Hang Seng Bank (China) Limited


Frequently Asked Questions
 
5. Privacy and Security
Q : How can I be sure that my information and account data are securely sent through Hang Seng Personal e-Banking?
A :

Confidentiality of customer account information is our utmost concern. To ensure confidentiality, the following security measures are used to protect our customers:

- Hang Seng Personal e-Banking is under a secure 128-bit encryption, the highest level of encryption commercially available. All data sent to and from Hang Seng Bank is encrypted to protect your personal and financial information.
- User Name, Password and Security Code must be entered to authenticate your identity every time you log on to Personal e-Banking. Your Password will be temporarily suspended if you incorrectly key in your Password three consecutive times.
-

If your computer is left idle for more than 20 minutes, the system will automatically log off to prevent any unauthorized access.

   
Q : How can I check if 128-bit encryption is being used?
A :

For Microsoft Internet Explorer:
- Move the mouse pointer over the 'security lock icon'; OR
- Select "File" and then "Properties", "Connection" with "TLS 1.0, RC4 with 128 bit encryption (High); RSA with 2048 bit exchange" should be shown.

   
Q : Must I have cookies enabled on my browser?
A : Yes. For Microsoft Internet Explorer:
a) Click on 'Tools' on the browser toolbar and select 'Internet Options'.
b) Choose the 'Security' page.
c) Click 'Custom Level'.
d) Click 'Enable' under 'Allow Cookies that are Stored on your Computer'.
e) Click 'OK'.
   
Q :
How can I check that the web page is ready that of Hang Seng Bank?
A :

In order to assure our customers that they are dealing with Hang Seng Bank, we provide a certificate at the beginning of the session. At the browser window, there will be an icon telling you if the page has been encrypted. Don't type your Password on a page that isn't encrypted. Simply click on the Encrypted Icon and you will see the security certificate of Hang Seng Bank (China) Limited.

For Microsoft Internet Explorer:
You may check the validity of the certificate as follows:

- Click the "security lock icon" (enable status bar if it cannot be seen)
- Check that the certificate information is displayed with:

Issued to = www.hangseng.com.cn
Issued by = Symantec Class 3 EV SSL SGC CA - G3
Valid from = "......" is a valid date

- Check if this certificate is within a valid date.

   
Q :
Can I exit Hang Seng Personal e-Banking by clicking the browser-closing button at the top-right of the window?
A : You should click the Logoff button on the navigation bar on the screen. This will ensure that your session is properly logged off.
   
Q : What precautions should I take to avoid unauthorized access to my accounts online?
A : To avoid unauthorized access to your account(s), you should not undertake any transactions or check your account balances in an area where Internet service is available to the public. You should also note the following points in taking care of your password:
- Do not disclose your password to anyone (not even the Bank's employees. No member of Bank staff will ever ask for your Password)
- Do not allow anyone else to use your Password
- Do not write down or record the Password without disguising it
- Do not use your birthday, name, Identity Card number, passport number, telephone number or similar numbers as your Password.
- Do not use a Password used on other web sites
- Periodically change your Password (at least every 30 or 60 days) via e-Banking Services.
   
Q : What is Spyware?
A :
- Spyware is a computer software program that installs itself without a user's permission and does not tell or dishonestly tells the user what information it is gathering from the computer and how it is using it.
- It transmits collected information to an unauthorized organization that use it to make profit in some way.
- It can lead to security issues such as 'Key logging', 'Confidential Information Leakage' and 'Compromised Computer Security'.
 
What to do
- To prevent the installation of spyware without your consent, do not download any freeware onto the computer that you use to access Internet banking.
- Always run an anti-virus software program and/or anti-spyware software before you download other programs or open e-mails.
- Regularly update your anti-virus software and Windows security patches.
- Change your Internet banking password REGULARLY to protect your personal data.
   
Q : What should I do if I forget my Password ?
A : You must to reset your password by clicking the "Forget your password?" hyperlink on the logon page. After completion, you are required to print and sign the acknowledgement letter and send it to any of our branches/sub-branches to activate your new password, or you may also bring the letter to one of our branches/sub-branches in person for assistance. If you have just copied the Reference Number and the Request Time as stated on the acknowledgement letter, you will be asked to sign an e-Banking Service Changes Form at the branch.
   
