on 02-10-2012 09:37 AM
Good Morning All,
As many of you are aware, our Click and Send website is currently down. We understand just how inconvenient this is for all of you and we are working with our provider to bring it back online as quickly as possible.
We thank you for your ongoing patience in the face of these issues and will let you know as soon as it is up and running again.
Alice
on 02-10-2012 01:16 PM
From an online article on news.com.au
"
A SECURITY flaw on Australia Post's website is putting customers' privacy at risk, with the company allegedly believing people were not smart enough to find the glitch.
The names and addresses of customers that use Australia Post's "Click & Send" service were being exposed by simply manipulating the website url.
The flaw could violate Australia's privacy code.
News Ltd was alerted to the problem by an Australia Post customer, Trent Bourne, a 23-year-old website administrator from Homebush, Sydney, who three times tried to alert the company about the problem.
"The first time they said `oh, our customers are not as smart as you so they will never find this glitch'," he said.
On the other two occasions Mr Bourne said his complaints were ignored.
The flaw is no longer accessible because Australia Post suspended the service after being contacted by News Ltd.
It had been found in the final stage of the Click & Send transaction. Once a user had logged into their account and created an item to send, they were required to print a label to stick on the parcel.
When that happened a pop-up window appeared containing the invoice transaction.
For a user's information to be exposed, all you needed to do was change the six digit shipping ID that could be found in the url that appeared along the top of the pop-up box to another random six digit number and hit enter. The page reloaded to reveal the name and address of another customer and the intended recipient of the parcel. Users needed only change one or two digits to access other customers' invoices.
The invoice also contained an article and reference number - which could be used to access credit card information stored within user accounts.
It was an easy process which News Ltd was able to replicate.
The glitch could not be used to target an individual, but provided a wealth of information through random searches.
Australia Post told News Ltd that the Click & Send service had "been temporarily suspended due to a system error".
"Customers who use the service have been notified via the online site," the spokesperson said.
"As a result, the site has been temporarily deactivated, as our team works to ensure the security of the system for all customers.
"We hope to have the service back up and running as soon as possible.
"Australia Post would like to reassure Click & Send customers that at no stage were their financial details compromised.
"Customers who wish to send parcels should visit their local Australia Post outlet who will assist them."
Australia Post said it had no record of Mr Bourne's complaint.
The Australian Information Commissioner has been contacted for comment."
on 02-10-2012 01:31 PM
termalert for regular parcels and express post to ensure that I have required paypal proof of post to addressee I just fill in the same lodgement slip as you would use for registered post parcels - (available at post office) I just add in regular parcel with tracking at top of form and hand it in with parcel to have verified and stamped by my Post Office.
on 02-10-2012 01:32 PM
Hi All,
I do understand your concerns and your wish to maintain your fantastic Customer Service levels, and I am sorry that this system outage is making that so difficult.
I wish I could give you more information and tell you exactly when the site will be back up, however I just don't have that information.
on 02-10-2012 01:33 PM
Hi All,
I do understand your concerns and your wish to maintain your fantastic Customer Service levels, and I am sorry that this system outage is making that so difficult.
I wish I could give you more information and tell you exactly when the site will be back up, however I just don't have that information.
Not sure what happened there, the rest of the post said:
I recognise that having to pay more for postage if you chose to post over the counter will have a major impact on your bottom lines, and I hope that things get back onboard before that becomes a necessity for you.
Alice
on 02-10-2012 01:53 PM
Thank you for the update Alice. I will let me customers know that their parcels will not be sent out today due to AP problems. It is annoying but we will all just have to handle it
on 02-10-2012 01:54 PM
Make that MY customers 😄
on 02-10-2012 02:06 PM
Good one cat.
I was trying to find the place to add the info you mentioned but I only have some old Mullti Forms on hand.
Thanks heaps for the tip though. Might be pushing it at my
local PO coz the franchisee is a bit greedy and will try to flog me
Reg Post labels instead...lol
I still think that AP took the lowest quote for their software development.
on 02-10-2012 02:10 PM
woa! that news.com article is rather disturbing!
not feeling any reassurance there....fellow sellers, I suggest we all make alternate postal measures. I will be using my usual ebay satchels for packing, but just printing off a postage address label to put in the clear sleeve, then opting for the $1.55 tracking when paying for the postage at my LPO.
on 02-10-2012 02:27 PM
on 02-10-2012 02:35 PM
termalert I just draw in another box at the top myself 🙂
or for express post I cross out the platinum at the end
haven't had any problems at all with a post office yet, I just point out first time that I use at a different post office that I require confirmation of addressee details and post for my business records