Share to: share facebook share twitter share wa share telegram print page
Available for Advertising

POLi Payments

POLi Payments Pty Ltd
Company typePrivate company
IndustryOnline banking
Founded2006; 18 years ago (2006)
HeadquartersMelbourne, Australia
ProductsElectronic commerce
ParentAustralia Post
Websitewww.polipayments.com

POLi Payments Pty Ltd (formerly known as Centricom)[1] is an online payments company based in Melbourne, Australia. It is the developer and provider of POLi, an online payment system that is used by merchants and customers in Australia and New Zealand. POLi Payments was acquired by SecurePay Holdings, a fully owned subsidiary of Australia Post, in December 2014.[2]

POLi enables customers to pay for goods or services directly from a merchant's website without the need for a credit card, but by using a direct connection to the user's internet banking. A benefit is that the merchant receives an instant receipt and that customers do not have to register to use POLi.[3] The service is used in Australia and New Zealand with its largest merchants being Jetstar, Virgin Australia, Air New Zealand, Sportsbet and Sportingbet.

The service has attracted widespread criticism from banks[4][5][6][7][8][9][10][11] and others.[12] The service has also been implicated in enabling payments that could be used for illegal gambling.[13][14]

In 2023, Australia Post announced they would close the Australian arm of POLi Payments in September.[15]

History

POLi Version 3 was released in July 2012 and enabled payments on Macs and mobile devices; neither was possible on previous versions. The implementation logs into a user's online banking interface from an automated virtual machine using a user's provided bank credentials, in order to direct debit the purchase amount.[16][17]

Version 2 is a .NET Framework ClickOnce application. This version is still operational in New Zealand Payments for several banks. This version to was built with security at the expense of user experience, as the process of downloading the .NET ClickOnce application is poor, and requires additional plugins for Firefox[18] and Chrome.[19]

POLi Version 1 was an ActiveX control. This version was used by some, but never gained traction due to security concerns with ActiveX. This version is no longer operational. Greg Day, a security analyst at McAfee stated "Using ActiveX for online payments is the kind of thing that would make me run a mile. [It] is probably the most used route for hackers to get in ... and steal personal information.".[20][21] Since 2008 the system has been operating on the .NET technology platform. This still gives rise to possible security breaches via downloading untrusted software, and the possible infiltration of malware.[22]

In July 2023, Australia Post announced that the Australian arm of POLi Payments would close down at the end of September that year.[15]

Security concerns

Although POLi Payments stresses that security is a high priority,[23][24] concerns remain regarding exposing the user's banking credentials to POLi, and liability for fraudulent transactions.[25][26][27]

ASB Bank, one of New Zealand's largest banks, has responded to POLi with a release stating that POLi is "spoofing/mirroring" their on-line banking pages and capturing customer information, and "due to the serious security and fraud risks" recommending that their customers not use it.[28][29][30] The release also claims that ASB has asked POLi to remove support for ASB customers from their service. POLi responded to the ASB advisory with an announcement, refuting the claims,[31] and apparently reverting the version of the payment system.[28]

ANZ New Zealand,[4][32][33] Bank of New Zealand,[5] Kiwibank,[6] Commonwealth Bank,[7][34] Westpac,[8][35] Bank of Queensland,[10] Bank Australia[11][36] and Police Bank[9] are also warning customers against using POLi.

ANZ and Kiwibank have further advised that use of POLi invalidated the bank's online guarantee, potentially making the customer liable for any losses if their online banking account were to be compromised.[6] POLi's terms and conditions note "We are not making any representation that we or POLi™ have the approval or, an affiliation with, or any licence from or agreement with your financial institution to operate or make POLi™ available for use by you."[37]

Unlike payments via credit cards, payments made via POLi cannot be reversed by the bank, nor are users protected under chargeback rules usually associated with major purchases undertaken using Credit or Debit Card payments. As a result, users may experience issues in seeking refunds or reimbursements for services not delivered, such as cancelled air flights or tickets. [38][39]

Version 1 and 2 that used the ActiveX and .NET platforms have additional security concerns regarding the integrity of this software and compatibility with non-Windows platforms.[citation needed]

