Banking Protection Override

Dober
Dober Posts: 4 Explorer

Hi

F-secure banking protection needs manual override as with some banking sites that i use the banking protection green window does not activate.

3 votes

Active · Last Updated

Comments

  • TVC15
    TVC15 Posts: 74 Active Engager
    edited September 13

    voted +1 Something where we can allow a Banking website.

    But, we do have this article, just in case it's addressed here:

    https://community.f-secure.com/internet-security-en/kb/articles/5239-banking-protection-does-not-activate-when-visiting-a-banking-site

    Diagnosis

    There are a few possibilities why Banking Protection may not activate when visiting a banking site. For example:

    • The browsing protection extension is not enabled or is not installed in your browser.
    • There is a 60 second 'cool down' period after ending the previous banking session. If you start a new session during this time, Banking Protection is not activated.
    • The product may have been upgraded in the background.
    • Your online bank may not be listed in our database.

    And as is shown in the article, we can submit the site to F-Secure support who could hopefully enable that on their end, for some of the other users to benefit from as well? From the F-Secure Total Windows desktop app. click on the Scam Protection module (or Safe Browsing for Internet Security) → left hand side, Submit a sample (for those who may read your topic).

    Kind regards.

  • Ukko
    Ukko Posts: 3,768 Superuser
    edited September 18

    Hello,

    And another thing to note: the way the functionality (Banking Protection) is currently/still designed - as soon as Banking Protection Session is activated, it basically affects the entire system as a whole.

    Therefore, if some banking website does not trigger the Banking Protection Session (or only some specific pages), and F-Secure Labs via F-Secure SAS cannot able to fix the situation, then just open in any (additional) browser tab a reliable banking website (or test-page: banking.fstestdomain.com with HTTPS) and use the desired banking website as its triggered from there.

    // Sorry if my understanding of the design is wrong.

  • TVC15
    TVC15 Posts: 74 Active Engager

    Good point, nice option. Open a known site that triggers the Banking protection, then in the same Browser window, open another tab to the other site, it will then be under the Banking protection.

    I think your understanding is spot on, it provides a nice workaround solution :)

  • TVC15
    TVC15 Posts: 74 Active Engager
    edited September 27

    And you're right, Ukko, that will only work regarding another banking site that may not of as yet, or for some reason, automatedly open the Banking Protection feature when the website is accessed.

    The example of trying to open another tab to an email account in the same window, rightly gets blocked by F-Secure as not being a Banking site :)

    Have a great weekend :)

  • Ukko
    Ukko Posts: 3,768 Superuser

    Hello,

    Thanks for your feedback. Actually..

     rightly gets blocked by F-Secure as not being a Banking site :)

    I don't think it was blocked due to not being a banking site. Just, again, for some reason, it is not marked in (Security Cloud) as reliable for banking transactions. Most often, email service will be available (in case if for transactions it may be necessary). I don’t know how long Protonmail has been using this domain, but the old one... seemed to be available during banking transactions (or, maybe, I never tried to check it).

    In recent years, it has been very difficult for me to come across a known website that would be blocked during banking transactions. And most often, it was some kind of too fresh or “subdomain of a subdomain” of the bank or its partners.

    Furthermore, there is some tricky thing as a "cache" in Security Cloud. Which will allow me to use some websites in circumstances where I wouldn't expect. And I feel strange about it. But I don’t think that this can somehow affect the degree of security and something similar (that is, it does not pose a particular threat to the user from my point of view).

    I, usually, will check if Banking Protection is working properly by trying to connect via ftp to some ftp resource (by using 'Run..') - it should not be accessible.

    Then, in case if you want to use a blocked resource while under Banking Protection session - you can always allow that website locally (Allow/Denied websites or Websites exclusions list). In general, this move will bypass domain for any 'checks' (perhaps).

    Thanks!

Feedback on New Design