Q :
What is my User Name ?
A :
- Your User Name is for identifying you when you access our e-Banking Services. You set up your User Name when you register for e-Banking. Each User Name must be unique.
- Your User Name should be something you can easily remember, yet cannot be easily guessed by anyone else. If you wish to use your name (or something equally familiar), we suggest using a mixture of letters and/or numbers.
- The auto-complete function on your browser should be disabled to avoid the automatic completion of your name when you type in User Name.
In the Internet Explorer browser, the auto-complete feature saves previous entries you have made for web addresses, forms, and Passwords. When you type information in one of these fields, auto-complete suggests possible matches. These matches can include folder and programme names you type in the address bar, and search queries, stock quotes, or information for just about any other field you fill in on a web page.
While you use the Personal e-Banking service, it will automatically prompt your User Name which you have used in the system. For security protection, the auto-complete function of your browser should be disabled to avoid the automatic completion of your name when you start to type the User Name.
To turn auto-complete on or off, first click the 'Tools' menu, then click 'Internet Options', the 'Content' tab, and the 'auto-complete' button. Finally disable the 'User Names and P asswords on forms'.
   
Q : Can I change my User Name and Password?
A : Once you've selected your User Name, it cannot be changed. Your Password can be altered at any time. Your new Password can be composed if alphanumeric characters (A-Z, 0-9) plus special characters (@), underscore (_), hyphen(-), apostrophe (’) and full stop(.), and must not be the same as your User Name or your old Password.
   
Q :
If I suspect there are unauthorized transactions in my account, what should I do?
A : Please immediately call our Customer Service Hotline 8008 30 8008 / 4008 30 8008 for assistance.
   
Q : What is your Internet privacy policy?
A : You can refer to our privacy policy by clicking here.
   
Q : My company uses a proxy server to speed up Internet access and increase security. How could this affect the use of your site?
A :

You may have difficulties in obtaining access to parts of our site sometimes. In addition, some proxy server configurations have made it difficult for other users to access the site. If you experience access problems and you know your company has integrated a proxy server, check with your system administrator. Our experience has been that, with the administrator's assistance, most situations can be resolved.

   
Q : What other security tips do I need to take note of?
A : You should:
- implement adequate physical security control over your PC(s).
- install virus detection software on your computer to protect from it known viruses. You should update this software regularly to ensure that you have the latest protection.
- install a firewall on your computer to help prevent unauthorized access and update this firewall regularly to ensure you are covered to the fullest extent possible. Please refer to your PC or software vendor to identify a firewall that best suits your PC environment.
- ensure you regularly check for, download and apply security updates and patches to your PC/browser. These are designed to provide you with protection from known possible security problems.
- to prevent viruses or other unwanted problems, do not open attachments from unknown or untrustworthy sources.
- not install pirated software or software from unknown sources.
- beware of keystroke loggers (i.e. hardware or software installed in your PC without your knowledge to record all keystrokes entered), hacker tools and other computer crime risks.
- know everyone who uses your computer and limit unauthorized access.
- always disconnect from the Internet when you have finished to avoid leaving your computer online when you are away from your pc.
- never write down your Internet banking details in a format that can be recognized by others. If you store any personal information in an electronic device, please ensure that it it well protected so that you are the only authorized person who can access the stored information.
- not access Hang Seng Personal e-Banking from computer terminals which are shared with other users (e.g. cyber cafes), as it is difficult to ensure these PCs are free from hacker programmes (someone might be able to access your personal/account information).
- ensure all other Internet sessions are closed before you log on to Internet banking. While you have an Internet banking session open, we recommend that you do not open other Internet browser sessions and access other sites. This can help to ensure your financial information is protected and blocked from unauthorized access via another website.
- type in the URL to guarantee that you have entered the real e-Banking site of Hang Seng Bank. Save the URL to your favourites and use this link to access the site in the future.
- verify that the Internet address is the genuine Hang Seng Bank website by double clicking the 'lock' icon at the bottom bar of the screen to check the security certificate of Hang Seng Bank.
- always remember to log off properly using the "Logoff" button when you have completed your banking activities.
- review your account regularly and always keep good records of your personal finances.
- you may want to print a hardcopy of this security FAQ page for reading offline.
  BackTop
   


Hang Seng China cross-border disclaimer