References

  1. ^ "Centricom Pty, Ltd.: Private Company Information - Businessweek". Bloomberg News. Retrieved 26 October 2016.
  2. ^ Bailey, Michael (2015). "Ahmed Fahour's letter to ecommerce startups: Australia Post will accelerate you". Archived from the original on 20 April 2017. Retrieved 27 October 2016.
  3. ^ "Buy - Pay with confidence from your internet banking". Retrieved 26 October 2016.
  4. ^ a b "Important information for ANZ Internet Banking customers using POLi to make payments online". Retrieved 19 December 2012.
  5. ^ a b "Important security update for BNZ customers using POLi to make online payments". Archived from the original on 7 March 2013. Retrieved 26 October 2016. "Providing log in details to a third party presents very serious security risks and contradicts both the New Zealand Code of Banking Practice and our terms and conditions."
  6. ^ a b c Kiwibank Limited. "Twitter: "We advise against using POLiPayments..."". Retrieved 19 October 2020."We advise against using POLiPayments as it invalidates our internet banking guarantee & is not secure"
  7. ^ a b Michael Lee. "NZ bank claims payment processor is capturing user details". ZDNet. Retrieved 25 February 2014. "The Commonwealth Bank does not have any working agreement with POLi Payments, and, as such, the payment site is not endorsed or supported by the bank. The bank urges customers making online payments to do so via the bank's own NetBank site, which guarantees the customer's security," CBA told ZDNet.
  8. ^ a b John Dunkerley. "Who's got your back when you're banking?". Retrieved 25 February 2014.
  9. ^ a b "POLi Not Recommended for Payments". Archived from the original on 18 September 2015. Retrieved 26 October 2016.
  10. ^ a b "Pay anyone and multi-payments". Retrieved 19 October 2020. "We take your Internet Banking security very seriously and, for this reason, we do not support the use of 3rd party applications such as POLi."
  11. ^ a b "Tweet from Bank Australia". Archived from the original on 24 December 2015. Retrieved 20 November 2018. "Unfortunately POLi payments don’t meet our security standards."
  12. ^ "POLi Payments: probably the worst idea for online payments, security-wise". 2015. Retrieved 19 October 2020.
  13. ^ "How Australia Post banks millions from offshore casinos - The New Daily". 14 April 2016. Retrieved 28 October 2016.
  14. ^ "Illegal Australian online casino faces investigation - The New Daily". 17 April 2016. Retrieved 28 October 2016.
  15. ^ a b Weber, Kate (13 July 2023). "Australia Post to close POLi Payments". Retrieved 4 August 2023.
  16. ^ "Anyone used POLi Payments ?". www.geekzone.co.nz. Retrieved 20 November 2018. Behind the scenes POLi is logging into your banking on a virtual machine hosted in AWS. Because of this, it is also very easy for banks to detect POLi and mark it in their fraud detection systems. From this point you've actually breaking the internet banking terms of conditions with most banks since you handed over your details to a third party.
  17. ^ "PB Tech Black Friday Sale - 16th November". www.geekzone.co.nz. Retrieved 20 November 2018.
  18. ^ "FFClickOnce". Retrieved 26 October 2016.
  19. ^ "Chrome Web Store - ClickOnce for Google Chrome™". Archived from the original on 30 January 2013. Retrieved 11 June 2013.
  20. ^ Hargrave, Sean (20 March 2008). "Experts cast a wary eye over new online payment systems". The Guardian. Retrieved 26 October 2016.
  21. ^ Symantec - example of a breach of an online payment system ActiveX control
  22. ^ Forum at The Register
    "they are installing an ActiveX control (shudder) whose only purpose is to make payments to arbitrary bank accounts when the user logs into their online banking. There is another name for software that does that. Internet Banking Trojan."
    "What a fantastic way to phish"
    "Not meaning to be paranoid, but how can I be sure that the merchant's website is anymore genuine, and the POLi script anymore trustworthy than the average phishing email?"
    "Not only is this an opportunity to phish people's bank details, you don't get the payment protection of using a credit card either."
    "Score out of 4: 1. MSIE only = fail, 2. Active X = fail, 3. Direct access to my bank acct = fail, 4. No CC protection = fail"
  23. ^ How POLi works "Simple and secure"
  24. ^ Rubens, Paul. "How Bug Bounty Programs Bring Big Savings and Better Security". Retrieved 28 October 2016.
  25. ^ POLi Terms and Conditions - Disclaimer and Indemnity "We will not be liable to you or any other party for any loss or damage, however caused (including through negligence), that you may directly or indirectly suffer in connection with your use of POLi™, including, without limitation, any loss or damage that arises as a result of your download or use of the third party software referred to above.", and
    "If You believe that there has been an unauthorised or mistaken transaction, You should contact your financial institution and endeavour to address the issue under the terms and conditions applicable to your internet banking facility."
  26. ^ Juha Saarinen, IT News (2012). "Banks concerned over POLi security". Retrieved 19 October 2020.
  27. ^ George Lekakis, The New Daily (2016). "Banks warn of increased risk of online fraud". Retrieved 19 October 2020.
  28. ^ a b "Important security information for ASB and Bank Direct customers making online payments using POLi". 2012. Archived from the original on 10 February 2013. Retrieved 26 October 2016. (Note appears on page under date heading of 19 Dec 2012)
  29. ^ ASB Bank (2012). "Important security information - online payments using POLi". Retrieved 25 February 2014.
  30. ^ ZDNet, Michael Lee (2012). "NZ bank claims payment processor is capturing user details". ZDNet. Retrieved 27 October 2016.
  31. ^ "POLi response to ASB Advisory" (PDF). Retrieved 19 December 2012.[dead link]
  32. ^ "A 'honeypot' for fraudsters, or a simple way to pay online?". 18 January 2019. Retrieved 19 October 2020." An ANZ staffer responded by saying, "to be super clear" ANZ do not support using Poli Pay and systems that involve logging in through a third party as it goes against the bank's terms and conditions. They also stated that If a customer had used this type of service "we recommend they change their password immediately".
  33. ^ "Buying online during Level 3? Banks warn against popular payment system". Retrieved 19 October 2020."The banks warn that using POLi can be a breach of their various terms and conditions, posing a serious security and fraud risk."
  34. ^ "Should I make a NetBank payment via POLi?".
  35. ^ Westpac Bank (2015). "Westpac Bank on Twitter". Retrieved 19 October 2020."POLI is not supported by the bank. If making online pymts, should do so via bank's own site which guarantees customer's security"
  36. ^ "Why am I unable to perform Poli payments using my Bank Australia Account?". Retrieved 19 October 2020.
  37. ^ "POLi(TM) Terms & Conditions". Retrieved 27 October 2016.
  38. ^ "POLi - How Transactions Work" (PDF). Archived from the original (PDF) on 23 March 2012. Retrieved 27 October 2016. page 6 (from the Merchant's perspective) "Unlike a credit card, once you receive a payment it can't be reversed by the bank."
  39. ^ Forum at The Register "the price seems to be the loss of any consumer protection"

