Click and Send Down (Sorry)

Good Morning All,

As many of you are aware, our Click and Send website is currently down. We understand just how inconvenient this is for all of you and we are working with our provider to bring it back online as quickly as possible. 

We thank you for your ongoing patience in the face of these issues and will let you know as soon as it is up and running again.

Alice

Message 1 of 77
Latest reply
76 REPLIES 76

Click and Send Down (Sorry)

From an online article on news.com.au


 


"


A SECURITY flaw on Australia Post's website is putting customers' privacy at risk, with the company allegedly believing people were not smart enough to find the glitch.


The names and addresses of customers that use Australia Post's "Click & Send" service were being exposed by simply manipulating the website url.


The flaw could violate Australia's privacy code.


News Ltd was alerted to the problem by an Australia Post customer, Trent Bourne, a 23-year-old website administrator from Homebush, Sydney, who three times tried to alert the company about the problem.


"The first time they said `oh, our customers are not as smart as you so they will never find this glitch'," he said.


On the other two occasions Mr Bourne said his complaints were ignored.


The flaw is no longer accessible because Australia Post suspended the service after being contacted by News Ltd.


It had been found in the final stage of the Click & Send transaction. Once a user had logged into their account and created an item to send, they were required to print a label to stick on the parcel.


When that happened a pop-up window appeared containing the invoice transaction.


For a user's information to be exposed, all you needed to do was change the six digit shipping ID that could be found in the url that appeared along the top of the pop-up box to another random six digit number and hit enter. The page reloaded to reveal the name and address of another customer and the intended recipient of the parcel. Users needed only change one or two digits to access other customers' invoices.


The invoice also contained an article and reference number - which could be used to access credit card information stored within user accounts.


It was an easy process which News Ltd was able to replicate.


The glitch could not be used to target an individual, but provided a wealth of information through random searches.


Australia Post told News Ltd that the Click & Send service had "been temporarily suspended due to a system error".


"Customers who use the service have been notified via the online site," the spokesperson said.


"As a result, the site has been temporarily deactivated, as our team works to ensure the security of the system for all customers.


"We hope to have the service back up and running as soon as possible.


"Australia Post would like to reassure Click & Send customers that at no stage were their financial details compromised.


"Customers who wish to send parcels should visit their local Australia Post outlet who will assist them."


Australia Post said it had no record of Mr Bourne's complaint.


The Australian Information Commissioner has been contacted for comment."

Message 21 of 77
Latest reply

Click and Send Down (Sorry)

termalert


termalert for regular parcels and express post to ensure that I have required paypal proof of post to addressee I just fill in the same lodgement slip as you would use for registered post parcels - (available at post office) I just add in regular parcel with tracking at top of form and hand it in with parcel to have verified and stamped by my Post Office.



Message 22 of 77
Latest reply

Click and Send Down (Sorry)

Hi All,

I do understand your concerns and your wish to maintain your fantastic Customer Service levels, and I am sorry that this system outage is making that so difficult.

I wish I could give you more information and tell you exactly when the site will be back up, however I just don't have that information.


Message 23 of 77
Latest reply

Click and Send Down (Sorry)


Hi All,

I do understand your concerns and your wish to maintain your fantastic Customer Service levels, and I am sorry that this system outage is making that so difficult.

I wish I could give you more information and tell you exactly when the site will be back up, however I just don't have that information.




Not sure what happened there, the rest of the post said:



I recognise that having to pay more for postage if you chose to post over the counter will have a major impact on your bottom lines, and I hope that things get back onboard before that becomes a necessity for you.

Alice


Message 24 of 77
Latest reply

Click and Send Down (Sorry)

Thank you for the update Alice. I will let me customers know that their parcels will not be sent out today due to AP problems. It is annoying but we will all just have to handle it

Message 25 of 77
Latest reply

Click and Send Down (Sorry)

Make that MY customers 😄

Message 26 of 77
Latest reply

Click and Send Down (Sorry)

Anonymous
Not applicable

Good one cat.


I was trying to find the place to add the info you mentioned but I only have some old Mullti Forms on hand.


Thanks heaps for the tip though. Might be pushing it at my


local PO coz the franchisee is a bit greedy and will try to flog me


Reg Post labels instead...lol


I still think that AP took the lowest quote for their software development.

Message 27 of 77
Latest reply

Click and Send Down (Sorry)

woa! that news.com article is rather disturbing!


not feeling any reassurance there....fellow sellers, I suggest we all make alternate postal measures. I will be using my usual ebay satchels for packing, but just printing off a postage address label to put in the clear sleeve, then opting for the $1.55 tracking when paying for the postage at my LPO.

Message 28 of 77
Latest reply

Click and Send Down (Sorry)

termalert I just draw in another box at the top myself 🙂



or for express post I cross out the platinum at the end



haven't had any problems at all with a post office yet, I just point out first time that I use at a different post office  that I require confirmation of addressee details and post for my business records






Message 30 of 77
Latest reply