QUOTE(aku_ker @ Dec 17 2018, 01:32 AM)
The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.
Anyway it's a security flaw and cimb should announce and take action.
Can explain more on the above? For Maybank u know right you can withdraw money without ATM card.
Anyway it's a security flaw and cimb should announce and take action.
QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
For me i noticed now transfer money also no need any tac for verification. Crazy. So if they masuk someone acc and no need tac verify... Thats it
Which bank can do that? QUOTE(hor @ Dec 17 2018, 02:14 AM)
My wild guess:
1) Business: ok guys we need to remove the 8 char pw limitation
2) Tester: wth I used to type the same but now couldn't login
3) Dev: that's easy, we just attempt login with full input and if cant we try again with first 8 char only
*roll out*
4) Customer: wth I can login with extra junk char
5) Dev: (*oh shit)
1) Business: ok guys we need to remove the 8 char pw limitation
2) Tester: wth I used to type the same but now couldn't login
3) Dev: that's easy, we just attempt login with full input and if cant we try again with first 8 char only
*roll out*
4) Customer: wth I can login with extra junk char
5) Dev: (*oh shit)
QUOTE(teehk_tee @ Dec 17 2018, 02:22 AM)
Cant they void all the old passwords and force customers to update new pw upon login? Many brokerages do this.
Not allow 8char + whatever shit to login.
Maybank actually do this a couple of months ago, I was force to change my password a couple of times. Probably kena... Not allow 8char + whatever shit to login.
QUOTE(leftycall9 @ Dec 17 2018, 03:16 AM)
CIMB didn't send any warning or anything about this through message or announcement. yeah I'm really pissed :/
it happened to mine and my friend's account. not sure about others but I have changed my password
What! it happened to mine and my friend's account. not sure about others but I have changed my password
Dec 17 2018, 04:49 AM

Quote


0.0565sec
0.66
7 queries
GZIP Disabled