Outline ·
[ Standard ] ·
Linear+
Chat CIMB kena hack?
|
teehk_tee
|
Dec 17 2018, 02:19 AM
|
|
QUOTE(JimbeamofNRT @ Dec 17 2018, 02:18 AM) daily max now rm30K knn... meaning still need to go to branch tomorrow WHYYYYYYYYYYYYYYYYYYYYY LAHHH CIMB!!!  How to increase limit online?
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 02:22 AM
|
|
QUOTE(otakotak @ Dec 17 2018, 02:21 AM) remind me of 3des in ecb mode haha. any 8 chars + 12345678 can straight login?  so migrate old customer with 8 chars password to new field length. do some shitty re-hashing workaround by just + current pass with random 12345678 number so that their password can still works. i guess that captcha thing is to reduce bruteforce attempt? kek  if this is the case, just update your password will do la  Cant they void all the old passwords and force customers to update new pw upon login? Many brokerages do this. Not allow 8char + whatever shit to login.
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 02:25 AM
|
|
QUOTE(JimbeamofNRT @ Dec 17 2018, 02:22 AM) IIRC kana do at the cimb atm machine only. online cannot . meaning if you are at overseas... GGWP Aiseh.. Stress. Sleep first aih
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 02:34 AM
|
|
QUOTE(JustcallmeLarry @ Dec 17 2018, 02:32 AM) Guys a bit tired to read through the thread now. Can someone pls give me the TLTR version. Just want to know who is at risk & what to do if you been compromised??? Don't ask me to transfer money to other Banks bcs I have few loans with cimb... Ok short version, please change your pw asap.
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 11:07 AM
|
|
Just freeze all yr debit cards. Credit cards usefulness is can dispute payment.
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 11:21 AM
|
|
QUOTE(ahpoo @ Dec 17 2018, 11:15 AM) so actually safe? CIMB introduced new password and captcha system....maybe the ones that kena hack via paypal are the ones that their banking details already compromised through online shopping transactions..that why suddenly panicked and blame new cimb system.. if u found out that your account is so user friendly that it can be accessed via a multitude of passwords [Krimpai1] <-- normal 8 char [Krimpai19] <-- welcum sir [Krimpai123] <-- welcum sir [Krimpai1394] <---welcum sir how would you feel?
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 11:37 AM
|
|
QUOTE(briantwj @ Dec 17 2018, 11:35 AM) Does this mean even at 3 failed login attempt, it will use the captcha and not block the account?  Cimb didnt implement login failures (not sure after this event got or not) many other banks u log in failed 3 times = lock online banking need to go to ATM/call CS/visit branch to reset. This post has been edited by teehk_tee: Dec 17 2018, 11:41 AM
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 12:01 PM
|
|
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 12:46 PM
|
|
Their app just stuck loading now...
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 12:47 PM
|
|
QUOTE(unthuged @ Dec 17 2018, 12:43 PM) 4chan introduced capcha a few years ago, but CIMB doing it now? For what though? 4chan I understand to cut spam, but CIMB is bank login, if a bot tries different variations to log into a single account, transactions will be suspended, and you need to unblock the account for security reasons at branch or something kan? So which stupid shit in CIMB decided to introduce capcha?  IT manager ingat ini wordpress site kot, implement captcha to slow down bot comments lel
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 01:03 PM
|
|
QUOTE(se7en @ Dec 17 2018, 12:55 PM) will just leave this here for now  Picture says a thousand words LUL
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 01:16 PM
|
|
QUOTE(puchongite @ Dec 17 2018, 01:07 PM) So why problem ? Their back end only take 8 characters mah .... Yr ic dun need the 12 digits lah. Only first 8 will do
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 01:26 PM
|
|
QUOTE(Duckies @ Dec 17 2018, 01:19 PM) This is because when they changed the password policy to include special characters, they didn't force everyone to change their password. Therefore they have to cater logic for old password logic and also new password logic. But to implement it in this half ass way is plain stupid. This is not some wordpress blog yo. This is a fucking bank. #programmingtalk Loled cuz my wordpress also implement captcha. Now somebody cv can proudly boast, implemented industry leading security login system for leading bank in country. Captcha on a bank login screen fukken lul
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 01:32 PM
|
|
QUOTE(khainiz94 @ Dec 17 2018, 01:30 PM) Maybe they should have implemented the failed login limits. For security purposes. Heck even my Bank Rakyat online account have that 5 times limit. Once exceeded limits, my online banking will be blocked and need to call bank to unblock. Bank Rakyat yo. A small bank only. Bank rakyat.. Not even a bank under pidm yoh... Security higher than leading bank
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 01:38 PM
|
|
QUOTE(Mummy Shark @ Dec 17 2018, 01:32 PM) honestly, nothing wrong with CAPTCHA on any screen. the core behind CAPTCHA is to reduce automated entry by machine. it is not possible to eliminate altogether in probability, but the bar is higher than nothing at all. even if you only manage to eliminate 50% of automated attacks, that itself is a reduction. look beyond the CAPTCHA and stop complaining about it being on any screen. instead, question what the screen does to further eliminate threats not yet filtered by CAPTCHA. Yes. But its a bandaid on an accident victim. If u deny requests at server side, it doesnt warrant a captcha. A captcha simply says, i cant stop u from multiple entries but im sure as hell gonna try to slow u down.
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 02:33 PM
|
|
QUOTE(Duckies @ Dec 17 2018, 02:26 PM) Coded at the client side aka website there which by right should be at server side only. Absolute garbage security
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 03:44 PM
|
|
QUOTE(RicoT @ Dec 17 2018, 03:40 PM) Last time was 8 alphanumeric characters, the password input during login will stop after typing 8 characters, then later it accepts many characters but only the first 8 will be taken. Been like that for sometime. nope.. definitely not before december because this the only 8char PW i have, so everytime i will punch a 10-13char pw first before i go 'oh ya this one text field capped at 8 char not my usual pw'
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 04:54 PM
|
|
QUOTE(maxpudding @ Dec 17 2018, 04:48 PM) Yup, but you still can opt out the debit card feature how to opt out ya? need to go to branch/call cs is it?
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 05:24 PM
|
|
QUOTE(RicoT @ Dec 17 2018, 05:23 PM) One question, I noticed a hotel employee jotted down my full credit card number, expiry date and the numbers behind. Is it normal or I should sound the manager? say goodbye to your card
|
|
|
|
|
|
teehk_tee
|
Dec 17 2018, 05:31 PM
|
|
QUOTE(TunaFish1990 @ Dec 17 2018, 05:24 PM) yea...someone replied me liao... seems like the pwd and this paypal thing are 2 different thing altogether closed front door with triple grill..but back door entrance still open wide even if they are two different matters as custodians of your funds, the way ppl are being lackadaisical in this is just a demonstration of the tidak apa attitude in general of msians. oh? vault not secure enough? tak apa lah.. money dlm ckit je
|
|
|
|
|