Change password problem solved?
Chat CIMB kena hack?
Chat CIMB kena hack?
|
|
Dec 17 2018, 09:01 AM
Return to original view | IPv6 | Post
#1
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
Change password problem solved?
|
|
|
|
|
|
Dec 17 2018, 09:04 AM
Return to original view | IPv6 | Post
#2
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
now they extended the password char limit
|
|
|
Dec 17 2018, 09:14 AM
Return to original view | IPv6 | Post
#3
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(alexander3133 @ Dec 17 2018, 09:04 AM) Unfortunately, might not. I dont even keep the cimb debit card for n years, lost it and dont give a fuck since thenIf hacker already snapshot your account info especially credit card/debit card number. They can link your card number to paypal and take money from there. Read more especially screenshot from people @ https://www.soyacincau.com/2018/12/17/was-c...-clicks-hacked/ Have to check whether it is still active or not |
|
|
Dec 17 2018, 09:25 AM
Return to original view | IPv6 | Post
#4
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(zeese @ Dec 17 2018, 09:22 AM) i had been hating cimb for a long time because they forced user to limit password for 8 chars.. After so many years since the existence of online banking, they made that changes only recently... Yes this is the most sohai online banking everEven cinapek PBB do it better |
|
|
Dec 17 2018, 09:29 AM
Return to original view | IPv6 | Post
#5
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
Virtual 2FA is a nightmare for IT noobs
Unless they learned from SG which is to give out physical token device to everyone |
|
|
Dec 17 2018, 10:03 AM
Return to original view | IPv6 | Post
#6
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
How does one get to link CC/Debit card to Paypal without trigerring TAC prompt?
Furthermore there is CVV number that need to be key in |
|
|
|
|
|
Dec 17 2018, 10:09 AM
Return to original view | IPv6 | Post
#7
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
|
|
|
Dec 17 2018, 10:10 AM
Return to original view | IPv6 | Post
#8
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
Ayam just called remisier to on hold remitting the sales proceed into cimb today
|
|
|
Dec 17 2018, 10:19 AM
Return to original view | IPv6 | Post
#9
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
|
|
|
Dec 17 2018, 11:11 AM
Return to original view | Post
#10
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(Mummy Shark @ Dec 17 2018, 10:51 AM) then actually it is 2 separate issuesone is their obsolete password policy and implementation second is someone managed to stole lots of card numbers and link them to paypal these 2 incidents could be related though |
|
|
Dec 17 2018, 11:15 AM
Return to original view | Post
#11
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
|
|
|
Dec 17 2018, 11:21 AM
Return to original view | Post
#12
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
|
|
|
Dec 17 2018, 11:29 AM
Return to original view | Post
#13
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(Mummy Shark @ Dec 17 2018, 11:24 AM) the one that didn't support transaction validation (malaysians call it TAC via mobile number) is paypal. i think google, spotify, netflix etc doesn't ask for TAC eithereven if CIMB is to be faulted for "releasing" card numbers to criminals, Paypal as platform provider is also guilty for not supporting mastercard and visa initiative to validate transactions. this cannot happen if paypal implements support for transaction validation. https://en.m.wikipedia.org/wiki/3-D_Secure its just not the angmoh culture, also due to the cc fraud is lower in the western world |
|
|
|
|
|
Dec 17 2018, 11:39 AM
Return to original view | Post
#14
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
|
|
|
Dec 17 2018, 11:46 AM
Return to original view | Post
#15
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(kraka @ Dec 17 2018, 11:44 AM) this is just not some paypal or hack issue...its an internal security flaw.... In CIMB there is a 2nd page after entering your username, where you need to confirm a "secureword" before you can proceed to the password page. I entered my email id once by mistake and i got logged into some other guy's secureword page.. So i just closed the site. this is not surprisingSo lets not just blame someone outside. the security systems were rotten to start with, even a small kid could hack into their websites some people tend to use their full name as per ic as userid now you can try input your friends name into it |
|
|
Dec 17 2018, 02:54 PM
Return to original view | Post
#16
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(OldSchoolJoke @ Dec 17 2018, 01:01 PM) if i read correctly, dun understandif password following the new format (have special characters and more or equal to 8 characters) then password will be as it is else if old password format (8 characters), it will only take first 8 characters. any characters behind don't care..kena chopped if password more >= 8 char, then the first condition wont satisfy if password is <8 char, then it only check up to 8th character no conflicts what |
|
|
Dec 17 2018, 03:01 PM
Return to original view | Post
#17
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
|
|
|
Dec 17 2018, 03:03 PM
Return to original view | Post
#18
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(axn992 @ Dec 17 2018, 02:55 PM) Or backend should reject passwords <8 with no special chars. Only except password length of 8 or more with special chars. They can force all users to change it and they can delete legacy code. or another way, just implement the cut off date to mandate all users to change into new password format lahvia SMS, email, site take over after the deadline, user will have to change their password apa susah, its just the user password and not the legacy Account No. its CIMB that wish to skim on the budgets to spread the news around |
|
|
Dec 17 2018, 03:10 PM
Return to original view | Post
#19
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(OldSchoolJoke @ Dec 17 2018, 03:06 PM) its not about conflict, it about the .substring(0, 8) part. i noticed the && logic in the IF statementmeans if it doesn't satisfy the first condition, it will only take the first 8 characters of the password e.g: your password is 123456789 since it doesn't satisfy the first condition, it will take first 8 characters which is 12345678 logically, 123456789 is not the same as 12345678. even if you plainly compare it is not the same. so those who want to attack the site, just need to guess for 8 characters which lessen the time to guess a correct password what they should do (IMO) is just send the password to server as it is instead of plainly showing to the world the checking. then i understand dy |
|
|
Dec 17 2018, 03:18 PM
Return to original view | Post
#20
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,587 posts Joined: Apr 2011 |
QUOTE(Mummy Shark @ Dec 17 2018, 03:13 PM) what is there to blame paypal?in US there is no mandated rule to use TAC paypal did not violate any rules set by US authorities neither do Visa/Master association themselves do mandate the use of TAC, TAC is just enforced by BNM as an additional gatekeeper to protect CC transaction that's it |
| Change to: | 0.0176sec
0.93
7 queries
GZIP Disabled
Time is now: 11th December 2025 - 05:19 AM |