Skip to content

Instantly share code, notes, and snippets.

@cjheath
Created November 10, 2015 23:34
Show Gist options
  • Save cjheath/ca01a2a03ec0f3a5176f to your computer and use it in GitHub Desktop.
Save cjheath/ca01a2a03ec0f3a5176f to your computer and use it in GitHub Desktop.
Dear Mygov,
Your web-based single sign-on solution is riddled with obvious bugs,
and is clearly built by incompetent staff and paid for by people
who DO NOT CARE about that. I've been in the software industry for
35 years and I have never seen such an important service so
comprehensively fouled up.
The first and most obvious thing is just a niggle: whenever I
re-visit the www.mygov.gov.au home page, I'm greeted by "Sorry,
your secure session with myGov has timed out. Please sign in again.
(RFM38)". This destroys confidence, since the last time I visited
may have been months ago. I expected to have to sign in again, and
I expect no indication that I was previously signed in to a session
that has expired.
When I do sign in, I get hassled EVERY TIME to provide my phone
number. Sorry, but you are so incompetent at software that I'm not
going to provide anything that's not mandatory. So where is the
"Don't show me this again" button? Nowhere to be seen. "Oh but
this is important"? I hear you say. Give me some reason for confidence,
and I'll consider giving you my data.
When trying to traverse to the ATO site to download a message, I
again get a cookie-related failure: "A951.30 - Session terminated
Sorry, your session with the Australian Taxation Office (ATO) has
been terminated." Well duh - I might have previously had a session
(weeks or months ago), but now I have a new one, one that DOESN"T
WORK. The ONLY WAY to retrieve this letter is to go into the web
browser (Google Chrome) settings and delete all cookies from
*.ato.gov.au. Happily *I* know how to do that, but what about the
average nuff-nuff? They're left knowing that there is important
correspondence that they simply can't access.
EVERY SINGLE USER of your system is being hit by these blatant bugs.
Your system has clearly not been tested, yet its whole purpose is
undermined by the lack of trust these problems create.
Yet no-one seems to have the power or the will to fix them.
It's just not good enough. If there was an alternative supplier of
government services, you'd be devoid of customers and bankrupt.
Just consider that for a minute, and then ask yourself what you'd
have to do to deliver the Australian taxpayer (your employer!) value
for money.
@dynamicdan
Copy link

And the mobile security code doesn't support international users/travellers. They should use some standard 2 factor authenticator app and not be dependent on an Australian mobile number.

@wefalltomorrow
Copy link

Still applicable sadly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment