POLi Payments
   HOME

TheInfoList



OR:

POLi Payments Pty Ltd (formerly known as Centricom) is an online payments company based in
Melbourne Melbourne ( ; Boonwurrung/Woiwurrung: ''Narrm'' or ''Naarm'') is the capital and most populous city of the Australian state of Victoria, and the second-most populous city in both Australia and Oceania. Its name generally refers to a met ...
, Australia. It is the developer and provider of POLi, an online payment system that is used by merchants and customers in Australia and
New Zealand New Zealand ( mi, Aotearoa ) is an island country in the southwestern Pacific Ocean. It consists of two main landmasses—the North Island () and the South Island ()—and over 700 smaller islands. It is the sixth-largest island count ...
. POLi Payments was acquired by SecurePay Holdings, a fully owned subsidiary of Australia Post, in December 2014. POLi enables customers to pay for goods or services directly from a merchant's website without the need for a credit card, but by using a direct connection to the user's internet banking. A benefit is that the merchant receives an instant receipt and that customers do not have to register to use POLi. The service is used in Australia and New Zealand with its largest merchants being
Jetstar Jetstar Airways Pty Ltd, operating as Jetstar, is an Australian low-cost airline (self-described as "value-based") headquartered in Melbourne. It is a wholly owned subsidiary of Qantas, created in response to the threat posed by airline Virgi ...
,
Virgin Australia Virgin Australia, the trading name of Virgin Australia Airlines Pty Ltd, is an Australian-based airline. It is the largest airline by fleet size to use the Virgin brand. It commenced services on 31 August 2000 as ''Virgin Blue'', with two ...
,
Air New Zealand Air New Zealand Limited () is the flag carrier airline of New Zealand. Based in Auckland, the airline operates scheduled passenger flights to 20 domestic and 30 international destinations in 18 countries, primarily around and within the Pacif ...
,
Sportsbet Sportsbet, is an online gambling company owned by Flutter Entertainment, primarily targeting the Australian market. Sportsbet is licensed as a corporate bookmaker in the Northern Territory under the ''Racing and Betting Act 1993'' (NT). Sportsb ...
and
Sportingbet Sportingbet is a British online gambling operator, owned by GVC Holdings plc. The company was listed on the London Stock Exchange and was a constituent of the FTSE SmallCap Index prior to its acquisition by GVC. History The company was found ...
. The service has attracted widespread criticism from banks and others. The service has also been implicated in enabling payments that could be used for illegal gambling.


History

POLi Version 3 was released in July 2012 and enabled payments on Macs and mobile devices; neither was possible on previous versions. The implementation logs into a user's online banking interface from an automated virtual machine using a user's provided bank credentials, in order to direct debit the purchase amount. Version 2 is a
.NET Framework The .NET Framework (pronounced as "''dot net"'') is a proprietary software framework developed by Microsoft that runs primarily on Microsoft Windows. It was the predominant implementation of the Common Language Infrastructure (CLI) until bein ...
ClickOnce ClickOnce is a component of Microsoft .NET Framework 2.0 and later, and supports deploying applications made with Windows Forms or Windows Presentation Foundation. It is similar to Java Web Start for the Java Platform or Zero Install for Linux. ...
application. This version is still operational in New Zealand Payments for several banks. This version to was built with security at the expense of user experience, as the process of downloading the .NET ClickOnce application is poor, and requires additional plugins for Firefox and Chrome. POLi Version 1 was an
ActiveX ActiveX is a deprecated software framework created by Microsoft that adapts its earlier Component Object Model (COM) and Object Linking and Embedding (OLE) technologies for content downloaded from a network, particularly from the World Wide We ...
control. This version was used by some, but never gained traction due to security concerns with ActiveX. This version is no longer operational. Greg Day, a security analyst at
McAfee McAfee Corp. ( ), formerly known as McAfee Associates, Inc. from 1987 to 1997 and 2004 to 2014, Network Associates Inc. from 1997 to 2004, and Intel Security Group from 2014 to 2017, is an American global computer security software company head ...
stated "Using ActiveX for online payments is the kind of thing that would make me run a mile. tis probably the most used route for hackers to get in ... and steal personal information.". Since 2008 the system has been operating on the .NET technology platform. This still gives rise to possible security breaches via downloading untrusted software, and the possible infiltration of malware.Forum at The Register
br />"they are installing an ActiveX control (shudder) whose only purpose is to make payments to arbitrary bank accounts when the user logs into their online banking. There is another name for software that does that. Internet Banking Trojan."
"What a fantastic way to phish"
"Not meaning to be paranoid, but how can I be sure that the merchant's website is anymore genuine, and the POLi script anymore trustworthy than the average phishing email?"
"Not only is this an opportunity to phish people's bank details, you don't get the payment protection of using a credit card either."
"Score out of 4: 1. MSIE only = fail, 2. Active X = fail, 3. Direct access to my bank acct = fail, 4. No CC protection = fail"


