Banking Protection Blocks Webpage Load After Login
- Banking Protection detects Self Service (fidelityrewards.com) and launches.
- After login Banking Protection prevents:
- The loading of webpage elements, booleans and connected data that are imported by embedded html from servers hosting the content/data.
- The use of authentication apps (e.g. Authy, Google or Microsoft Authenticator are blocked from connecting to the network and this breaks them) that are required to be used as MFA to access certain webpage elements.
Solutions that have NOT worked include:
- Exclude fidelityrewards.com individual webpages from Banking Protection.
- Exclude the entire fidelityrewards.com domain from Banking Protection.
- Start the MFA authentication app before launching the webpage detected by Banking Protection.
The only solution that does work and permits use of the website combined with the required intra-page access requiring MFA authenticator app is:
- Disable Banking Protection entirely for the entire fidelityrewards.com domain.
- Webpage elements populate.
- User can obtain code from authenticator app.
Accepted Answer
-
Hi @Karibu
Today I received a reply about your problem from the security department.
They have updated the category of the reported domain, but from the screenshot it seems that the webpage having issue is the member of area which we are unable to access.
So if the problem persists we will need to receive the diagnostic data.
I'll send you a private message on community forum.
Please check your inbox.
Kind regards
Pawel
Making every digital moment secure, for everyone
Answers
-
Received reply from Support that fidelityrewards.com has been added to Banking Protection on the F-Secure side.
Despite this URL whitelisting, issues reported still persist.
Followed official F-Secure troubleshooting guide provided by Support, still issue persists.
Browser used does not matter... Chrome, Microsoft Edge, Firefox, Internet Explorer (which is no longer available on Windows 11).
-
Hello,
Sorry for the discussion.
Is it possible that some CDNs (or any other third-party domains) are just not rated as safe for banking by F-Secure.
Could you check which one resources are loaded while you logged (and probably 'failed' to be loaded)? It is possible to do by using Browsing console (perhaps, usually, accessible via F12 button). As for MFA - I think it is also can be something as Iframes.. or similar loaded resources from the sides.
At least, with mentioned login page - I do see, at least, three domains (one of them is CDN-purposed) which are with some difficulties to get content from. But my set-up has a bit more tweaks about - so I am not sure which part will block something.
-
The vast majority of U.S. financial websites use CDNs and most of them also perform re-directs to external webpages for certain functionality - such as money transfers or making credit card balance payments.
F-Secure Banking Protection is not blocking IFrames with regards to MFA. It blocks the Authy desktop app from connecting to its backup & sync server - which is required for it to generate a 2FA code.
F-Secure needs to contact Authy directly for infos.
-
Hello Pawel,
It appears to be fixed for this specific website: www.fidelityrewards.com .
I will update here should any further problems happen for this specific website.
Thank You
Hei Pawel,
Se näyttää olevan korjattu tälle verkkosivustolle: www.fidelityrewards.com .
Päivitän tänne, jos tälle verkkosivustolle tulee lisää ongelmia.
Kiitos
Tere Pawel,
See näib olevat selle konkreetse veebisaidi jaoks parandatud: www.fidelityrewards.com .
Värskendan siin, kui sellel konkreetsel veebisaidil peaks ilmnema probleeme.
Aitäh
Witaj Paweł,
Wygląda na to, że zostało to naprawione w przypadku tej konkretnej witryny: www.fidelityrewards.com.
Zaktualizuję tutaj, jeśli pojawią się dalsze problemy z tą konkretną witryną.
Dziękuję
Здравствуйте, Павел!
Кажется, это исправлено для этого конкретного веб-сайта: www.fidelityrewards.com.
Я сообщу здесь, если возникнут какие-либо дальнейшие проблемы с этим конкретным веб-сайтом.
Спасибо
-
Same problem:
www.huntington.com
(website of bank that issues its very own credit card; consumer makes credit card balance payments here)
www.myaccountaccess.com
(website of large international credit card issuer on behalf of many banks; consumer makes credit card balance payments here)
F-Secure Banking Protection prevents webpage re-directs and webpage content\elements from loading. Webpages are unusable while F-Secure Banking Protection is enabled for each website.
🚩 What Do You Think?
We’d love your thoughts on our fresh look! Quick survey, big impact!