<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Australia Post/Click and Send Online Security Breach in Selling</title>
    <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27007#M4468</link>
    <description>&lt;P class="mce-p"&gt;Hmmm.. I am under the distinct impression that this is old news re-hashed...&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;I am pretty sure that they closed the site over the weekend a week or two back and "fixed" it then??&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Oct 2012 23:21:00 GMT</pubDate>
    <dc:creator>b3llag1na</dc:creator>
    <dc:date>2012-10-18T23:21:00Z</dc:date>
    <item>
      <title>Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/26972#M4454</link>
      <description>&lt;P class="mce-p"&gt;&lt;A href="http://www.heraldsun.com.au/news/national/australia-post-in-online-privacy-breach/story-fndo45r1-1226498834454"&gt;http://www.heraldsun.com.au/news/national/australia-post-in-online-privacy-breach/story-fndo45r1-1226498834454&lt;/A&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&lt;A href="http://www.heraldsun.com.au/news/national/australia-post-in-online-privacy-breach/story-fndo45r1-1226498834454"&gt; &lt;/A&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Arrghh.&amp;nbsp;&amp;nbsp; This is absolutely no surprise to me but makes me boiling mad.&amp;nbsp; When Click and Send first started I took them to task over the fact that they sent all my info (passwords and all) back to me unencrypted.&amp;nbsp;&amp;nbsp; 6 months later they were still doing it.&amp;nbsp; And now this.&amp;nbsp; As well as the consistent difficulties I have using their site.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Anyone else have this experience or am I just being unfairly grumpy? &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Boo.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2012 22:44:00 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/26972#M4454</guid>
      <dc:creator>boomct</dc:creator>
      <dc:date>2012-10-18T22:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/26998#M4463</link>
      <description>&lt;P class="mce-p"&gt;I have been using C&amp;amp;S from the time it was introduced and have not had any major problems; safe for the site disputing correct postcodes.&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;I find the claim that "Customers who typed a random number into the online parcel tracking system were provided with the details of thousands of customers" bit strange.&amp;nbsp; When you type tracking number into the search you do not get anybody's name and address; you just get where/when that particular parcel was lodged, other points of scan and then just the suburb where it was delivered.&amp;nbsp; I can imagine that if you have a tracking number and alter the last couple of digits you would be getting valid tracking numbers and the info would be available to you, but would be pretty much useless.&amp;nbsp; Some AP staff may have an access to more info, and if anybody was able to log in with the staff code they may be able to get such an info.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2012 23:16:32 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/26998#M4463</guid>
      <dc:creator>***super_nova***</dc:creator>
      <dc:date>2012-10-18T23:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27007#M4468</link>
      <description>&lt;P class="mce-p"&gt;Hmmm.. I am under the distinct impression that this is old news re-hashed...&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;I am pretty sure that they closed the site over the weekend a week or two back and "fixed" it then??&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2012 23:21:00 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27007#M4468</guid>
      <dc:creator>b3llag1na</dc:creator>
      <dc:date>2012-10-18T23:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27013#M4471</link>
      <description>&lt;P class="mce-p"&gt;No, I couldn't get tracking info yesterday and the day before for probably just under a day.&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Seems sus but now a bit worried. Tracking system isn't too crash hot as it is... now we have to worry about security breaches? &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 00:09:39 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27013#M4471</guid>
      <dc:creator>calsof</dc:creator>
      <dc:date>2012-10-19T00:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27021#M4473</link>
      <description>&lt;P class="mce-p"&gt;That article doesn't explain the (alleged) breach very well - the issue (again, allegedly &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ), was that once a transaction was completed via C&amp;amp;S, anyone could alter the URL of the site - which contains an ID number - with randomly selected numbers and bring up someone else's completed transaction details.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 00:46:32 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27021#M4473</guid>
      <dc:creator>digital*ghost</dc:creator>
      <dc:date>2012-10-19T00:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27032#M4476</link>
      <description>&lt;P class="mce-p"&gt;And yes, this happened a couple of weeks ago, with an announcement made by AP on the 4th of October:&amp;nbsp;&lt;A href="http://www2.ebay.com/aw/au/201210.shtml#2012-10-04165630"&gt;http://www2.ebay.com/aw/au/201210.shtml#2012-10-04165630&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 00:48:18 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27032#M4476</guid>
      <dc:creator>digital*ghost</dc:creator>
      <dc:date>2012-10-19T00:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27045#M4479</link>
      <description>&lt;P class="mce-p"&gt;As has been noted several times, this is old news.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 04:38:36 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27045#M4479</guid>
      <dc:creator>davewil1964</dc:creator>
      <dc:date>2012-10-19T04:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27062#M4481</link>
      <description>&lt;P class="mce-p"&gt;Old news perhaps, but it points to a system that has had IT security issues from the beginning which are very easily preventable.&amp;nbsp; And with rising Aus Post charges, I would expect much better.&amp;nbsp; Grumpph . . .&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 05:09:02 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27062#M4481</guid>
      <dc:creator>boomct</dc:creator>
      <dc:date>2012-10-19T05:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27085#M4487</link>
      <description>&lt;P class="mce-p"&gt;What a huge fuss about nothing, just like most of these scaremongering articles. If the press hadn't drawn attention to the issue just how many people would have tried to do this if they hadn't read about it? I suspect zero, I suspect AP found the problem themselves and then announced it and said their would be disruptions to the service while they did so.&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;I have only had a&amp;nbsp; problem with click &amp;amp; send twice and a quick phone call sorted them out quickly and efficiently and of course it was my ineptitude that caused them in the first place.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 06:13:38 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27085#M4487</guid>
