Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
maxpudding
post Dec 17 2018, 09:05 PM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(agewisdom @ Dec 17 2018, 09:04 PM)
Ok, I see now.

The password issue is due to some customers with weak passwords such as an all numerical password getting compromised. What I still don't get then is that CIMB didn't implement the 'three strikes and you're out' system? I mean this is done for ATM cards. Why not for their online banking?  hmm.gif
*
Ask cimb why

We also dont know why they are so stupid in implementing better security
maxpudding
post Dec 17 2018, 09:07 PM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(heinlein @ Dec 17 2018, 09:06 PM)
when linking debit/credit card, paypal will impose a min amount to ur acc together with 4 pin code. You either receive it from sms or online banking statement. The linking will only succeed once you key in the 4 pin sent by paypal. After that, paypal will refund the min amount imposed earlier. Failure to do so wont link your card to paypal. After a certain duration, PayPal will still refund the amount imposed even if card linking failed. My cards were linked without sms or transaction details from cimb.
*
Yesza

Thats why it’s so easy using cimb+paypal

Easy for the bad people too
maxpudding
post Dec 18 2018, 07:29 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(yeo1992cc @ Dec 18 2018, 04:41 AM)
Just sharing, about the debate on truncate overflow password (Any characters over the given limit will not take into account).

As far as I know, it's pretty common in Malaysia bank, i can confirm Maybank and Public Bank implement this way too. (At least for me since my password pretty long, missing few last characters still able to login).
*
I tried with maybank, nope.
maxpudding
post Dec 18 2018, 07:38 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(yhtan @ Dec 18 2018, 07:36 AM)
I guess his head going to roll after this incident

user posted image
*
Lol
maxpudding
post Dec 18 2018, 07:51 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
https://www.lowyat.net/2018/175127/cimb-pay...bit-clicks-faq/

Response from cimb about paypal

In a nutshell they are saying: nothing out of ordinary is happening, business as usual.

I really dont know what to say la, asking cimb to address the issue of possibility of leaked card information is like asking a trained slug

This post has been edited by maxpudding: Dec 18 2018, 07:52 AM
maxpudding
post Dec 18 2018, 09:22 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(meteoraniac @ Dec 18 2018, 08:48 AM)
of coz CIMB going to deny this happened

billions of institutional money will be gone if they admit this case happening

u want them to take action? go organise protest kat hq dia, biar viral kao2
*
There are more diplomatic ways of addressing this issue, rather than blatantly denying it, I think they should be clear about what has happened and what they are planning to do to bring back the people’s confidence

Not simply saying “oh nothing’s wrong”
maxpudding
post Dec 19 2018, 07:40 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(lawliet88 @ Dec 18 2018, 10:34 PM)
just read sin chew daily , they put this cimb thing as "fake news" section lol  icon_idea.gif
*
Fake news butoh

Must be getting loan and extra credits from cimb
maxpudding
post Dec 19 2018, 08:21 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(John Chaser @ Dec 19 2018, 12:25 AM)
Nasi lemak tech says cimb did nothing wrong:
NLT
*
Wow challenging se7en issit
maxpudding
post Dec 21 2018, 10:05 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(aminpro @ Dec 21 2018, 06:08 AM)
The current updated FAQ from CIMB suggests that special characters were allowed in the past, just not mandatory.
The JS implementation also allows for special characters to be submitted if it was less than 8 characters.

The first article was taking the assumptions of how the old system used to work.
The second article reflects a more accurate situation due to the currently given evidence.

So far we cannot find good evidence that special characters were not allowed during the 8 character era. Everything else points to it being allowed back then.
Regarding the 8 characters thing you mentioned earlier, in the past, the characters were fixed to 8 characters maximum and minimum.
There was never > 8 characters in the past because it does not exist due to the old password policy being fixed at 8 characters.
The JS logic representing the old policy is the one that is saying "less than 8" as a criterion.

user posted image

All that said, the conclusion is that security was never compromised or hacked due to the new mechanisms for CIMB Clicks as some articles are suggesting in their clickbait headlines smile.gif
*
Putting “cimb did nothing wrong” in the title is extremely misleading. Se7en’s articles were written with public’s interests at heart. Your article seems to ridicule the people’s concern about security, normalizing the 8 characters limit, and the use if recaptcha

3 Pages < 1 2 3Top
 

Change to:
| Lo-Fi Version
0.0534sec    0.55    7 queries    GZIP Disabled
Time is now: 12th December 2025 - 06:42 AM