List of UK stock trading websites that are not secure by default

By Stephen Kellett
19 December, 2017

This is one of several posts of the topic of security of websites. Inspired by my initial post on the security of UK banks.

The reason for splitting this data into multiple posts is to make it more manageable. So that data on one institution is not mixed with data on another type of institution.

I thought it would be interesting to look at each bank in the UK to see if when you visit their company homepage, is that secure by default? That is, is the page loaded by HTTPS? There are more tests than this that you could do, but that’s the baseline. If they can’t meet that then the other tests are meaningless.

Some banks provide the website in both http and https versions. This is bad practice. If someone visits the website as http then the customer should be served the https version of the page.

Also please note, these test results are for a desktop computer visiting the website. A mobile phone may well get a different experience. In other words desktop visitors may get a secure site, but mobile visitors might not. Or vice versa.

The following key is used for the secure status:

YesThe site is secure, loaded via https
DualThe site can be loaded via http, or via https.
InvalidThe site loads via https, but the security certificate is invalid and thus the site is insecure.
PartialThe site loads via https, but loads some parts of the page without https. The site is insecure.
NoThe site is loaded via http, not via https.
FixedThe site is loaded via https, but at the time of first writing it was loaded via http.
??We could not find a website to evaluate.

We tested 66 stock trading websites, most of them based in the UK. We found 20 stock trading websites that did not have a secure home page (not https or did have https with an invalid security certificate). That is 30% of stock trading websites have security vulnerabilities.

Stock TraderSecureHome Page
Alliance Trust SavingYeshttps://atonline.alliancetrust.co.uk/atonline/login.jsp
ANZYeshttps://shareinvesting.anz.com/home.aspx
Angel BrokingNohttp://www.angelbroking.com/online-share-trading
Bank of ScotlandYeshttps://www.bankofscotland.co.uk/
BarclaysYeshttps://www.smartinvestor.barclays.co.uk/campaign/investment-account.html
Barclays Trading HubYeshttps://www.barclaystradinghub.co.uk/home/what-is-cfd-trading/spread-trading-versus-contracts-for-difference.html
Beaufort SecuritiesYeshttps://www.beaufortsecurities.com/online-share-dealing-t-14
BelforfxNohttp://bonus.belforfx.com
Broker DirectYeshttps://www.brokerdirect.co.uk/News/ShareTradingNew.aspx
Charles SchwabNohttp://www.schwab.co.uk/public/schwab-uk-en/us-investing
Charles Stanley DirectYeshttps://www.charles-stanley-direct.co.uk
CitiYeshttps://www.citibank.co.uk/personal/equities.do
City IndexYeshttps://www.cityindex.co.uk/share-trading/
CMC MarketsYeshttps://www.cmcmarkets.com/en-au/markets-shares
ComputershareYeshttps://www.computershare.trade/
DegiroYeshttps://www.degiro.co.uk/
Digital LookNohttp://www.digitallook.com
Direct Market TouchYeshttps://www.directmarkettouch.com/
EtoroYeshttps://www.etoro.com/
Easy Share TradingYeshttps://easysharetrading.co.uk/stocks-and-shares-courses/
ETradeYeshttps://us.etrade.com/home
ETX CapitalYeshttps://www.etxcapital.co.uk/equities-trading
Equiniti share viewNohttp://www.shareview.co.uk/4/Info/Portfolio/Default/en/Home/Pages/Home.aspx
Fair Investment CompanyNohttp://www.fairinvestment.co.uk/uk_share_trading.aspx
Fantasy Stock ExchangeNohttp://www.fantasystockexchange.biz/
FCMB Group PlcNohttp://fcmbgroup.com/share-trading-policy
First DirectNohttp://www1.firstdirect.com/1/2/savings-and-investments/sharedealing
FortradeYeshttps://www.fortrade.com/
Free TradeYeshttps://freetrade.io/
FxProYeshttps://www.fxpro.co.uk/trading/shares
Get StocksYeshttps://getstocks.com
HalifaxYeshttps://www.halifax.co.uk/sharedealing/our-accounts/share-dealing-account/Default.asp
Hargreaves LansdownNohttp://www.hl.co.uk/investment-services/fund-and-share-account
HSBCYeshttps://investments.hsbc.co.uk/product/9/sharedealing
IGYeshttps://www.ig.com/uk/shares
Interactive investorNohttp://www.iii.co.uk/
InternaxxYeshttps://www.internaxx.com/
iDealingYeshttps://www.idealing.com/en/index
iWebNohttp://www.iweb-sharedealing.co.uk/share-dealing-home.asp
Lloyds BankYeshttps://www.lloydsbank.com/share-dealing/share-dealing-account.asp
London Capital GroupYeshttps://www.lcg.com/uk/
London South EastNohttp://www.lse.co.uk/share-trading/
Natwest InvestYeshttps://personal.natwest.com/personal/investments/natwest_invest/natwest-invest.html
Plus 500Yeshttps://www.plus500.co.uk/Trading/Stocks
Redmayne BentleyYeshttps://www.redmayne.co.uk/stockbroking
Religare brokingNohttp://www.religareonline.com/
RHB Trade SmartYeshttps://rhbtradesmart.com/
Saga share directYeshttp://www.sagasharedirect.co.uk/
Saxo Capital MarketsYeshttps://www.home.saxo/en-gb
Self TradeYeshttps://selftrade.co.uk/
Shareprices.comYeshttps://shareprices.com/trading/
Share ScopeYeshttps://www.sharescope.co.uk/
Stock TradeNohttp://www.stocktrade.co.uk/
Sure TraderYeshttps://www.suretrader.com/
SVS XOYeshttps://svsxo.com/
The share centreYeshttps://www.share.com/share-account/
WestpacYeshttps://www.westpac.com.au/personal-banking/investments/share-trading/
UAEXChangeNohttp://www.uaeexchange-etrade.com/
UK Trading ViewYeshttps://uk.tradingview.com/
Virgin MoneyYeshttps://uk.virginmoney.com/virgin/isa/stocks-and-shares/#
Which Way To PayNohttp://www.whichwaytopay.com/compare-share-dealing-summary.asp
XMYeshttps://www.xm.co.uk/
XONohttp://www.x-o.co.uk/
XTBYeshttps://www.xtb.com/en
Yorkshire Building SocietyNohttp://sharedealing.ybs.co.uk/
You InvestYeshttps://www.youinvest.co.uk/dealing-account

