Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
teehk_tee
post Dec 17 2018, 05:36 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(Silverknight @ Dec 17 2018, 05:30 PM)
So it's actually the most people panic-ed for seeing captcha at login screens and then speculate that the website got hacked? And by the way, those who claimed that their account got hacked did not claim it with sufficient evidences but merely just a message saying their account's balance deducted.

The point is, how do we know whether that person who got "hacked" actually did made an online transaction to subscribe Daily Awesome Midget Porn in one of the pornsite and credentials was compromised there? We'll never know.
*
what is a password

note; singular

pass-word

on sunday night people were finding out that
variants of their password , ie; pass-words were able to log in.

how will you have felt?


them spinning this to ''oh, yours is an old format we merely truncated the characters to 8'' is deflecting blame.

on top of that now that the source code is obtained (from the client side, not the server side) effectively telling the world, if PW = old format, truncate and take 8 chars to login)

how would u have felt?
teehk_tee
post Dec 17 2018, 05:39 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(RicoT @ Dec 17 2018, 05:36 PM)
I booked the hotel online, then the receptionist says need too record down. It is a reputable 4 star hotel with many branches in Malaysia.

Maybe during check out, I will ask for that paper she jotted down.
*
record down for what?
if want to take security deposit just put a block on the card first.

not write down on piece of paper as deposit topkek

This post has been edited by teehk_tee: Dec 17 2018, 05:40 PM
teehk_tee
post Dec 17 2018, 05:45 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(stormsea7 @ Dec 17 2018, 05:42 PM)
won't that risk bank run if everyone transfer away?
*
lol thats your problem,
i already emptied my cimb preferred account
teehk_tee
post Dec 17 2018, 05:48 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(emburrar @ Dec 17 2018, 05:45 PM)
dah fix ke
this prob
*
according to the news, everything is fine and dandy
what problem?
teehk_tee
post Dec 17 2018, 07:55 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(silent_stalker @ Dec 17 2018, 07:44 PM)
Its normal actually. No way any bank gonna say "yea we fucked up". 😒. The only way thry will acknowledge their mistake is thru court.
*
I taruh my RM in the afternoon. Keep saying money is safe, the pw system is designed to be like that.

I whack bck her said last month it wasnt like that. How can it be a password if 'passwords' can unlock it?

Then how also dont admit la u know how it goes.
So i told her, ok fine. Since u say the system was designed like that, i would like to buy a bank draft. Please close my acc tq.
teehk_tee
post Dec 17 2018, 08:42 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(C-Fu @ Dec 17 2018, 08:32 PM)
Waddafak..

I assume this would be a server side verification
Hopefully not the useless user+pw verification coding junk that they churned out
teehk_tee
post Dec 17 2018, 10:52 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(mina 1.0 @ Dec 17 2018, 10:22 PM)
This was a good piece of investigative journalism

https://www.lowyat.net/2018/175102/what-cim...you-but-should/

but what's the point anyway?

CIMB can just lie to its customers and nobody will care

Malaysians don't care if their Govt or company or whatever lies to them and takes advantage of them

Malaysians never take action to boycott them or demand justice

Malaysians only care when it's an issue involving the wrong race or religion
*
amen

as evidenced many ppl just selamba aja
some even potek the bank

accountability and trust dont really matter to many ppl
teehk_tee
post Dec 18 2018, 10:53 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

For me the core of the problem is the coverup nothing is wrong this was by design attitude.

This is a bank, not a direct sales company.
for that, im out.
teehk_tee
post Dec 18 2018, 10:56 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(Silverknight @ Dec 18 2018, 10:53 AM)
I am a bit confused, even if the password is compromised, the hacker would still need TAC right to make online transactions? So basically those that do not use credit/debit cards are safe?
*
A compromise is a compromise.
this is like saying my front door got breached but luckily my bedroom door is sturdy.

It just comforts you but in reality you gotta change that front door.
teehk_tee
post Dec 21 2018, 02:12 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(aminpro @ Dec 21 2018, 06:08 AM)
The current updated FAQ from CIMB suggests that special characters were allowed in the past, just not mandatory.
The JS implementation also allows for special characters to be submitted if it was less than 8 characters.

The first article was taking the assumptions of how the old system used to work.
The second article reflects a more accurate situation due to the currently given evidence.

So far we cannot find good evidence that special characters were not allowed during the 8 character era. Everything else points to it being allowed back then.
Regarding the 8 characters thing you mentioned earlier, in the past, the characters were fixed to 8 characters maximum and minimum.
There was never > 8 characters in the past because it does not exist due to the old password policy being fixed at 8 characters.
The JS logic representing the old policy is the one that is saying "less than 8" as a criterion.

user posted image

All that said, the conclusion is that security was never compromised or hacked due to the new mechanisms for CIMB Clicks as some articles are suggesting in their clickbait headlines smile.gif
*
I can assure u prior to this passwords were alphanumeric only.
because my other banks use symbols, this the only bank i cannot put a symbol in my pw.
teehk_tee
post Dec 24 2018, 03:13 PM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(one1002 @ Dec 24 2018, 03:02 PM)
so all back to normal? no fuss no nothing... what happen..hehe
*
normal for me
already move out everything

3 Pages < 1 2 3Top
 

Change to:
| Lo-Fi Version
0.0572sec    0.64    7 queries    GZIP Disabled
Time is now: 14th December 2025 - 06:38 PM