      <dc:creator>phorum_junkie*</dc:creator>
      <dc:date>2012-10-19T06:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27095#M4488</link>
      <description>&lt;P class="mce-p"&gt;and I suspect that now you can use paypal to pay for click and send you can expect a lot more of it&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;the OP mentioned unencrypted passwords&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;... What a huge fuss aboput nothing PJ???? are your click and send, ebay and paypal passwords (if you use paypal to pay for click and send) being sent unencrypted to and fro on the internet?&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;The Op says yes, and it does not bother you??...&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;I do not think it is names and addresses of the person who bought the frilly red knickers is the "crux" of the security breach argument but rather the passwords.&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Nicola Roxon is on the right track with mandatory data breach reporting&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;http://theconversation.edu.au/youve-been-hacked-why-data-breach-reporting-should-be-mandatory-10220&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;an excerpt&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Entitled “Australian Privacy Breach Notification”, the discussion paper asks whether companies and other organisations should be required to report any breaches that occur to personal data they are storing.&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Only a day after Ms Roxon released the discussion paper we saw a great example of why mandatory data-breach notification is required.&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&lt;A href="http://www.ag.gov.au/Consultationsreformsandreviews/Pages/Australian-Privacy-Breach-Notification.aspx"&gt;On Thursday Australia Post &lt;/A&gt;&lt;A href="http://www.news.com.au/business/companies/australia-post-in-online-privacy-breach/story-fnda1bsz-1226498834454?sv=1684ecf6a51b387578fce1b3187fa84c&amp;amp;buffer_share=5b32d&amp;amp;utm_source=buffer"&gt;shut down its electronic parcel tracking service after a computer malfunction exposed the personal details of thousands of customers who were sent parcels. Mandatory data-breach reporting would have required Australia Post to tell customers of the breach immediately &lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: large;"&gt;&lt;A href="http://www.news.com.au/business/companies/australia-post-in-online-privacy-breach/story-fnda1bsz-1226498834454?sv=1684ecf6a51b387578fce1b3187fa84c&amp;amp;buffer_share=5b32d&amp;amp;utm_source=buffer"&gt; rather than having the message delivered through the media the following day&lt;/A&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&lt;A href="http://www.news.com.au/business/companies/australia-post-in-online-privacy-breach/story-fnda1bsz-1226498834454?sv=1684ecf6a51b387578fce1b3187fa84c&amp;amp;buffer_share=5b32d&amp;amp;utm_source=buffer"&gt;Of course, Australia Post is not alone – many large Australian companies and organisations – including &lt;/A&gt;&lt;A href="http://www.smh.com.au/it-pro/security-it/telstras-734000-account-privacy-blunder-breached-multiple-laws-regulators-20120629-2165z.html"&gt;Telstra, &lt;/A&gt;&lt;A href="http://www.abc.net.au/news/2012-03-05/defence-under-investigation-over-privacy-breach/3870002"&gt;Defence and &lt;/A&gt;&lt;A href="http://www.smh.com.au/technology/security/paternity-and-drug-test-details-leak-online-in-privacy-breach-20110718-1hkyn.html"&gt;Medvet – have suffered data breaches in the recent past.&lt;/A&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;What Ms Roxon didn’t say was the majority of companies don’t seem to take customer privacy very seriously.&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Currently, if an Australia company suffers a data or security breach, they are&lt;STRONG&gt;&lt;SPAN style="font-size: large;"&gt; &lt;A href="http://www.oaic.gov.au/publications/guidelines/privacy_guidance/data_breach_notification_guide_april2012.html"&gt;encouraged (but not required) to disclose the details to the Privacy Commissioner.&lt;/A&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 18:34:33 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27095#M4488</guid>
      <dc:creator>viewmont1071</dc:creator>
      <dc:date>2012-10-19T18:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27105#M4489</link>
      <description>&lt;P class="mce-p"&gt;&lt;EM&gt;I suspect AP found the problem themselves and then announced it and said their would be disruptions to the service while they did so.&lt;/EM&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Customer Trevor Ryan, a former mail contractor, tried to alert Australia Post to the problem yesterday but was told to &lt;STRONG&gt;put his complaint in writing.&lt;/STRONG&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;An Australia Post spokeswoman yesterday apologised for the "inconvenience" of suspending the parcel-tracking service&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&lt;STRONG&gt;- but not for exposing private information&lt;/STRONG&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;because.....obviously.... unless they are forced to give a rat's about their customers privacy then they will not but would prefer the PJ style of action&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;.... ie "quick under the carpet with all that dirt, bloody whingers...nothing going on here, move along move along"&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 18:41:07 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27105#M4489</guid>
      <dc:creator>viewmont1071</dc:creator>
      <dc:date>2012-10-19T18:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Australia Post/Click and Send Online Security Breach</title>
      <link>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27109#M4490</link>
      <description>&lt;P class="mce-p"&gt;So AFAIK from the stories a breach occurred on the 4th and a breach occurred again on the 18th at least and possibly the whole period in between those dates...is that current or "old news"&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;Given APs seemingly total lack of responsibility and the fact that they do not have to tell customers of security breaches coupled to the fact that disclosures of breaches would deter some customers from using the system&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;ie. not good advertising for the online system&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt;.;..who thinks there may be more????&lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;&lt;BR /&gt;
&lt;P class="mce-p"&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2012 19:30:55 GMT</pubDate>
      <guid>https://community.ebay.com.au/t5/Selling/Australia-Post-Click-and-Send-Online-Security-Breach/m-p/27109#M4490</guid>
      <dc:creator>viewmont1071</dc:creator>
      <dc:date>2012-10-19T19:30:55Z</dc:date>
    </item>
  </channel>
</rss>

