Delicious/delimiterau
- Early investors drop Facebook
- Victoria kills HealthSMART IT project
- Woz not great - mUmBRELLA
- Santos' thin client starts big-data plans
- Nokia Lumia 800 revs up at Bridgestone
- Telstra privacy breach was 'one little oops'
- 'Battleground of the future' the focus of new agreement with US
- The rise of the vendor management office
- NSW Government signs mega data centre deal
- NBN FUD: will Abbott ever learn?
News - Written by Brenton Currie on Wednesday, September 14, 2011 17:42 - 10 Comments
Westfield Australia ‘Find My Car’ privacy blunder uncovered
An embarrassing blunder has been discovered with Westfield’s ‘Find My Car’ feature announced in July, that allowed anyone to access images taken using its ParkAssist technology using a public API.
The issue, discovered by software architect and Microsoft MVP Troy Hunt, revolves around the application programming interface (API) that Westfield was using to power the license plate search for its Bondi complex, provided by ParkAssist.
The API gave Westfield the ability to provide a new feature in its iPhone application – downloaded more than 83,000 times — that allowed visitors to its Bondi complex find their car in the car park by simply typing in their license plate.
However as Hunt discovered using tools such as Fiddler, the API for the service wasn’t protected at all, potentially allowing anyone access to information provided by the service outside of the iPhone app.
“What this means is that anyone with some rudimentary programming knowledge can track the comings and goings of every single vehicle in one of the country’s busiest shopping centres,” Hunt wrote in a lengthy post detailing the vulnerability.
“Whilst I’m by no means a strong privacy advocate, something about this just doesn’t sit quite right with me.”
Images of the cars weren’t the only information available through the API — according to Hunt, it was also possible to gain access to the license plate in text and the time of arrival of a car in a parking space, or even the entire carpark.
Westfield said in a statement this afternoon that it had only been made aware of the authentication issue by provider ParkAssist this morning, and that it was working on a solution with the company, in the meantime disabling the car finding functionality.
“This issue has been addressed immediately by Park Assist and the Find My Car functionality will be not be available for approximately one week until the app has been modified to ensure that data cannot be publicly assessable online,” a spokesperson for the company said.
On the more broader topic of privacy concerns raised by the car finding functionality, Westfield says it doesn’t believe the app contravenes Australian privacy laws, with license plates not considered “personal information” under the act.
“The application theoretically could be used for purposes other than its original intention, however it does not facilitate any activity that couldn’t already happen otherwise,” the spokesperson said, before mentioning in extreme cases police may request access to the application to “assist in their enquiries”.
Westfield said it plans to introduce the Find My Car tool into “future” complexes in Australia, with visitors to existing Australian complexes able to mark their parking spots manually.
Image Credit: Westfield
Related posts:
- Google grilled in privacy enquiry
- Privacy Commissioner still won’t talk OzLog
- Google didn’t collect bank data: Privacy Commissioner
- CBA’s Kaching app raises privacy concerns
- VHA breached Privacy Act, says Commissioner
| Tweet | |
![]() |
10 Comments
Leave a Comment
Enterprise IT, News - May 21, 2012 13:32 - 15 Comments
The ABC didn’t sack Bitcoin miner
More In Enterprise IT
- Victoria dumps HealthSMART e-health project
- HP completes giant new NSW datacentre
- Microsoft beats Salesforce to utility CRM deal
- NSW finalises colossal datacentre consolidation
- Two good Australian CIO interviews
News, Telecommunications - May 21, 2012 10:48 - 5 Comments
iiNet ramps up Internode digestion
More In Telecommunications
- China concerned by Huawei NBN ban, says Bob Carr
- Parliament knocks back surveillance terms
- Evidence: Rural Australia is demanding the NBN
- Pristine Telstra network photos: We sourced our own
- NBN no CommBank or Qantas, says Hockey
Gadgets, News - May 21, 2012 12:32 - 5 Comments
Galaxy S III listed for Telstra, Optus and Vodafone
More In Gadgets
- Will Telstra skip Nokia’s Lumia 900?
- New BlackBerry OS 7.1 hits Australia
- ASUS Transformer Pad tablet hits Australia
- HTC One XL on sale: Compatible with Telstra 4G
- Optus a “disgusting” company, says AFL chief
Reviews - May 7, 2012 18:16 - 2 Comments
Telstra Mobile Wi-Fi 4G: Review
More In Reviews
- Samsung Galaxy S III: Preview
- HTC Titan II 4G: Preview
- Nokia Lumia 710: Review
- Sony Xperia S: Review
- Samsung Omnia W: Review








sponsored post ING Direct recently implemented a private cloud solution to virtualise its entire banking platform, allowing it to provision a new copy of itself -- a so-called 'bank in a box' -- within minutes. 
I wish this wasn’t announced. How am I supposed to stalk my ex now??
You still can, you just have to use the iPhone app to do it now, instead of your custom built API accessing program.
So much less convenient and so much less of a privacy issue using an iPhone app.
There is of course a simple solution to this problem, remember where you parked, seriously it’s not that difficult.
Unfortunately not, since it’s tracking your license plate whether you want it to or not… Of course, you could just not shop at Bondi Westfield (or come by public transport).
Well I’m on the Central Coast so won’t be shopping at Bondi anytime soon, and the only time we have any real trouble with parking is during tourist season
I think its a great idea. Although I do agree its not that hard to remember where you parked. That being said it was only a matter of time for something like this to happen.
Also, grum, you can still stalk your ex, just enter her number plate and see if she is in the shopping center and then wait by the car.
I don’t think Australian car parks are big enough to forget where you parked.
after just having returned from malaysia and parking in places such as the KLCC and Gurney plaza and queensbay mall, i would have to agree with you 100%.
place like that have multi level parking that can only be access from certain escalators or lifts and even then they have things like half levels. it can be a real task to locate your car.
australian parking lots are a piece of piss.
haha yeah the multi story carparks in Malayasia are evil