so..now is safe to login or not?
Chat CIMB kena hack?
Chat CIMB kena hack?
|
|
Dec 17 2018, 09:18 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,706 posts Joined: May 2008 |
so..now is safe to login or not?
|
|
|
|
|
|
Dec 17 2018, 09:19 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,968 posts Joined: Sep 2012 |
QUOTE(linkinstreet @ Dec 17 2018, 09:16 AM) Last night new password can be more than 8 chars + you need a special char too. A bit too late if you ask me tho They already announce new password policy earlier this year if I rmb correctly. Just they did not force all users to update. They just put an announcement in their website. So yg x update policy all kena this exploit. Those that have updated password prior to this, should not be affected. And guys. About those that keep asking if ur affected. If u have a cimbclicks account and is still on the old 8 character password policy, then yes, you are affected. |
|
|
Dec 17 2018, 09:20 AM
|
![]()
Junior Member
17 posts Joined: Apr 2009 From: Klang 。◕‿◕。 |
QUOTE(eltaria @ Dec 17 2018, 09:08 AM) For those that are saying u can still login with 8 correct password + xyzzzzzzz remember last time cimb backup goes missing while in transport? might have something to do with this? The reason for that is probably 1) you urself didnt change the original 8 characters password. 2) the system still need to provide backward compatibility to users who didn't change to a longer password, maybe their implementation is poor, if fail to match full length password, then match 1st eight type of code... 3) in term of the 8 characters password being a problem in the 1st place.... That shouldn't b.. passwords even with 8 characters shld be sufficiently strong if you have it at least randomized, they shld implement blocking of subsequent tries after failure of the first 10 attempts. Whatever is happening, its more than just a password issue i believe. |
|
|
Dec 17 2018, 09:20 AM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,215 posts Joined: Jul 2009 From: Penang Island |
me ikan bilis balance still there..
so i try to change password but keep on say invalid. |
|
|
Dec 17 2018, 09:21 AM
Show posts by this member only | IPv6 | Post
#545
|
![]() ![]()
Junior Member
82 posts Joined: Feb 2008 From: Vladivostok |
block paypal purchase liaoooo
|
|
|
Dec 17 2018, 09:21 AM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,750 posts Joined: Feb 2009 |
QUOTE(eltaria @ Dec 17 2018, 09:08 AM) For those that are saying u can still login with 8 correct password + xyzzzzzzz even their data import when they doing system layout change that time also stupid. The reason for that is probably 1) you urself didnt change the original 8 characters password. 2) the system still need to provide backward compatibility to users who didn't change to a longer password, maybe their implementation is poor, if fail to match full length password, then match 1st eight type of code... 3) in term of the 8 characters password being a problem in the 1st place.... That shouldn't b.. passwords even with 8 characters shld be sufficiently strong if you have it at least randomized, they shld implement blocking of subsequent tries after failure of the first 10 attempts. Whatever is happening, its more than just a password issue i believe. some of my information were not imported correctly, ie the email address to notify the third party when you transfer money to them was actually imported as a**********.com rather than abcde@gmail.com i'm willing to bet money that the developer of the website ada cable, and has no experience in handling bank security before This post has been edited by incubus_skj: Dec 17 2018, 09:22 AM |
|
|
|
|
|
Dec 17 2018, 09:22 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
7,617 posts Joined: Mar 2009 |
shit!! I cannot log in at all. it says "Invalid User ID or Password [CLK00619]". someone change my password????
|
|
|
Dec 17 2018, 09:22 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,187 posts Joined: Jan 2003 From: sleepy melati |
so now safe to login even with captcha? first post still says don't login if got captcha.
|
|
|
Dec 17 2018, 09:22 AM
Show posts by this member only | IPv6 | Post
#549
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,818 posts Joined: Jan 2005 From: Kuala Lumpur |
i had been hating cimb for a long time because they forced user to limit password for 8 chars.. After so many years since the existence of online banking, they made that changes only recently...
This post has been edited by zeese: Dec 17 2018, 09:23 AM |
|
|
Dec 17 2018, 09:22 AM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,701 posts Joined: Oct 2010 From: Under your bed |
RIP CIMB users.
|
|
|
Dec 17 2018, 09:23 AM
|
![]() ![]() ![]()
Junior Member
342 posts Joined: Jan 2013 |
|
|
|
Dec 17 2018, 09:24 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
7,617 posts Joined: Mar 2009 |
|
|
|
Dec 17 2018, 09:25 AM
Show posts by this member only | IPv6 | Post
#553
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(zeese @ Dec 17 2018, 09:22 AM) i had been hating cimb for a long time because they forced user to limit password for 8 chars.. After so many years since the existence of online banking, they made that changes only recently... Yes this is the most sohai online banking everEven cinapek PBB do it better |
|
|
|
|
|
Dec 17 2018, 09:25 AM
|
![]()
Junior Member
7 posts Joined: Dec 2008 |
Can someone tell me from the technical point of view, why is :
1. Existing username + existing 8 character password = safe (I presume this is safe otherwise you won't be using the same password for n years) 2. Existing username + (existing 8 character password + random character string) = unsafe |
|
|
Dec 17 2018, 09:25 AM
|
|
Moderator
9,275 posts Joined: Jan 2005 From: KL. Best place in Malaysia. Nuff said |
|
|
|
Dec 17 2018, 09:27 AM
Show posts by this member only | IPv6 | Post
#556
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,017 posts Joined: Sep 2011 |
|
|
|
Dec 17 2018, 09:27 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,809 posts Joined: Mar 2007 |
QUOTE(jimmyktp @ Dec 16 2018, 10:59 PM) Instead of recaptcha, they should follow what UK banks doing. 2FA. But problem is that could be too complicated for users to set up the first time. Recaptcha is to identify bots. What about real humans? I don't think recaptcha is relevant for a banking website. Blizzard uses it to protect their World of Warcraft subscribers too.I'm using HSBC UK's 2FA. Really powerful. But is a pain to set up for the first time. |
|
|
Dec 17 2018, 09:29 AM
Show posts by this member only | IPv6 | Post
#558
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
Virtual 2FA is a nightmare for IT noobs
Unless they learned from SG which is to give out physical token device to everyone |
|
|
Dec 17 2018, 09:31 AM
|
![]() ![]()
Junior Member
87 posts Joined: Dec 2010 From: Johor Lumpur |
QUOTE(StreetBaller89 @ Dec 17 2018, 09:25 AM) Can someone tell me from the technical point of view, why is : Me too1. Existing username + existing 8 character password = safe (I presume this is safe otherwise you won't be using the same password for n years) 2. Existing username + (existing 8 character password + random character string) = unsafe |
|
|
Dec 17 2018, 09:32 AM
Show posts by this member only | IPv6 | Post
#560
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,616 posts Joined: Jul 2016 |
|
| Change to: | 0.0266sec
0.92
6 queries
GZIP Disabled
Time is now: 11th December 2025 - 10:13 AM |