Charles Schwab & First Direct

First Direct were the first bank without a bank branch in the UK. That is they’ve always been online only. But their website is not secure by default. It is vulnerable to a man in the middle attack.

Charles Schwab was one of the very first share trading sites aimed at making share trading easy, even for non-experts. As such they’ve been around for a long time. But their website is not secure by default. It is vulnerable to a man in the middle attack.

Just because a business is established, that doesn’t mean you can trust their security.

Fantasy Stock Exchange

Fantasy Stock Exchange is website where children can go to trade pretend stocks and shares. To understand what is happening without any financial risks. It’s an interesting idea. But it’s not secure by default. Anything where children are involved I’d like to think that is secure, we read enough unpleasant stuff about grooming in other environments without their accounts being at risk as well.

Insecure Login

Most of these insecure websites are secure when you try to login, but not secure on the homepage. That makes them vulnerable to a man in the middle attack. However, one stock trading site, Digital Look, is completely insecure, even the login page is not secure, and has a remember me option!

Digital Look is not secure

Insecure Browser Extension

Another website was so problematic that we could not visit the website without being forced to install a chrome extension, that was allegedly to improve our security while using their site. The problems with this is are numerous:

  • The extension is downloaded from a non-disclosed location (you can’t see where it’s downloaded from, a website name briefly flashes past that is not destination website).
  • The extension is download from a non-secure location. Thus it could be anything.
  • You can’t verify anything about the extension before installing it in Chrome.
  • Whether you choose to install an extension in order to view a website should be a choice, not mandatory.

We were going to name this company, but when we later tried to reproduce this to get some screenshots of this dangerous chrome extension behaviour could not be repeated. If you see behaviour like this with a website please let us know.

Fully functional, free for 30 days