Nice idea, shame about the dangerously poor implementation
I ordered a Globe Cash Passport to withdraw cash from ATMs while abroad. The card arrived a few days later with a welcome letter and a copy of the terms and conditions; so far so good.
The letter instructed me to dial a phone number to activate the card. I navigated the automated menu until I was forwarded to another phone system. After five minutes on hold I was abruptly disconnected. I tried again. This time, I made it through to another automated system that asked for the 16 digit number printed on my card. That number is incorrect...that number is incorrect...that number is incorrect...that number is incorrect...the system refused to activate my card.
I was about to try Google when I noticed a phone number printed on the back of the card. Worth a try? It connected me to an identical automated system, only this one had a British accent instead of a US one. This system was happy to take my number and activate the card, so clearly they are printing the wrong phone number on the welcome letter - thanks Travelex!
That out of the way, it was time to set up my online account to check my balance. I made it through the maze of bizarre, antiquated web pages until they asked for my phone number. That number doesn't match our records...that number doesn't match our records...that number doesn't match our records. Hey, Travelex, how about giving me a clue as to the format you would like it in? Or maybe you'd like to try properly validating your online forms? I tried +44, I tried 0044, I tried a leading 0. No, the correct answer was no leading zero and no country code. Obviously...
That was exhausting! Time to try topping up the card I suppose? Hmmm...no, the online account doesn't have that facility. WHAT!?!? What year is this? If this system was a GCSE IT project, I would consider it to be unfinished.
Topping up is handled by a separate system that requires you to enter the full 16 digit Cash Passport number and all of your personal and bank details EVERY SINGLE TIME. Great work, guys! Unfortunately, every page of this monstrosity is encrypted with obsolete protocols, which you could almost get away with, except that the encryption on the final page (which is where you enter your bank details) is TOTALLY BROKEN.
I'm surprised to find a financial institution with weak and broken encryption that hasn't made headline news for a hacking scandal, but perhaps I'm the only customer to have waded this far through the Travelex quagmire. Needless to say, I won't be entering my bank details. I'll pay my bank's exorbitant foreign transaction fees, cancel my Globe Cash Passport on my return home, and try to forget that I ever heard the name 'Travelex'.
EDIT 16/04/2015 FOLLOWING TRAVELEX REPLY:
Travelex - "...this would be the same telephone number found on the back of the card."
The number in the letter and the number on the card are different. The number on the card worked, the number in the letter did not. It was obvious the numbers connected me to different systems.
Travelex - "When accessing a SHA-1 protected site in Internet Explorer or Mozilla Firefox, both browsers currently affirm that the site is secure, and can be trusted."
While I'm not thrilled about SHA-1, it wouldn't stop me using the website. My problem is that the page where you enter the payment details is not fully protected. This error is not related to the use of SHA-1; it is caused by incorrect implementation. The issue can be seen in Chrome, Firefox, Safari...any modern browser.
Travelex - "Travelex already performs regular security tests against it's web sites, using a specialist security testing partner. These tests would immediately identify any instances of ineffectual encryption functionality."
Get a Globe Cash Passport, try to top it up online, and see the problem for yourself. Once again, this is not SHA-1 related; this is a separate issue that occurs only on the page where you enter your payment details. It is very easy to test because it happens every time. The page is still broken as of today (16/04/2015).
Travelex - "In conclusion, Travelex takes the security of it's customer's data seriously, and does not consider the current support for SHA-1 to pose a significant, material risk."
Fair enough, I concede the point about SHA-1, but there is still the issue of the broken encryption on the payment page.
22 March 2015
Unprompted review