Further reading

Read other articles:

Folk metalSubway to Sally pada tahun 2015Sumber aliran Heavy metal lagu daerah musik dunia folk rock Sumber kebudayaanAwal 1990-an, EropaBentuk turunan Metal viking pagan metal Subgenre Celtic metal medieval metal oriental metal Versi regional Norwegia Denmark Finlandia Britania Raya Islandia Jerman Irlandia Swedia Rusia Brasil Spain Topik lainnya Folk punk Metal latin pirate metal daftar grup musik folk metal Folk metal adalah genre perpaduan musik heavy metal dan musik rakyat tradisional ya...

F. W. MurnauLahirFriedrich Wilhelm PlumpePekerjaanSutradara filmTahun aktif1919—1931 Friedrich Wilhelm Murnau (28 Desember 1888 – 11 Maret 1931) adalah sutradara asal Jerman pada masa film bisu dan merupakan salah satu sutradara yang terkenal pada saat itu. Beberapa filmnya telah hilang meskipun sebagian besar masih ada. Salah satu karyanya yang paling dikenang adalah film Nosferatu tahun 1922 yang mengadaptasi novel Dracula karya Bram Stoker. Pengawasan otoritas Umum I...

For the Odakyu station, see Katase-Enoshima Station. For the Shōnan Monorail station, see Shōnan-Enoshima Station. Railway station in Fujisawa, Kanagawa Prefecture, Japan Enoshima Station江ノ島駅Enoshima Station building in September 2018General informationLocation1-4-7 Katase-Kaigan, Fujisawa-shi, Kanagawa-ken 251-0035JapanCoordinates35°18′40″N 139°29′15″E / 35.31111°N 139.48750°E / 35.31111; 139.48750Operated by Enoshima Electric RailwayLine(s) Enos...

List of Christoph Waltz awards and nominations Waltz at the 82nd Academy Awards in 2010 Award Wins Nominations Academy Awards 2 2 BAFTA Awards 2 2 Cannes Film Festival 1 1 Primetime Emmy Awards 0 1 Golden Globe Awards 2 3 Saturn Awards 0 2 The following is a list of awards and nominations received by Austrian-German actor Christoph Waltz. Major associations Academy Awards Year Category Nominated work Result 2010 Best Supporting Actor Inglourious Basterds Won 2013 Best Supporting Actor Django ...

