Is CIMB Clicks down?

vegavega25

Senior Member
Joined
Aug 30, 2016
Messages
1,166
Reaction score
127
Technical glitches can happen, as seen so recently with DBS, and so far I'm not worried about CIMB SG as a going concern.

However I do find baffling that their Facebook page won't even acknowledge the issue. There were 500+ customers' comments complaining, and they had to do so in response to the bank's latest post on the 28th about some campaign or promo, but CIMB not once even mentioned the multi-day glitch. That does give me cause for concern.
 

lzydata

Supremacy Member
Joined
Oct 16, 2010
Messages
6,716
Reaction score
3,029
对此,联昌银行今日回复记者说,由于客户过去三日频繁访问网上银行进行外汇转账及查看新元兑换马来西亚令吉的汇率,导致网上银行平台的性能下降,一些客户因此遇到间歇性服务问题。

联昌表示,为缓解网上银行流量激增的问题,客户可在cimbbank.sg/sgmy-fixed查询新元兑令吉的汇率,只在须要进行交易时才登录网上银行。

https://www.zaobao.com.sg/realtime/singapore/story20211230-1227935
CIMB says that the breakdown was due to too many people making forex transactions and checking the SGD-MYR exchange rate. :unsure:

Also, MAS has been informed and is monitoring developments.
 

galapogos

Moderator
Moderator
Joined
Aug 30, 2000
Messages
30,098
Reaction score
42
Agree with diversification, but a case can be made that CIMB's infrastructure and security isn't as good. The website design is dated, the security policies are arcane (userid requires numbers, but the max password length is just 8). Compared to other local banks, I'm not confident of its security posture TBH.
 

BBCWatcher

Arch-Supremacy Member
Joined
Jun 15, 2010
Messages
24,483
Reaction score
5,541
Compared to other local banks, I'm not confident of its security posture TBH.
Your take is at least not well timed given the news about OCBC yesterday! (OCBC and their customers have recently lost 10s of millions to phishing attacks. And this news is particularly distressing to me if you check my past posts.)

About the 8 character password, yes, a longer one would be a good idea. But about that local bank(s)...how do you feel about 6 digit PINs then? (They both have multi-factor authentication.)

A "dated" Web design is a GOOD thing from a security point of view, other things being equal.

There's a reasonable argument a CIMB ATM card is a little more secure because it won't work in Singapore except at one ATM.

Don't assume, don't speculate. Stick to facts that matter as best we can determine them, and (still) maintain a little financial diversity.
 
Last edited:

CrashWire

Supremacy Member
Joined
Nov 28, 2000
Messages
5,931
Reaction score
801
There's a reasonable argument a CIMB ATM card is a little more secure because it won't work in Singapore except at one ATM.
I've never tried this, but wouldn't CIMB ATM cards be able to withdraw at all ATMs on the Plus network?
 

lzydata

Supremacy Member
Joined
Oct 16, 2010
Messages
6,716
Reaction score
3,029
I've never tried this, but wouldn't CIMB ATM cards be able to withdraw at all ATMs on the Plus network?
Do you mean the atm5 network? Then no, as it is not a member. Members are Bank of China, Citibank, HSBC, Maybank, Stanchart and SBI.
 

vegavega25

Senior Member
Joined
Aug 30, 2016
Messages
1,166
Reaction score
127
I've never tried this, but wouldn't CIMB ATM cards be able to withdraw at all ATMs on the Plus network?

In Singapore: only CIMB ATMs.

Other countries: at CIMB ATMs if available (no service charge), or those in the Plus network (1% Visa fee applies and anything else the ATM owning bank charges).
 

BBCWatcher

Arch-Supremacy Member
Joined
Jun 15, 2010
Messages
24,483
Reaction score
5,541
I'm pretty sure cards arrive disabled by default for overseas use. That part is the same.
 

galapogos

Moderator
Moderator
Joined
Aug 30, 2000
Messages
30,098
Reaction score
42
Your take is at least not well timed given the news about OCBC yesterday! (OCBC and their customers have recently lost 10s of millions to phishing attacks. And this news is particularly distressing to me if you check my past posts.)

About the 8 character password, yes, a longer one would be a good idea. But about that local bank(s)...how do you feel about 6 digit PINs then? (They both have multi-factor authentication.)

A "dated" Web design is a GOOD thing from a security point of view, other things being equal.

There's a reasonable argument a CIMB ATM card is a little more secure because it won't work in Singapore except at one ATM.

Don't assume, don't speculate. Stick to facts that matter as best we can determine them, and (still) maintain a little financial diversity.
Phishing scams are not indicative of the bank's security posture since they rely on social engineering if the victims, so it could conceivably happen to any bank.

A dated Web design is indicative of a dated tech stack with old components that are not updated and hence may have known vulnerabilities.

I'm not a fan of 6 digit PINs either, and yup I know DBS/OCBC uses this, but UOB and SCB supports longer passphrases.
 

