<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BT.com, My Account, SSL and reporting the problem. in Archive</title>
    <link>https://business.forums.bt.com/t5/Archive/BT-com-My-Account-SSL-and-reporting-the-problem/m-p/37413#M23181</link>
    <description>&lt;P&gt;Logged in to my business account today from&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&amp;nbsp;&lt;A href="https://www.bt.com/cmp/public/hub.do" target="_blank"&gt;https://www.bt.com/cmp/public/hub.do&lt;/A&gt;&amp;nbsp;page and when it completed the browser crossed out the https and the padlock. &amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This usually indicates a web site that should be using SSL but isn't. &amp;nbsp;My billing details were displayed. &amp;nbsp;Knowing that the site was therefore not secure I hit sign out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This produced the following&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;"Duplicate headers received from server&lt;/LI&gt;&lt;LI&gt;The response from the server contained duplicate headers. This problem is generally the result of a misconfigured website or proxy. Only the website or proxy administrator can fix this issue.&lt;/LI&gt;&lt;LI&gt;Error 350 (net::ERR_RESPONSE_HEADERS_MULTIPLE_LOCATION): Multiple Location headers received. This is disallowed to protect against HTTP response splitting attacks."&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Now this sounds like a problem for BT.com's website team. &amp;nbsp;I tried for two hours to report this problem. &amp;nbsp;In the process being passed from one team to another. &amp;nbsp;I was repeatably assured that the website was safe to use but if I felt it wasn't I could use the telephone or email to access my account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For me this has rasied 3 issues&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I couldn't get through to anyone who understood the problem.&lt;/LI&gt;&lt;LI&gt;I couldn't get to find who to talk to re the problem.&lt;/LI&gt;&lt;LI&gt;The agents who assured me that the site was safe to use need some further training before continuing with their day job.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Has anybody else noticed the issue?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Apr 2012 14:54:03 GMT</pubDate>
    <dc:creator>NickPaling</dc:creator>
    <dc:date>2012-04-05T14:54:03Z</dc:date>
    <item>
      <title>BT.com, My Account, SSL and reporting the problem.</title>
      <link>https://business.forums.bt.com/t5/Archive/BT-com-My-Account-SSL-and-reporting-the-problem/m-p/37413#M23181</link>
      <description>&lt;P&gt;Logged in to my business account today from&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&amp;nbsp;&lt;A href="https://www.bt.com/cmp/public/hub.do" target="_blank"&gt;https://www.bt.com/cmp/public/hub.do&lt;/A&gt;&amp;nbsp;page and when it completed the browser crossed out the https and the padlock. &amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This usually indicates a web site that should be using SSL but isn't. &amp;nbsp;My billing details were displayed. &amp;nbsp;Knowing that the site was therefore not secure I hit sign out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This produced the following&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;"Duplicate headers received from server&lt;/LI&gt;&lt;LI&gt;The response from the server contained duplicate headers. This problem is generally the result of a misconfigured website or proxy. Only the website or proxy administrator can fix this issue.&lt;/LI&gt;&lt;LI&gt;Error 350 (net::ERR_RESPONSE_HEADERS_MULTIPLE_LOCATION): Multiple Location headers received. This is disallowed to protect against HTTP response splitting attacks."&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Now this sounds like a problem for BT.com's website team. &amp;nbsp;I tried for two hours to report this problem. &amp;nbsp;In the process being passed from one team to another. &amp;nbsp;I was repeatably assured that the website was safe to use but if I felt it wasn't I could use the telephone or email to access my account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For me this has rasied 3 issues&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I couldn't get through to anyone who understood the problem.&lt;/LI&gt;&lt;LI&gt;I couldn't get to find who to talk to re the problem.&lt;/LI&gt;&lt;LI&gt;The agents who assured me that the site was safe to use need some further training before continuing with their day job.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Has anybody else noticed the issue?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2012 14:54:03 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/BT-com-My-Account-SSL-and-reporting-the-problem/m-p/37413#M23181</guid>
      <dc:creator>NickPaling</dc:creator>
      <dc:date>2012-04-05T14:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: BT.com, My Account, SSL and reporting the problem.</title>
      <link>https://business.forums.bt.com/t5/Archive/BT-com-My-Account-SSL-and-reporting-the-problem/m-p/38175#M23182</link>
      <description>&lt;P&gt;I wouldn't worry to much about it. It means that some parts of the webpage are only not encoded on SSL like javascript.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't pinpoint which part it is but overall, I would say the connection is secure. Btw, what browser are you using on this? Also try other browsers and see if the results are the same.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Apr 2012 13:36:23 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/BT-com-My-Account-SSL-and-reporting-the-problem/m-p/38175#M23182</guid>
      <dc:creator>kuerten</dc:creator>
      <dc:date>2012-04-21T13:36:23Z</dc:date>
    </item>
  </channel>
</rss>

