Tuesday, 28 September 2010

CBA PayPas - the second response

Dear Mr Benschop,

I have again referred this matter to our Credit Card Product Team, the response is as follows:

Thank you for outlining your further concerns about the security of contactless payments, such as MasterCard PayPass. PayPass is a feature enjoyed by the majority of our customers due to the payment flexibility and convenience it provides PayPass has been designed to be as secure as other payment methods, such as magnetic stripe transactions. You will continue to be protected from liability on unauthorised transactions as long as you continue to adhere to the Conditions of Use.

We do not recommend any attempt at manipulation of your card plastic.

Regards

Commonwealth Bank
{redacted}
Customer Experience Consultant

Rapid Resolution Team

CBA Group Customer Relations
Group Sales & Service Support Team
Level 19, 150 George Street
Parramatta NSW 2150
P: 1800 805 605
F: 1800 028 542

Monday, 9 August 2010

CBA PayPas - my email to the bank

Dear {redacted},

{redacted}

In response to your email, you are correct that I am not happy with the response provided as it did not in any way address any of the concerns I raised on the phone with you and your colleague.

I'll state again, this time in writing, what the concerns are.

I am concerned about PayPass from a personal safety perspective. I'm concerned that you as a bank have created a personal security issue for me that I cannot remove or reduce. You did this without my permission and you provide no way for me as a consumer to opt-out, decrease my exposure or remove any such concerns.

You have advised me that PayPass allows for individual transactions of up to $100 per transaction. In addition you advised me, there is no limit on the number of transactions allowed. This means that in effect I am carrying in my wallet the total credit limit of my card in cash. This means that anyone observing that I have a PayPass card has the ability to gain access to those funds without my authorisation or participation.

The unlimited access to funds that the PayPass system represents provides ample incentive for the criminal element to become interested.

My concern is not the funds which you keep telling me are protected; my concern is my personal safety if force was used to obtain my card without my permission. If I need to spell it out, a thief could sit in a coffee shop and observe that I have a PayPass card. They can follow me out the door and take my wallet from me and have unlimited access to my funds. Common sense continues to prevent me from carrying large amounts of cash and I'm not prepared to start now.

In addition, the access need not even be forceful or physical as outlined above. Since PayPass uses RFID technology, access could be achieved using wireless access and a few dollars of equipment. 30 minutes on the Internet gave me several research papers and suggestions on how this might be achieved and examples were available showing access to such cards. I have found several scenarios which allow unfetted access to my card. With no limits on the card, there is ample incentive to develop solutions to circumvent any security measures. Just because Mastercard says that it cannot be hacked, doesn't make it so.

I've been in the IT industry for too long to believe that security through obscurity is sufficient and I expect better from my bank.


In addition the the above, I also asked you what the impact would be of disabling the RFID chip in my card, by inserting my card into a microwave or power drill.

I look forward to your response.


Kind regards,
Onno Benschop

Friday, 6 August 2010

CBA PayPas - the response

Dear Mr Benschop

Thank you for your call, which to this office 30 July 2010. In regards to the issues you have raised regarding the PayPass function on your credit card, I have requested review from the product area and they have provided a response as follows:

PayPass functionality is included with all CBA issued MasterCard credit and debit cards, and cannot be turned off. However if a customer would not like to use the technology, they can continue to sign/enter a PIN through the terminal, and can simply avoid tapping against PayPass readers.

PayPass is an extremely secure payment method, and is not more vulnerable to fraud than any other form of payment (such as signing for transactions).

Mr Benschop, I understand that you have already been provided with this response and that you will not be happy with this decision.

If you wish to discuss this matter further please contact me

Regards


Commonwealth Bank
{redacted}
Customer Experience Consultant

Rapid Resolution Team

CBA Group Customer Relations
Group Sales & Service Support Team
Level 19, 150 George Street
Parramatta NSW 2150
P: 1800 805 605
F: 1800 028 542

Friday, 30 July 2010

CBA PayPas

Today I found out that the Commonwealth Bank has a new "feature" called PayPass or Tap 'n Go. I'd recently seen it advertised on TV and wondered what the implementation was like.

The idea behind this technology is that you can make a transaction without needing to sign or enter your PIN when making a purchase. You just wave your card in front of a reader and the transaction is complete. There is no physical contact between your card and the reader - in fact you don't even need to take your card out of your wallet.

I learnt the following:
  1. The transaction limit is $100 per transaction.
  2. There is no limit to the number of transactions.
  3. You cannot set a limit.
  4. You cannot opt-out.
I contacted the bank customer service team via phone to confirm what I learnt. Initially there was some discussion about the $100 limit, but this was finally confirmed.

I asked the bank why I was unable to limit my exposure to this "feature" since I was concerned about my personal security as well as issues relating to RFID. The bank's response was: "You don't need to take your card with you, you can just leave it at home."

I asked to escalate the call and ended up speaking with a team leader in the Rapid Resolution Team who after some discussion began to understand my concerns and they created a case for me.

I've been promised a response in writing.

Thursday, 9 July 2009

VMware guest time sync under OSX

To sync time without needing VMware tools, you can run a cron job every minute that syncs with the OSX time daemon.

  1. Determine the IP address that OSX uses for the VMware network
  2. Add a cron job in the guest that runs

    ntpdate -s {ip address}
I'm running this in Ubuntu 8.10 under OSX 10.5.7 VMware Fusion 2.0.5.

