic
    masonic Posts: 27,169 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    joe134 wrote: »
    Just out of curiousity, being as this is not open source software but freeware paid for by the banks, if one stops using the bank or banks supplying the download free, does one have to pay for it?or even uninstal it? If so how much and from where?:p
    Anyone can download it from the Trusteer website and use it for free. The banks seem to be paying for automatic integration with their websites and customised installation.
  • joe134
    joe134 Posts: 3,336 Forumite
    edited 7 February 2010 at 6:27PM
    masonic wrote: »
    Anyone can download it from the Trusteer website and use it for free. The banks seem to be paying for automatic integration with their websites and customised installation.
    Cheers Masonic, it,s working ok up to present,still in conjunction with all my usual security though. got the hang of certification now.ciao
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.8K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.