Welcome Guest ( Log In | Register )

90 Pages « < 26 27 28 29 30 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
fantasy1989
post Dec 17 2018, 09:18 AM

Look at all my stars!!
*******
Senior Member
4,706 posts

Joined: May 2008



so..now is safe to login or not?
briantwj
post Dec 17 2018, 09:19 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(linkinstreet @ Dec 17 2018, 09:16 AM)
Last night new password can be more than 8 chars + you need a special char too. A bit too late if you ask me tho
*
They already announce new password policy earlier this year if I rmb correctly. Just they did not force all users to update. They just put an announcement in their website.

So yg x update policy all kena this exploit. Those that have updated password prior to this, should not be affected.

And guys. About those that keep asking if ur affected. If u have a cimbclicks account and is still on the old 8 character password policy, then yes, you are affected.
boystyle
post Dec 17 2018, 09:20 AM

New Member
*
Junior Member
17 posts

Joined: Apr 2009
From: Klang 。◕‿◕。


QUOTE(eltaria @ Dec 17 2018, 09:08 AM)
For those that are saying u can still login with 8 correct password + xyzzzzzzz

The reason for that is probably
1) you urself didnt change the original 8 characters password.
2) the system still need to provide backward compatibility to users who didn't change to a longer password, maybe their implementation is poor, if fail to match full length password, then match 1st eight type of code...
3) in term of the 8 characters password being a problem in the 1st place.... That shouldn't b.. passwords even with 8 characters shld be sufficiently strong if you have it at least randomized, they shld implement blocking of subsequent tries after failure of the first 10 attempts.

Whatever is happening, its more than just a password issue i believe.
*
remember last time cimb backup goes missing while in transport? might have something to do with this? hmm.gif
yahiko
post Dec 17 2018, 09:20 AM

Regular
******
Senior Member
1,215 posts

Joined: Jul 2009
From: Penang Island


me ikan bilis balance still there..
so i try to change password but keep on say invalid.


grixis
post Dec 17 2018, 09:21 AM

Getting Started
**
Junior Member
82 posts

Joined: Feb 2008
From: Vladivostok



block paypal purchase liaoooo
incubus_skj
post Dec 17 2018, 09:21 AM

oh mai gotto
******
Senior Member
1,750 posts

Joined: Feb 2009


QUOTE(eltaria @ Dec 17 2018, 09:08 AM)
For those that are saying u can still login with 8 correct password + xyzzzzzzz

The reason for that is probably
1) you urself didnt change the original 8 characters password.
2) the system still need to provide backward compatibility to users who didn't change to a longer password, maybe their implementation is poor, if fail to match full length password, then match 1st eight type of code...
3) in term of the 8 characters password being a problem in the 1st place.... That shouldn't b.. passwords even with 8 characters shld be sufficiently strong if you have it at least randomized, they shld implement blocking of subsequent tries after failure of the first 10 attempts.

Whatever is happening, its more than just a password issue i believe.
*
even their data import when they doing system layout change that time also stupid.

some of my information were not imported correctly, ie the email address to notify the third party when you transfer money to them was actually imported as a**********.com rather than abcde@gmail.com

i'm willing to bet money that the developer of the website ada cable, and has no experience in handling bank security before

This post has been edited by incubus_skj: Dec 17 2018, 09:22 AM
annoymous1234
post Dec 17 2018, 09:22 AM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

shit!! I cannot log in at all. it says "Invalid User ID or Password [CLK00619]". someone change my password????
Uzumaki NaruTo
post Dec 17 2018, 09:22 AM

oro?
*******
Senior Member
4,187 posts

Joined: Jan 2003
From: sleepy melati



so now safe to login even with captcha? first post still says don't login if got captcha.
zeese
post Dec 17 2018, 09:22 AM

Warning Level
******
Senior Member
1,818 posts

Joined: Jan 2005
From: Kuala Lumpur
i had been hating cimb for a long time because they forced user to limit password for 8 chars.. After so many years since the existence of online banking, they made that changes only recently...

