Popular Posts
- Telstra Privacy Breach Caused By An Unsecured RightNow Webform Being Indexed By Google
- Telstra Media Release From Peter Jamieson - Executive Director Customer Service
- Telstra Internal Website Made Public, Releasing Account Details Of One Million Customers
- Telstra & BigPond Online Services Offline
- Telstra & BigPond Services Still Unavailable
- Does Telstra Need A Free Trial of BigPond Security?
Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts
Monday, 12 December 2011
Telstra - We Are Sorry We Let You Down This Weekend
As you're aware some of our online services were unavailable from late Friday 9th to late Saturday 10th December due to an earlier internal systems issue.
I want to sincerely apologise for any inconvenience you may have experienced this weekend because of the disruption.
Services are now back up again for the majority of our customers, and your BigPond services should be working as normal.
The decision to temporarily reduce access to these services was not taken lightly and I know that our actions resulted in a poor online experience for you and was a source of frustration.
So if you have any technical difficulties after logging into your BigPond email account please see our online help, visit us on CrowdSupport or just call us on 133 933. We’re here to help any time.
Once again, I apologise for the disruption to your service and thank you for your patience.
Best regards,
Peter Jamieson
Executive Director, Customer Service
Click here to see a copy of the email
Australian Privacy Commissioner To Investigate Telstra Again
The Privacy Commissioner has previously investigated breaches of the Privacy Act by Telstra, Google and Vodafone in 2011 and will once again shine the spot light on Telstra.
Google & Vodafone promised to improve their privacy practices and agreed to advise the Privacy Commissioner of their progress but Telstra is now back in the bad books with this most recent privacy breach.
As we have previously reported on Saturday Telstra issued blanket password resets to 60,000 customers whose passwords were published on the internet.
The passwords and email addresses were contained in customer notes recorded by Telstra staff members. Bank and credit card details were not included in the notes.
It has been reported that up to a million customers were exposed in the privacy breach. Telstra has promised to contact all the customers that were affected but said the process "will take some time".
AUSTRALIAN IT - Privacy czar investigates Telstra
Location:
Australia
Sunday, 11 December 2011
Saturday, 10 December 2011
Does Telstra Need A Free Trial of BigPond Security?
Telstra and BigPond customers wished that Telstra took their own advise and had some security on the Telstra Bundles RightNow web-based database that caused the privacy breach that was reported yesterday!
The database listed customers details including usernames and passwords (Screenshot below). 60,000 customers require their passwords to be changed. Unfortunately changing the passwords disconnects the customers from the Internet and requires them to contact Telstra to get the new password before they can get back online.
With so many customers affected the call wait times to contact BigPond technical support to get a new password are very lengthy. The password change is definitely warranted and I agree that Telstra has done the right thing in changing all affected customers passwords for their security, it is just a shame that security wasn't the original priority when the bundle database was open to anyone on the Internet.
Speculations from security experts and ex-Telstra employees indicate that this issue has been around for many years. Telstra first started using RightNow (the system responsible for the privacy breach) in 2006 and the lack of security was a known issue.
Telstra Privacy Breach Caused By An Unsecured RightNow Webform Being Indexed By Google
UPDATED 14 December 2011
Cached data from Google searches on the domain have now been removed and you are no longer able to view them. The site is still online but now has an IP filter so everyone outside of Telstra gets an error message (Screen shot below). Is this enough security now the domain is known?
Does Telstra Need A Free Trial of BigPond Security?
The privacy breach was first discovered by a Whirlpool forum user on 09/12/11. They performed a Google search and found a Telstra webpage used by staff to give customers information on their bundle orders.
The website address is: http://telstratccmail.custhelp.com/app/bundles_search/ the site has now been taken offline along with all other Telstra & BigPond online services.
The website domain custhelp.com redirects to RightNow.com an online service that offers major companies all over the world including Telstra self-service tools, knowledge bases, customer correspondence tools and webforms and databases.
RightNow is yet to make a public statement on the privacy breach. As the breach was on a RightNow server and not a Telstra one it would indicate that RightNow is at fault but this might not necessarily be true as they offer services for customers and staff. Telstra would have requested the service and selected if it was for internal or external use and should have tested the service before going live.
Telstra & BigPond Online Services Offline
Due to the Telstra Privacy Breach Telstra's Online Services are still Offline
BigPond's 'My BigPond' online service & Email still unavailable
Friday, 9 December 2011
Telstra Internal Website Made Public, Releasing Account Details Of One Million Customers
Telstra privacy breach caused by an unsecured RightNow webform being indexed by Google
Telstra has inadvertently exposed customer information to the web after one of its internal tools was indexed by Google and made public.
Read more at news.com.au & ZDNet.com.au
Telstra has inadvertently exposed customer information to the web after one of its internal tools was indexed by Google and made public.
Read more at news.com.au & ZDNet.com.au
Location:
Australia
Subscribe to:
Posts (Atom)