Wappen des Army War College – Das Motto der Institution geht auf Horaz zurück: Prudens futuri temporis exitum caliginosa nocte premit deus. („Ein kluger Gott drängt den Ausgang künftiger Zeit in undurchsichtige Nacht.“) Das United States Army War College (USAWC) ist eine höhere Bildungseinrichtung der US Army. Das College befindet sich in Carlisle, Pennsylvania, auf dem historischen Gelände der Carlisle Barracks, einem Stützpunkt, dessen Geschichte bis in die 1770er Jahre zurückr...

Artikel ini membutuhkan rujukan tambahan agar kualitasnya dapat dipastikan. Mohon bantu kami mengembangkan artikel ini dengan cara menambahkan rujukan ke sumber tepercaya. Pernyataan tak bersumber bisa saja dipertentangkan dan dihapus.Cari sumber: Kamang Hilia, Kamang Magek, Agam – berita · surat kabar · buku · cendekiawan · JSTOR Kamang HilirNagariNegara IndonesiaProvinsiSumatera BaratKabupatenAgamKecamatanKamang MagekKodepos26153Kode Kemendagri1...

Uma molécula de água é um exemplo comum de uma molécula polar. As duas cargas parciais, negativa e positiva, estão representadas, respectivamente, pelas cores vermelhas e azuis. Polaridade, em Química, refere-se à moléculas que apresentam momento de dipolo elétrico, o qual é influenciado pela separação das cargas elétricas e também possuem contribuição de pares de elétrons isolados[1]. Moléculas polares interagem principalmente por forças intermoleculares como dipolos-dipol...

Heusden Deelgemeente in België Situering Gewest Vlaanderen Provincie Oost-Vlaanderen Gemeente Destelbergen Fusie 1977 Coördinaten 51° 2′ NB, 3° 48′ OL Algemeen Oppervlakte 14,13 km² Inwoners (1/1/2020) 8.669 (613 inw./km²) Overig Postcode 9070 Netnummer 09 NIS-code 44013(B) Oude NIS-code 44028 Detailkaart Locatie in Destelbergen Portaal    België Heusden is een dorp in de Belgische provincie Oost-Vlaanderen en een deelgemeente van Destelbergen, het was een zelfsta...

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (نوفمبر 2023) مايكل سيرفيراس   معلومات شخصية الميلاد 6 نوفمبر 1960 (63 سنة)  بيثيسدا  مواطنة الولايات المتحدة  الحياة العملية المدرسة الأم جامعة ييلأكاديمية فيلبس ...

Michel Navratil Jr.Lahir(1908-06-12)12 Juni 1908Nice, PrancisMeninggal30 Januari 2001(2001-01-30) (umur 92)Montpellier, PrancisOrang tuaMichel Navratil dan Marcelle Caretto Michel Marcel Navratil, Jr. (12 Juni 1908 – 30 Januari 2001) adalah salah satu korban selamat terakhir dari tenggelamnya kapal RMS Titanic pada tanggal 15 April 1912. Michel, bersama dengan saudaranya, Edmond Navratil (1910-1953), dikenal sebagai Yatim Titanic, karena merupakan hanya satu-satunya anak-...

Tigerair Australia IATA ICAO Kode panggil TT TGW GO CAT Didirikan2007Mulai beroperasi23 November 2007Pusat operasi Bandar Udara Melbourne Bandar Udara Sydney Armada11Tujuan8SloganGo Tiger AustraliaPerusahaan indukTiger Airways Holdings[1]Kantor pusatMelbourne, Victoria, AustraliaTokoh utama Andrew David (CEO). Situs webwww.tigerairways.com.au Tiger Airways Australia Pty Ltd, beroperasi sebagai Tigerair Australia adalah maskapai penerbangan bertarif rendah yang memulai penerbangan pada...

Artikel ini perlu diwikifikasi agar memenuhi standar kualitas Wikipedia. Anda dapat memberikan bantuan berupa penambahan pranala dalam, atau dengan merapikan tata letak dari artikel ini. Untuk keterangan lebih lanjut, klik [tampil] di bagian kanan. Mengganti markah HTML dengan markah wiki bila dimungkinkan. Tambahkan pranala wiki. Bila dirasa perlu, buatlah pautan ke artikel wiki lainnya dengan cara menambahkan [[ dan ]] pada kata yang bersangkutan (lihat WP:LINK untuk keterangan lebih lanjut...