BBCWatcher

Arch-Supremacy Member
Joined
Jun 15, 2010
Messages
24,483
Reaction score
5,541
Phishing scams are not indicative of the bank's security posture since they rely on social engineering if the victims, so it could conceivably happen to any bank.
I disagree. You can refer to my previous posts for background on this point.
A dated Web design is indicative of a dated tech stack with old components that are not updated and hence may have known vulnerabilities.
I disagree again. The "attack surface" of a simpler user interface is reduced, other things being equal. And there's nothing preventing the backend being current on security-related maintenance. If there is a less mature technology backend then, other things being equal, there's been less time to shake out possible security vulnerabilities and have security teams review them. There's just no assumption that can be inferred here along the lines you're describing. Hypothetically CIMB could be providing *terminal* user interfaces, and they could have a very high security profile indeed.
I'm not a fan of 6 digit PINs either, and yup I know DBS/OCBC uses this, but UOB and SCB supports longer passphrases.
OK, so close your accounts at DBS, POSB, and OCBC first, correct?
 

galapogos

Moderator
Moderator
Joined
Aug 30, 2000
Messages
30,098
Reaction score
42
I'm not sure what you posted on why OCBC's phishing scams are indicative of a technical problem on their side, but based on what is public about the scam, it seems like it's purely a social engineering attempt that could have happened to anyone. They didn't exploit any subdomain takeover, HTML injection, CSRF, URL redirection, or other vulnerabilities that may have made the malicious link look more legitimate. They just registered a domain that contained ocbc in it - not exactly rocket science. As for spoofing OCBC's SMS channel, it's also rather trivial to do, and could have happened to any other organisation.

Also, if you've ever pentested, or even ran a VA scan on an older website vs a newer one, you'd know that older tech stacks often don't have many security mitigations built into the frameworks by default. Anti-CSRF tokens, anti XSS, parameterised queries, etc are more prevalent nowadays compared to a website from 15 years ago. And that's just the Web side of things. Mobile is another ballgame, and most local banks use a virtual secure element solution. I'm not sure if CIMB does, but some of my colleagues took a look at their mobile app a few years ago and were quite disappointed in the level of security there. Sure, it may have improved over the years, but given the same dated interface and track record, I'm not holding my breath.
 
Last edited:

CrashWire

Supremacy Member
Joined
Nov 28, 2000
Messages
5,931
Reaction score
801
Mobile is another ballgame, and most local banks use a virtual secure element solution. I'm not sure if CIMB does, but some of my colleagues took a look at their mobile app a few years ago and were quite disappointed in the level of security there. Sue, it may have improved over the years, but given the same dates interface and track record, I'm not holding my breath.
There is a digital key feature now. The main benefit is that the user doesn't have to do SMS OTP for their transactions on that device.
 

galapogos

Moderator
Moderator
Joined
Aug 30, 2000
Messages
30,098
Reaction score
42
There is a digital key feature now. The main benefit is that the user doesn't have to do SMS OTP for their transactions on that device.
Yup, I'm aware of that, but I'm not familiar with their implementation and how secure it is. I'm more familiar with the solution used by other banks such as UOB and DBS.
 

sohguanh

Supremacy Member
Joined
Jul 10, 2010
Messages
9,460
Reaction score
3,202
Just to tag along to this thread. The CIMB FastSaver and StarsSaver revised interest rate from 01 Aug 2022 onwards. For ppl who meet the tier below is a more optimised way to place you funds.
Assumption 1: You have both FastSaver and StarSaver
Assumption 2: You have total 175K to be funded to both accounts

FastSaver
1st 25K 0.50% = 125
Next 25K 0.80% = 200
Next 25K 1.00% = 250
Total for 75K = 575 (why magic number 75K is based on the interest rate tier they provide)

StarSaver
1st 100K 0.40% = 400
Next 150K 0.80% . 75K at this tier is 600

Option 1: 75K (FastSaver) + 100K (StarSaver)
Option 2: 175K (StarSaver)
FastSaver no fall below fees so can leave 0 or a few cents. If want interest at least 1K

Hope SC eSaver and Maybank iSavvy up their interest rate soon
 

sohguanh

Supremacy Member
Joined
Jul 10, 2010
Messages
9,460
Reaction score
3,202
SC eSaver 0.8% promo end Jul. Seems nothing from them.
SC 0.8% interest come in already so can shift out and so far CIMB revised rate look better at the moment. How ironic for a Msia bank to start the ball rolling than our own local banks which some argue a lot of monies so no need take monies from customers I guess they are right.
 

sohguanh

Supremacy Member
Joined
Jul 10, 2010
Messages
9,460
Reaction score
3,202
Just to tag along to this thread. The CIMB FastSaver and StarsSaver revised interest rate from 01 Aug 2022 onwards. For ppl who meet the tier below is a more optimised way to place you funds.
Assumption 1: You have both FastSaver and StarSaver
Assumption 2: You have total 175K to be funded to both accounts

FastSaver
1st 25K 0.50% = 125
Next 25K 0.80% = 200
Next 25K 1.00% = 250
Total for 75K = 575 (why magic number 75K is based on the interest rate tier they provide)

StarSaver
1st 100K 0.40% = 400
Next 150K 0.80% . 75K at this tier is 600

Option 1: 75K (FastSaver) + 100K (StarSaver)
Option 2: 175K (StarSaver)
FastSaver no fall below fees so can leave 0 or a few cents. If want interest at least 1K

Hope SC eSaver and Maybank iSavvy up their interest rate soon

From 1 Sep 2022 rate increased again. This time Option 1 is better. Just remember to put back the 75K into FastSaver.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top