EFForg / privacybadger

Privacy Badger is a browser extension that automatically learns to block invisible trackers.
https://privacybadger.org
Other
3.19k stars 386 forks source link

Credit card 2FA broken #2919

Open soleofthesea opened 1 year ago

soleofthesea commented 1 year ago

I'm having an issue when I try to purchase something online via credit card and it asks for SMS 2FA. While I can recieve the OTP just fine attempting to submit/continue causes an infinite hang. Occured twice with an HSBC-issued Mastercard.

Apologies for the lack of details, but I was a bit hesitant with mucking about with the extension given it forces an auto-reload.

ghostwords commented 1 year ago

Hello and thanks for opening an issue!

What site does this happen on?

Have you already submitted a broken site report? To do so, get to the step that breaks (you put in the one time verification code and it doesn't do anything), open Privacy Badger's popup and click on "Report broken site".

soleofthesea commented 1 year ago

Hi ghostwords, thanks for the attention to this matter.

I ran into the issue on two different sites, Siemens and Deliveroo. The payment process gets deferred to a different domain though...

I've yet to submit a report, and while I would love to, I'm concerned attempts to recreate the bug would get my card flagged for suspicious activity...

ghostwords commented 1 year ago

Could you visit Privacy Badger's options page, select the Tracking Domains tab, and search for "aexp-static"? Do you get any results?

Edit: Never mind, wrong card.

ghostwords commented 1 year ago

I would like to fix this, but I don't know which domain or domains are responsible for the breakage at checkout.

Next time something like this happens, send us a broken site report, and then let me know here the site it happened on. Thank you and sorry for the hassle!