Feature Request: User Consent Before Activating Banking Protection - HUMAN CONTROL

rfv370
rfv370 Posts: 4 Observer

Dear F-Secure Team,

I recently encountered a critical issue with the Banking Protection feature that I believe requires immediate attention. While attempting to pay my hospital bill, the Banking Protection activated automatically, interrupting the payment process without any prior warning or consent. This behavior left me unable to complete the payment and caused unnecessary delays and stress.

Here are the key concerns with the current functionality:

  1. Automatic Activation Without User Consent: The Banking Protection triggers immediately upon detecting a payment process, stopping all activity without giving the user a chance to review or approve this action.
  2. Lack of Control for Users: The speed at which the feature activates makes it impossible to override or manage the process before it interrupts critical tasks.
  3. Potential for Anxiety: While I managed to work around the issue as an IT professional, this could cause significant anxiety or confusion for less tech-savvy users, such as elderly family members, especially during urgent transactions.

My Suggestions for Improvement:

  1. Add a Consent Prompt: Implement a pop-up notification that allows users to approve or decline the activation of Banking Protection before it halts ongoing processes.
  2. Grace Period: Introduce a short delay or grace period (e.g., 5–10 seconds) before activating the protection, giving users time to react.
  3. Customizable Settings: Allow users to configure Banking Protection to suit their preferences, such as enabling or disabling automatic activation for certain websites.

Your product is excellent, and I greatly appreciate the protection it offers. However, this current implementation is counterproductive in critical scenarios and could be refined to better balance security with usability.

Thank you for considering this feature request. I look forward to hearing your thoughts and any potential updates regarding this matter.

Sincerely,
Robert

1 votes

Active · Last Updated

Comments

  • Ukko
    Ukko Posts: 3,778 Superuser

    Hello,

    I'm also only F-Secure user.

    I like some of the general points of some of the ideas proposed. Because they sound quite good in parts.

    However, it may be possible to report mentioned 'routine' with mentioned trouble directly to F-Secure Support in the meantime (or via F-Secure SAS/Labs: https://www.f-secure.com/en/support/submit-a-sample) - https://www.f-secure.com/en/support

    Because (https://community.f-secure.com/internet-security-en/kb/articles/5276-what-is-banking-protection-and-how-does-it-work) should not interrupting the payment process. When this happens, something has gone wrong by design. And it would be better to eliminate the reasons for this. To improve the current design even without significant changes in approach (such as the ideas you suggested).

    It was not entirely clear to me whether a particular website, a specific online payment gateway or application was blocked. But in any case, the F-Secure Banking Protection feature should support such a scenario. So you can try to describe it through support and maybe they will be able to correct the situation specifically in this scenario (or for all similar ones). While your feature request will be active for upvote by users and consideration by developers.

    Thanks!

  • rfv370
    rfv370 Posts: 4 Observer

    Hi @Ukko

    Indeed, I started off first with a long and bitter complain to the F-Secure support…. :-)…. trust me. they know about me.

    I was very offensive with the F-Secure support as it happened to me when paying for hospital registration! And the registration got… stuck… ! A real pain to restart the whole process and more frustration…anyway at the end it went through on second time and I was ready and disable f-secure completely to deal with the transaction… - albeit I lost the a side insurance on hospital room which would not accept a re-try… - mild issue for me but for an older person it could be serious.

    Over all, I agree with you that this is a very serious on the F-secure protection, BECAUSE, I am an IT guy and I know how to do it - ie to disable F-secure, purge everything and re-start a full process with F-secure disabled.

    But my whole family , kids and parents, are covered through my f-secure 10+ licenses on all their computers, phones and tablets…. hence it could generate serious issue with our parents which are now quite senior and not versed at all in IT. Such issue of breaking a payment process could generate very serious anxiety and delays on some transaction which could be serious - like doctors, medics , hospital and so on…. this is why I was so no unhappy with the handling method used by the banking protection which activated itself blocked everything and disapaered like a ghost without asking anything !!! a flickering green borderline around my browser, transaction stopped and, hop, it vanished !!! what!!!!

    I was so angry that this could have happened to one of my parents or parents in law… while I am away or on business crisis unavailable ….. - as I am the IT guy of the family… I could already feel the family crisis pointing its shadow…. :-)

    So yes, I would really appreciate that F-Secure team does change the behavior of the banking protection.

    cheers and enjoy the festivity tonight!!

    best

    Robert

  • JOnes
    JOnes Posts: 731 Forum Champion

    I would suggest at least the following:

    1. Submit a feature request for banking protection to the "Feature Request" queue(if not allready)

    2. Send a sample URL to F-Secure lab where banking protection is working strangely/not working at all https://www.f-secure.com/en/support/submit-a-sample

    3. Cross your fingers for many "likes" and hope for the best

    4. Banking protection is pretty easy to disable at the site level if experiencing issues

    https://help.f-secure.com/product.html#home/total-windows/latest/en/task_591B3C762B54490B8A70CE6B6DB84CAD-latest-en

  • rfv370
    rfv370 Posts: 4 Observer

    @JOnes

    thanks I tried submission but the URL submission seems to like the hospital URL…

    A bit weird…. why the submission page does not like the URL… ( https:∕∕assurance-prolongation-ramsay․souscription․eu∕souscription∕paiement?errorPBX=error&uid= ) - which I provided to the F-Secure support (my requested was handled by Arivind R - a human support I suspect, at least typing like a human ;-) ).

    Also looking at the address domain "souscription.eu" itself it is suspicious….yeah I know. - but I got really registered to their hospital, so it not a fake address- I suspect it is a redirect from the the secondary insurance system within the hospital registration system.

    cheers

  • rfv370
    rfv370 Posts: 4 Observer

    And someone did register our chat within the "Features Request". Thanks to him/her!

    cheers.

  • Ukko
    Ukko Posts: 3,778 Superuser

    Hello,

    bit weird…. why the submission page does not like the URL…

    I tried typing your URL from the screenshot and it was okay for F-Secure SAS page.

    ( https:∕∕assurance-prolongation-ramsay․souscription․eu∕souscription∕paiement?errorPBX=error&uid= )

    When you then typed it there (what was also visible in the screenshot) - the trouble is with "∕" as I suppose.

    I mean, by using "/" instead of "∕" and URL is acceptable for F-Secure SAS form.

    just like https://domain_name_whatever_canbe.whateverdomainone/subpage/parameters?one=another

    Actually, I tried to use "∕" for a couple more websites with URL forms and no one accepted it (from tried ones by me).

    Thanks!

Feedback on New Design