Welcome Guest ( Log In | Register )

3 Pages  1 2 3 >Bottom

Outline · [ Standard ] · Linear+

Prepaid Cards BigPay - Prepaid MasterCard (with Mobile Apps) V2, CashBack, BigPoint & Remittance

views
     
honsiong
post Aug 5 2020, 08:17 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
ONGOING BIGPAY PHISHING ATTACK!

I just received a whatsapp call from fake bigpay.

user posted image

Asking for SMS TAC.

However the SMS received looks different.

This is how legit one looks like:

user posted image

And these are the ones that just came in:

user posted image

After I froze the card in app, I gotten a fund request and the fella quickly cancelled it:

user posted image

--

Edit: I think they don't know my PAN and full name. The app login is 1 factor authentication because no password required, to be frank, BigPay is sibjected to simjacking which is crazy widespread in US.

They can just poll random phone numbers in app, if there is a name returned, they phone them up.



This post has been edited by honsiong: Aug 5 2020, 08:37 PM
honsiong
post Aug 5 2020, 09:05 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(!@#$%^ @ Aug 5 2020, 08:58 PM)
yikes, better block these numbers
*
Before that, REPORT the number.
honsiong
post Nov 8 2020, 09:51 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
I wrote a blog post - Why BigPay is not that safe
honsiong
post Nov 12 2020, 10:57 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(!@#$%^ @ Nov 12 2020, 09:49 PM)
what can they do?
*
Implement 2FA like all other banks. BigPay is the only one with only 1 factor of authentication out there.

Asking for password will seriously thwart scammers because it's more intuitive to most people so they don't give away their passwords easily.

I explained further in https://anonoz.github.io/security/2020/11/0...y-security.html
honsiong
post Nov 12 2020, 11:27 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(!@#$%^ @ Nov 12 2020, 11:23 PM)
maybe in the future. so far i don't think any e-wallet or even banking apps in Malaysia have 2FA
*
False.

- UOB Mighty app is 2FA everytime we login
- Maybank apps will do SMS TAC when we do outgoing transaction in app.
- GrabPay will do both SMS TAC + user's PIN before authorising transactions.

Only BigPay needs only 1FA to do outgoing transaction, I confirm this.
honsiong
post Nov 12 2020, 11:49 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(!@#$%^ @ Nov 12 2020, 11:34 PM)
owh, that's normal security. SMS TAC to sign into BP. i thought u talking about using authenticators.
*
Both timed one time password and SMS one time password fall under "what you own" factor.

Read more: https://en.wikipedia.org/wiki/Multi-factor_authentication

No seriously, BigPay's 1FA is kinda silly. They trust telco too much.
honsiong
post Nov 13 2020, 12:08 AM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(!@#$%^ @ Nov 12 2020, 11:57 PM)
i see.

but login into new phone need SMS - 1F
then transfer money need fingerprint or passcode - 1F

like this not considered 2F?
*
Read my blog post, you can change the passcode by simply type in your NRIC.

NRIC and SMS TOTP both fall under "what you own", say if someone steals or snatches your purse, and your SMS can be read without unlocking the phone, your BigPay account is completely gone.

You can argue normal credit cards are less safe, but BigPay is positioning themselves as challenger bank and have applied for license with BNM iirc.

This post has been edited by honsiong: Nov 13 2020, 12:09 AM
honsiong
post Nov 13 2020, 11:25 AM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(COOLPINK @ Nov 13 2020, 11:21 AM)
they can come up even with 3FA or more but the fact is as long as gullible/greedy/desperate people are still giving away all their security information to the scammers no amount of security feature can save them.
*
It’s easy to say that to defend the designers in BigPay.

But if BigPay is targeted significantly more than other banks, maybe there is something to think about.
honsiong
post Nov 13 2020, 12:45 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL


QUOTE(COOLPINK @ Nov 13 2020, 11:38 AM)
im not defending anyone just stating the facts. financial institutes are always trying to improve their security features to protect their customers but even they have admit they cant protect customers from themselves.

well you could be right that Bigpay is targeted more significantly recently than other banks which would indicate that customers database have been compromised. it is highly suspicious that they could get so many customers data so suddenly.

anyway to everyone here always remember DO NOT GIVE OUT ANY INFORMATION OVER THE PHONE not even your home address.
*
Saying their customer db has been compromised is a serious allegation. Thing is probably as simple as this guy below said.

QUOTE(!@#$%^ @ Nov 13 2020, 11:32 AM)
my guess is because of login via phone number and tells scammer whether someone is really using bigpay or not.
*
Correct, it's pretty easy to tell if someone has a BigPay account. Or you can brute force import phone numbers onto a phone and see who show up as friends in the Payment tab.

BigPay is targeted hard specifically because of their 1FA design. And tech illiterate people are probably only think about safeguarding their passwords and not other personal identifiable information.
honsiong
post Nov 13 2020, 01:36 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(COOLPINK @ Nov 13 2020, 01:35 PM)
yes can import phone number to your contacts and see whose numbers turn up.
but the thing is the scammers know your full name and certain information that you cant get that through import phone number.
there is more going on here than meets the eye.
*
CAN. Use DuitNow reverse NRIC/phone number to name lookup, or whatsapp/telegram name.

They always call thru whatsapp anyway.
honsiong
post Nov 14 2020, 08:52 AM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(andrekua2 @ Nov 14 2020, 07:29 AM)
AA want to become Malaysia's Ant?
*
Ant has 50% stake in touchngo digital iirc.

