iTnews

Westfield ditches SMS feature over privacy issues

By Allie Coyne on Feb 3, 2016 6:48AM
Westfield ditches SMS feature over privacy issues

Exclusive: Potential to track cars that aren't your own.

Westfield operator Scentre Group has removed the SMS notification feature of its ticketless parking service after being alerted to a potential privacy breach that could have allowed anyone to track someone else's vehicle.

Over the past few years Westfield has progressively rolled out ticketless parking to four of its 35 shopping centres around the country.

The service means vehicle license plates are scanned upon entry and exit by Park Assist technology, eschewing the need for a physical ticket.

The shopping centre operator also recently began offering a feature for users to receive free SMS notifications outlining the time they entered the car park and an alert when they approach their free parking limit.

The SMS service is currently available at the Miranda, Hurstville and Bondi Junction Westfield centres in NSW, and Doncaster in Victoria. Around 10 percent of carpark users at the centres have registered for the service.

To sign up, users need only enter a name, license plate number and mobile phone number.

But concerns were raised by privacy experts who noted there was no requirement for a user to prove the license plate number they enter is their own.

It meant an individual could enter any license plate number and receive notifications on when the vehicle enters a specific Westfield centre, providing its physical location.

Privacy experts said the feature was particularly concerning when considering the implications for domestic violence victims or those with an apprehended violence order.

Scentre Group has now decided to "temporarily suspend" the SMS reminder service after being notified of the privacy concerns by iTnews as part of responsible disclosure.

"While the rest of the [ticketless parking] system will continue to operate we made a decision that a risk, no matter how small, was more than we were comfortable with when it came to the privacy of our shoppers," a company spokesperson said.

"Privacy is a priority for us - as is the confidence of our shoppers - and if we don’t believe one of our systems measures up, we’ll continue to make adjustments until it does."

The company confirmed it had not undertaken a privacy impact assessment prior to releasing the service.

It said it was currently working through a number of options for the future of the SMS feature.

"Some of them are short to medium-term and some are more long-term, depending on the level of complexity – technical or otherwise," the spokesperson said.

"While we look forward to reinstating the service we’d like to be as sure as possible that the risk of any privacy breach is mitigated." 

Privacy problems

Principal analyst at Constellation Research Steve Wilson said the service had potentially breached the Australian Privacy Act.

"I should think that [using the service to get alerts] about the movement of a car from a car park's CCTV, without the driver agreeing or even knowing, would breach the Privacy Act," he said.

Whether the license plate was already in the public domain is "irrelevant" in the eyes of the Act, he said.

"One of the counter inuitive aspects of our Privacy Act is it doesn't contain the words "public" and "private". It is a data protection statute, which concerns itself with restraining the collection and use of any personal information, regardless of where it comes from."

Westfield's ticketless parking service made headlines in 2011 after similar privacy implications were raised with Bondi Westfield's "find my car" feature.

The company's mobile application was found to be leaking customers' license plate numbers on the public internet, allowing anyone with "rudimentary programming knowledge" to monitor when cars entered and exited the car park.

Scentre Group was using an unprotected API to power the search function of the app, meaning the information contained with in the app was accessible on the public internet.

Independent security expert Troy Hunt identified the issue in 2011, and today said he was surprised Scentre Group had not fully thought through the implications of the SMS alert feature given the company's experience five years ago.

"... but often organisations rush into rolling out systems as they focus on the potential upside without giving due consideration to the potential risks," he told iTnews.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
privacy security sms ticketless westfield

Partner Content

What is zero trust cybersecurity?
Partner Content What is zero trust cybersecurity?
New Intel NUCs advancing mini-PC possibilities for business
Partner Content New Intel NUCs advancing mini-PC possibilities for business
Putting cyber security basics in place
Partner Content Putting cyber security basics in place
Resetting cyber security for the new threat landscape
Partner Content Resetting cyber security for the new threat landscape

Sponsored Whitepapers

Is the technology refresh dead?
Is the technology refresh dead?
DevSecOps: A framework for digital innovation
DevSecOps: A framework for digital innovation
Encryption: Protect your most critical data
Encryption: Protect your most critical data
Overcoming data security challenges in a hybrid, multicloud world
Overcoming data security challenges in a hybrid, multicloud world
Move beyond passwords
Move beyond passwords

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • [Webinar] - Transformation versus compliance – a guide for CXOs
  • Masters of Microsoft Licensing
By Allie Coyne
Feb 3 2016
6:48AM
0 Comments

Related Articles

  • Civil groups want EU lawmakers to boost privacy rights in planned WhatsApp, Skype rules
  • Apple to start enforcing new app privacy notifications in coming weeks
  • OAIC asks govt to require de-identification in data sharing laws
  • Google draws US antitrust scrutiny over third-party cookies ban
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Aussie Broadband to white label its services

Aussie Broadband to white label its services

Aussie Broadband says some customers are switching providers to get high-speed NBN discounts

Aussie Broadband says some customers are switching providers to get high-speed NBN discounts

ATO loses its cyber security chief

ATO loses its cyber security chief

Swinburne University data breach exposes details of 5000 staff, students

Swinburne University data breach exposes details of 5000 staff, students

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.