Is Web Signer for UTSP safe?
Web Signer for UTSP sends the user's signing PIN and the document to be signed to a local Thales application when signing UK BACS and Direct Debit payment transactions.
On UK Bacs/Direct Debit payment portals (Lloyds, Bank of Scotland, Vocalink and related BACS bureau sites), this extension's content script reads the PIN entered into its signing modal along with the document data, certificate and slot identifiers, and passes them to its background worker. The background worker forwards that data over Chrome's native messaging channel to a locally installed Thales/Gemalto application (com.gemalto.esignerwe) that performs the actual cryptographic signing with a hardware or software certificate. This flow only runs on the specific BACS/payment-portal domains listed in the extension's content script, and the data goes to the user's own local signing software, not an external server.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.