Security concerns

Although POLi Payments stresses that security is a high priority, concerns remain regarding exposing the user's banking credentials to POLi, and liability for fraudulent transactions. ASB Bank, one of New Zealand's largest banks, has responded to POLi with a release stating that POLi is "spoofing/mirroring" their on-line banking pages and capturing customer information, and "due to the serious security and fraud risks" recommending that their customers not use it. (Note appears on page under date heading of 19 Dec 2012) The release also claims that ASB has asked POLi to remove support for ASB customers from their service. POLi responded to the ASB advisory with an announcement, refuting the claims, and apparently reverting the version of the payment system. ANZ New Zealand, Bank of New Zealand, "Providing log in details to a third party presents very serious security risks and contradicts both the New Zealand Code of Banking Practice and our terms and conditions."
Kiwibank Kiwibank Limited is a New Zealand state-owned bank and financial services provider with approximately 4% of market share in terms of assets. Kiwibank is owned by the New Zealand Government and provides some of its banking services through i ...
,"We advise against using POLiPayments as it invalidates our internet banking guarantee & is not secure" Commonwealth Bank, "The Commonwealth Bank does not have any working agreement with POLi Payments, and, as such, the payment site is not endorsed or supported by the bank. The bank urges customers making online payments to do so via the bank's own NetBank site, which guarantees the customer's security," CBA told ZDNet.
Westpac Westpac Banking Corporation, known simply as Westpac, is an Australian multinational banking and financial services company headquartered at Westpac Place in Sydney, New South Wales. Established in 1817 as the Bank of New South Wales, ...
, Bank of Queensland, "We take your Internet Banking security very seriously and, for this reason, we do not support the use of 3rd party applications such as POLi." Bank Australia "Unfortunately POLi payments don’t meet our security standards." and Police Bank are also warning customers against using POLi. ANZ and Kiwibank have further advised that use of POLi invalidated the bank's online guarantee, potentially making the customer liable for any losses if their online banking account were to be compromised. POLi's terms and conditions note "We are not making any representation that we or POLi™ have the approval or, an affiliation with, or any licence from or agreement with your financial institution to operate or make POLi™ available for use by you." Unlike payments via credit cards, payments made via POLi cannot be reversed by the bank, nor are users protected under chargeback rules usually associated with major purchases undertaken using Credit or Debit Card payments. As a result, users may experience issues in seeking refunds or reimbursements for services not delivered, such as cancelled air flights or tickets. Forum at The Register
"the price seems to be the loss of any consumer protection"
Version 1 and 2 that used the
ActiveX ActiveX is a deprecated software framework created by Microsoft that adapts its earlier Component Object Model (COM) and Object Linking and Embedding (OLE) technologies for content downloaded from a network, particularly from the World Wide We ...
and .NET platforms have additional security concerns regarding the integrity of this software and compatibility with non-Windows platforms.


References


Further reading

*Baltazar, Michelle (2012)
"Just debit it: Centricom"
''Financial Standard''.


External links


Official website
{{Payment service providers Online companies of Australia Payment service providers Online financial services companies of Australia