Elisabeth und Albert Reich (1912) Unterschrift Albert Reich (* 14. Januar 1881 in Neumarkt in der Oberpfalz; † 12. April 1942 in München) war ein deutscher Maler, Grafiker, Zeichner und Illustrator. Inhaltsverzeichnis 1 Leben 1.1 Erster Weltkrieg und Nachkriegsjahre 1.2 Zeit des Nationalsozialismus 1.3 Tod 2 Ehrungen und Kritik 3 Bildbände und Illustrationen 3.1 Eigene Veröffentlichungen 3.2 Buchillustrationen 4 Literatur 5 Weblinks 6 Einzelnachweise Leben Albert Reich, Sohn eines Schuhm...

Balai Kebebasan Antar-KoreaBalai Kebeasan di sisi Korea Selatan dari perbatasan (bangunan di belakang kabin-kabin biru), dilihat dari Paviliun Phanmun di sisi Korea Utara dari perbatasanInformasi umumRampung9 Juli 1998 (dibangun ulang)Data teknisJumlah lantai4Nama KoreaHangul자유의집 Hanja自由의집 Alih AksaraJayuuijipMcCune–ReischauerChayuŭijip Balai Kebebasan Antar-Korea (Hangul: 자유의집; RR: Jayuuijip) adalah sebuah bangunan empat lantai yang terletak d...

Village in Maryland, United StatesHickory RidgeVillageCountryUnited StatesStateMarylandCityColumbiaEstablished1974[1]Named forHickory Ridge Plantation Villages of Columbia Hickory Ridge is one of the 10 villages in Columbia, Maryland, United States, located to the west of the Town Center with a 2014 population of 13,000 in 4,659 housing units.[2] The village overlays the former postal community of Elioak. It was first occupied in 1974.[3] Neighborhoods in the village a...

X-45 Boeing X-45A Role Unmanned Combat Air VehicleType of aircraft Manufacturer Boeing Integrated Defense Systems First flight 22 May 2002 Primary user United States Air Force Number built 2 Variants Phantom Ray Boeing X-46 The Boeing X-45 unmanned combat air vehicle is a concept demonstrator for a next generation of completely autonomous military aircraft, developed by Boeing's Phantom Works. Manufactured by Boeing Integrated Defense Systems, the X-45 was a part of DARPA's J-UCAS projec...

Presidential race in the Philippines 2016 Philippine presidential election ← 2010 May 9, 2016 2022 → Turnout80.69% 6.35%   Candidate Rodrigo Duterte Mar Roxas Party PDP–Laban Liberal Running mate Alan Peter Cayetano Leni Robredo Popular vote 16,601,997 9,978,175 Percentage 39.01% 23.45%   Candidate Grace Poe Jejomar Binay Party Independent UNA Running mate Francis Escudero Gregorio Honasan Popular vote 9,100,991 5,416,140 Percentage 21.39%...

2005 studio album by Chris Brown Chris BrownStudio album by Chris BrownReleasedNovember 29, 2005RecordedFebruary–May 2005GenreR&B[1]Length59:01Label CBE Jive Producer Chris Brown Tina Davis Mark Pitts Scott Storch Jermaine Dupri Bryan-Michael Cox WyldCard The Underdogs Dre & Vidal Shea Taylor Cool & Dre Sean Garrett Christopher Young Shannon Slam Lawrence Oak Felder Eddie Hustle LRoc Antonio Dixon Mike Winans Lance Bennett Chris Brown chronology Chris Brown(2005) Exc...

Artikel ini membutuhkan rujukan tambahan agar kualitasnya dapat dipastikan. Mohon bantu kami mengembangkan artikel ini dengan cara menambahkan rujukan ke sumber tepercaya. Pernyataan tak bersumber bisa saja dipertentangkan dan dihapus.Cari sumber: Hoegeng Iman Santoso – berita · surat kabar · buku · cendekiawan · JSTOR Hoegeng Iman SantosoKepala Kepolisian Negara Republik Indonesia ke-5Masa jabatan9 Mei 1968 – 2 Oktober 1971PresidenSoeka...

Moroccan tennis player Younes El Aynaoui يونس العيناويCountry (sports) MoroccoResidenceRabat, MoroccoBorn (1971-09-12) 12 September 1971 (age 52)Rabat, MoroccoHeight1.93 m (6 ft 4 in)Turned pro1990Retired2017PlaysRight-handed (two-handed backhand)Prize money$4,044,667SinglesCareer record265–227Career titles5Highest rankingNo. 14 (11 March 2003)Grand Slam singles resultsAustralian OpenQF (2000, 2003)French Open4R (1995, ...

Kembali kehalaman sebelumnya