I think AirAsia just wants to offer full stack services for migrant community here. They will use AirAsia to fly to and from their home country, use BigPay to remit their income home, use TuneTalk IDD to call home etc.
honsiong
post Feb 3 2021, 09:39 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(GrumpyNooby @ Feb 3 2021, 05:41 PM)
Good sharing:

With BigPay’s entry into the DuitNow ecosystem operated by Payments Network Malaysia (PayNet), BigPay users will soon be able to use DuitNow for instant domestic money transfers, and pay at merchants with the DuitNow QR function, Malaysia’s national QR code standard for payments at local merchants.

But CC top up limited to RM 1k, not much hype with BigPay.
*
K bigpay is really becoming a normal bank app.
honsiong
post Feb 3 2021, 09:54 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(GrumpyNooby @ Feb 3 2021, 09:40 PM)
But they won't award you any interest for the wallet balance kept with them. whistling.gif
*
Eh they give us 0% foreign exchange rate very good already, I will take that over saving interest rate. Forex can save 3%+ vs other cards.
honsiong
post Apr 3 2022, 07:54 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
Bigpay charges 0.6% forex spread, same as Wise now.
honsiong
post Apr 3 2022, 08:00 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(adam1190 @ Apr 3 2022, 07:57 PM)
Last time bigpay don't charge forex spread?
*
Thats what I used to know, but now I read their website, they have changed their tone recently.

honsiong
post Apr 3 2022, 08:07 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
https://web.archive.org/web/20200511170548/...w.bigpayme.com/

May 2020:
- BEST CURRENCY EXCHANGE RATE
Banks charge you a mark-up fee on top of the currency
exchange rate. We don’t. That’s more money for you.

https://web.archive.org/web/20220223193835/...w.bigpayme.com/

2022:
- the BigPay card gives you real exchange rates, anywhere in the world.

It's a slight change in language lah, but bigpay is still much better than typical cards when paying non-MYR stuff
honsiong
post Apr 3 2022, 09:43 PM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(Ramjade @ Apr 3 2022, 08:34 PM)
Care to share the source about the 0.6% Forex spread?
This is bad news.
*
I sendiri compare against XE app. Again, it's possible BigPay isn't using XE rate, so I probably should have checked against Visa's rates.

user posted image

Edit: OK so Visa has 0.33% markup over spot rate. I just checked XE and Visa website at the same time:

- XE.com spot rate 4.6509
- Visa exchange rate 4.6688

This is Bigpay's FAQ:

QUOTE
We use the exchange rate from Visa / Mastercard, and additional charges are made from these two networks. Your financial goals matter, and we make sure our rates are fair to help you make the most out of your money


"Additional charges from these two networks" is the key -- they still give the best rates among Malaysian debit cards, but it's no longer using spot rates like before covid.

This post has been edited by honsiong: Apr 3 2022, 09:51 PM
honsiong
post Apr 4 2022, 07:26 AM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(Kadaj @ Apr 3 2022, 11:35 PM)
So is it better to use Wise or Bigpay if I travel oversea?
*
Why not both? I think bigpay still has advantage in ATM withdrawals. But its safe to keep both at hand, just in case you lose one of them.
honsiong
post Aug 9 2022, 03:14 AM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(biertrinker @ Aug 9 2022, 01:22 AM)
Do you still use the virtual credit card if you have the physical credit card already?
*
The virtual card is meant for card-not-present transactions, aka online purchases.

If you never use the card offline, freeze your physical card for max protection.

QUOTE(waisang @ Aug 9 2022, 02:12 AM)
Is it still worth to use Bigpay while travel abroad? You may have to pay 1% fee  for top up RM1k above, compared to the bank credit card international charges, any saving on this card?

How is it if you compare with Wise card?
*
You can DuitNow $ from your saving account into BigPay to not pay the 1% charge. Maybank doesn't support it, get a UOB Malaysia account please.

I don't have Wise Malaysia card so I can't tell much, but Wise Singapore card limits usage to S$ 30000 per year (only ~ RM 8000/mo) which is insufficient for my spending as a digital nomad. So I have to use Bigpay which has no spending limit.


honsiong
post Aug 9 2022, 10:35 AM

Look at all my stars!!
*******
Senior Member
3,182 posts

Joined: Nov 2008
From: KL
QUOTE(touristking @ Aug 9 2022, 07:39 AM)
I used my BP a few months ago in Europe. Contactless transaction often fail for unknown reason. It got so bad that I gave up using BP and just stick to normal credit card. You have that problem?
*
Yes, failed only in Netherlands. But for RFID txn I use Wise SG on Apple Pay mostly.

Currently in Mexico, half of the card readers here do not have RFID reader, Bigpay chip & sign works well here.

QUOTE(Ramjade @ Aug 9 2022, 08:29 AM)
Go apply for wise. Wise for Malaysian will come from sg.
*
I have Wise SG card... no we cannot have 2nd account from another country.

Wise MY card is different from SG card, the SG card is issued from UK bank but MY card is from US bank iirc. You can check their first 6 digits BIN.

SG card has Apple Pay which is very safe way to pay, I always disable the physical card.

This post has been edited by honsiong: Aug 9 2022, 10:37 AM

3 Pages  1 2 3 >Top
 

Change to:
| Lo-Fi Version
0.0610sec    0.50    7 queries    GZIP Disabled
Time is now: 11th December 2025 - 06:41 PM