This post has been edited by zeese: Dec 17 2018, 09:23 AM
mengfart
post Dec 17 2018, 09:22 AM

༼ つ ◕_◕ ༽つ Giff Me Mana Kotol
******
Senior Member
1,701 posts

Joined: Oct 2010
From: Under your bed
RIP CIMB users.
ZeaXG
post Dec 17 2018, 09:23 AM

Casual
***
Junior Member
342 posts

Joined: Jan 2013


QUOTE(annoymous1234 @ Dec 17 2018, 09:22 AM)
shit!! I cannot log in at all. it says "Invalid User ID or Password [CLK00619]". someone change my password????
*
You type korek or not first. If korek, then RIP. try call customer service see can help or not
annoymous1234
post Dec 17 2018, 09:24 AM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

QUOTE(ZeaXG @ Dec 17 2018, 09:23 AM)
You type korek or not first. If korek, then RIP. try call customer service see can help or not
*
ops my bad. too panic type wrong sweat.gif
PhakFuhZai
post Dec 17 2018, 09:25 AM

harimau putih
******
Senior Member
1,587 posts

Joined: Apr 2011
QUOTE(zeese @ Dec 17 2018, 09:22 AM)
i had been hating cimb for a long time because they forced user to limit password for 8 chars..  After so many years since the existence of online banking, they made that changes only recently...
*
Yes this is the most sohai online banking ever

Even cinapek PBB do it better
StreetBaller89
post Dec 17 2018, 09:25 AM

New Member
*
Junior Member
7 posts

Joined: Dec 2008
Can someone tell me from the technical point of view, why is :

1. Existing username + existing 8 character password = safe (I presume this is safe otherwise you won't be using the same password for n years)
2. Existing username + (existing 8 character password + random character string) = unsafe
linkinstreet
post Dec 17 2018, 09:25 AM

Red Bull Addict
Group Icon
Moderator
9,275 posts

Joined: Jan 2005
From: KL. Best place in Malaysia. Nuff said

QUOTE(yahiko @ Dec 17 2018, 09:20 AM)
me ikan bilis balance still there..
so i try to change password but keep on say invalid.
*
New passwords needs to have a mixture of alphabet, numbers and at least one special characters. I can change last night
hightechgadgets8
post Dec 17 2018, 09:27 AM

\(^o^)/
*******
Senior Member
6,017 posts

Joined: Sep 2011


QUOTE(ZeaXG @ Dec 17 2018, 09:23 AM)
You type korek or not first. If korek, then RIP. try call customer service see can help or not
*
Cs no free
soitsuagain
post Dec 17 2018, 09:27 AM

Let's do it together!
*******
Senior Member
3,809 posts

Joined: Mar 2007


QUOTE(jimmyktp @ Dec 16 2018, 10:59 PM)
Instead of recaptcha, they should follow what UK banks doing. 2FA. But problem is that could be too complicated for users to set up the first time. Recaptcha is to identify bots. What about real humans? I don't think recaptcha is relevant for a banking website.

I'm using HSBC UK's 2FA. Really powerful. But is a pain to set up for the first time.
*
Blizzard uses it to protect their World of Warcraft subscribers too.
PhakFuhZai
post Dec 17 2018, 09:29 AM

harimau putih
******
Senior Member
1,587 posts

Joined: Apr 2011
Virtual 2FA is a nightmare for IT noobs
Unless they learned from SG which is to give out physical token device to everyone
kopikaukau
post Dec 17 2018, 09:31 AM

Getting Started
**
Junior Member
87 posts

Joined: Dec 2010
From: Johor Lumpur
QUOTE(StreetBaller89 @ Dec 17 2018, 09:25 AM)
Can someone tell me from the technical point of view, why is :

1. Existing username + existing 8 character password = safe (I presume this is safe otherwise you won't be using the same password for n years)
2. Existing username + (existing 8 character password + random character string) = unsafe
*
Me too
Cookie101
post Dec 17 2018, 09:32 AM

Regular
******
Senior Member
1,616 posts

Joined: Jul 2016
QUOTE(PhakFuhZai @ Dec 17 2018, 09:29 AM)
Virtual 2FA is a nightmare for IT noobs
Unless they learned from SG which is to give out physical token device to everyone
*
They have shifted to digital token.

Welcome out of cave.

90 Pages « < 26 27 28 29 30 > » Top
 

Change to:
| Lo-Fi Version
0.0266sec    0.92    6 queries    GZIP Disabled
Time is now: 11th December 2025 - 10:13 AM