Friday, 26 June 2009

A letter to VMware

In case there is any interest in improving your client interaction, my customer interaction with your company today:
  • I was advised by an Apple technician to update my 6 day old copy of VMware Fusion 2.0.4 - I'd installed the shipped copy 2.0 an hour earlier - to 2.0.5 because it would fix the issue I was having.
  • After agreeing to a licence, I downloaded 2.0.5 , which when I installed it, asked me to agree to yet another license. I've now agreed to the one for 2.0, the one to download 2.0.4, the one to install 2.0.4, the one to download 2.0.5, the one to install 2.0.5 - despite having to actually login to my profile before I can even begin the download - have your lawyers not got anything better to do?
  • The problem was not resolved, and since I had a spare 15 minutes, and despite several hours of research to resolve the issue over the weekend, I thought I'd phone support since I have 30 days support when I bought VMware Fusion. The website indicated that support was available in Australia from 7am to 7pm EST, so I launched the white pages, did a national search for VMware, found your Perth Office number and dialled it.
  • The telephone number in the electronic white pages shows a phone number for VMware in my local town of Perth, Western Australia. Only it is no longer connected.
  • The electronic white pages do not show the 1800 number for telephone support.
  • When I contacted the Sydney number, a long distance call, I asked to speak with technical support. I was provided with the 1800 number.
  • I dialled the 1800 number, chose technical support, workstation, fusion, and then got a message telling me that it was closed - even though your web-site tells me that it's open from 7am to 7pm EST (or Sydney time)
  • When I contacted the Sydney number again, I was put through to technical support where I spent 7 minutes on the phone with a lady who didn't speak much English and turned out to be in licensing support. All she could tell me was that I didn't own any copies of VMware - my bank disagrees.
  • When I contacted the Sydney number again, I was put through to licensing again, who put me through to technical support. The gentleman who answered was in Canada, but could not provide telephone support. He actually called me back on my phone so we could have a conversation on your dime, rather than mine. It transpired that your registration process had not registered my product. I was advised to speak with licensing support.
  • I tried to license my copy of VMware Fusion on the web - no success, not a valid serial number, despite the fact that the serial number was written on the CD sleeve and that it had happily been used by the application as a license key.
  • I dialled the 1800 number and chose licensing support. I spent 13 minutes discussing the merits of your web-form when finally the gentleman was able to license my copy of VMware Fusion. I wanted to ask about why my VMware workstation license wasn't visible, but the call had already ended.
  • I dialled the 1800 number in an attempt to speak with customer service, no such option.
  • I tried to license my copy of VMware Workstation on the web - no success, not a valid serial number, despite the fact that it was copied from an email you sent me.
  • I dialled the 1800 number and chose licensing support. I spent 15 minutes attempting to license my copy of VMware workstation. The gentleman advised me to contact the sales team "to swap the key".
  • I dialled the Sydney number, but they had gone home, despite that the web site says that it was open for another hour and a half.
  • I dialled the 1800 number and chose the sales team, where I got the global voice mail for VMware USA.
You can just imagine how much fun I was having. I then tried to lodge a support call on the web.
  • The web-form tells me that the maximum length for the description is 2000 characters, but when I pasted 1908 of them, it told me that there were too many.
  • The web-form has the ability to upload files, and even has sections describing what files are smart to upload, only OSX doesn't exist, nor does VMware Fusion.
So, all in all, I've now been at this since 14:16. It's now 16:35. Whom do I bill for the $355 dollars in time this has cost me, let alone the cost in phone calls, which I'm not looking forward to.

Wednesday, 20 May 2009

Out of the mouths of babes...

My 73 year old mother in law sent me some Australian Computer humour which I thought worthy of sharing around - not so much for the humour but for the fact that she was thinking of me with a twinkle in her eye at the time:

Australian Computer Terminology

LOG ON:Adding wood to make the barbie hotter.
LOG OFF:Not adding any more wood to the barbie.
MONITOR:Keeping an eye on the barbie.
DOWNLOAD:Getting the firewood off the Ute.
HARD DRIVE:Making the trip back home without any cold tinnies.
KEYBOARD:Where you hang the Ute keys.
WINDOW:What you shut when the weather's cold.
SCREEN:What you shut in the mozzie season.
BYTE:What mozzies do.
MEGABYTE:What Townsville mozzies do.
CHIP:A bar snack.
MICROCHIP:What's left in the bag after you've eaten the chips.
MODEM:What you did to the lawns.
LAPTOP:Where the cat sleeps.
SOFTWARE:Plastic knives & forks you get at Red Rooster.
HARDWARE:Stainless steel knives & forks - from K-Mart.
MOUSE:The small rodent that eats the grain in the shed.
MAINFRAME:What holds the shed up.
WEB:What spiders make.
WEBSITE:Usually in the shed or under the verandah.
SEARCH ENGINE:What you do when the Ute won't go.
CURSOR:What you say when the Ute won't go.
YAHOO:What you say when the Ute does go.
UPGRADE:A steep hill.
SERVER:The person at the pub who brings out the counter lunch.
MAIL SERVER:The bloke at the pub who brings out the counter lunch.
USER:The neighbour who keeps borrowing things.
NETWORK:What you do when you need to repair the fishing net.
INTERNET:Where you want the fish to go.
NETSCAPE:What the fish do when they discover the hole in the net.
ONLINE:Where you hang the washing.
OFFLINE:Where the washing ends up when the pegs aren't strong enough.