Thursday, July 9, 2009

Investec Online Registration: unsecure

Investec Asset Management is pushing for investors to register for on-line access to their investment portfolio. However, the registration page is via unsecure http (not https), which means data transmitted is not encrypted. This might not sound like a problem, but they require information such as ID number, street address and full banking details with account numbers. Be aware that it's exactly this kind of information that identity thieves are after.

Here is a screen dump showing some of the info they are looking for, with the unsecure http.

I have tried to contact Investec concerning this matter, but they are singularly disinterested in doing anything about it. The irony is that once you are registered, logging in to their site is via secure http...