webcompat / web-bugs

A place to report bugs on websites.
https://webcompat.com
Mozilla Public License 2.0
746 stars 67 forks source link

www.onlinecreditcenter6.com - see bug description #1489

Closed GdrjirfRtrUhYUdrjUMm closed 8 years ago

GdrjirfRtrUhYUdrjUMm commented 9 years ago

URL: https://www.onlinecreditcenter6.com/consumergen2/login.do?subActionId=1000&clientId=amazon&langId=en&accountType=plcc Browser / Version: Firefox 39.0 Operating System: Windows 7 Problem type: Something else - I'll add details below

Steps to Reproduce 1) Navigate to: https://www.onlinecreditcenter6.com/consumergen2/login.do?subActionId=1000&clientId=amazon&langId=en&accountType=plcc 2) …

Expected Behavior: The site to support TLS version 1.2, Forward Secrecy, OCSP stapling, DNSSEC, and HSTS.

Actual Behavior: It doesn't.

GdrjirfRtrUhYUdrjUMm commented 9 years ago

Their Nginx server supports all these options except DNSSEC which would have to be implemented with their domain registrar.

hallvors commented 9 years ago

https://www.ssllabs.com/ssltest/analyze.html?d=www.onlinecreditcenter6.com gives a C score - they have stuff to do..

hallvors commented 9 years ago

(Is this a legitimate site though? Some Amazon branding..looks scammy to me. WDYT @karlcow?)

karlcow commented 9 years ago

They link to it in https://www.amazon.com/gp/help/customer/display.html?nodeId=201133570

When → http GET http://www.syncbank.com/amazon, we get:

HTTP/1.1 301 Moved Permanently
Content-length: 0
Date: Tue, 13 Oct 2015 21:50:30 GMT
Location: https://www.onlinecreditcenter6.com/consumergen2/login.do?subActionId=1000&clientId=amazon&langId=en&accountType=plcc
Server: Oracle-iPlanet-Web-Server/7.0
karlcow commented 8 years ago

The score is now B instead of C. https://www.ssllabs.com/ssltest/analyze.html?d=www.onlinecreditcenter6.com

as for the domain name

synchronycredit.com onlinecreditcenter6.com

are both registered to

Admin Organization: Synchrony Financial
Admin Street: 777 Long Ridge Road
Admin City: Stamford
Admin State/Province: CT
Admin Postal Code: 06902
Admin Country: US
Admin Phone: +1.8664194096

As if it's legit http://www.amazon.com/forum/store%20card?_encoding=UTF8&cdForum=Fx1RJQNXF8J189X&cdThread=Tx3VH8J413J1GNV

Yup it seems.

Contact form. https://www.synchronyfinancial.com/compliments-concerns-form.html

karlcow commented 8 years ago

This server accepts RC4 cipher, but only with older protocol versions. Grade capped to B.

I'll switch to worksforme.

This is not exactly a Web Compatibility issue. But feel free to contact them.