<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by thewan</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Fri, 05 Jun 2026 11:50:36 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>The problem with SMS is the user has ZERO control</title>
            <link>http://forum.lowyat.net/topic/5303093</link>
            <description>I would like to highlight one of, probably the main issue with SMS. As the user, we have zero control over SMS. It was standardized around the 1980s. The same core technology is still used until now. &lt;br /&gt;&lt;br /&gt;The problem with SMS is that there is no form of authentication. There is no need to identify the sender, the service used to send the SMS, or the receiver.  Person A can send a SMS pretending to be B. C can pretend to be the service provider, intercepting the SMS and reading the contents. D can pretend to be the receiver and receive the SMS. And this part can be done with or without SIM swapping, you just need to invest in the right tools and software, and those are cheap and relatively easy to procure.&lt;br /&gt;&lt;br /&gt;Also, the bank does not know that the SMS has arrived safely for its intended recipient. The user cannot verify that the one sending the SMS is indeed from a bank.&lt;br /&gt;&lt;br /&gt;Where else by using non SMS methods, a user has some form of control of the end result. Let&amp;#39;s take for example the banking app. Assuming that you trust your bank to do the right thing by securing their app and the method of communication between the app and the bank, the only thing a user has to worry about is the security of their phone. This is something under your control. &lt;br /&gt;&lt;br /&gt;For example, you can buy an iPhone, which is usually more secure due to its heavily controlled app ecosystem. In case of Android, you can choose a more reputable brand, that not only has good security practices, but has regular security and OS updates. When your updates end, you can choose to buy a new phone, or buy a different brand. You can use more complicated phone passwords instead of pin numbers, enable device encryption, or use biometrics instead of a password if u feel you can&amp;#39;t be bothered to use a complicated password because of your poor memory. You can make sure your phone is with you at all times, make sure not to lose or forget it, and in the event you cannot retrieve it safely, try your best to remote erase it. You can disable notifications for your financial apps as an additional security measure, or make sure no app has the permission to read your notifications other than required by your phone OS.&lt;br /&gt;&lt;br /&gt;With the above we have some control and some choices over how we secure ourselves. If you made the wrong choice and lose your money in the process, and if it was under your control, you will learn from your mistakes and be able to fix it and perform better.&lt;br /&gt;&lt;br /&gt;SMS is a different story. You can&amp;#39;t do anything about it. You can&amp;#39;t fix any mistakes. The only thing you learn is that SMS is a useless form of authentication and should be abandoned. You can only pray that the sender is the bank, it has traveled through only your provider, there is no one intercepting the SMS, no one sim swapped you and no one uses tools and software to pretend to be you. Also no app, be it any official app or some funny app you found on the internet, is reading your SMS or notifications (permissions can only help if there are no security holes in your OS and it is updated in security patches). I mean you can&amp;#39;t guarantee your Facebook app isn&amp;#39;t reading your SMS and notifications (for advertising purposes obviously) and that Facebook is the one leaking your OTP/TAC. It should only be used for emergencies and casual communication if you have no data for some reason. &lt;br /&gt;&lt;br /&gt;Even if you trust your bank that everything else is secure, their app, their service, their network, their infrastructure. In the end the SMS is the weak point. If you don&amp;#39;t trust them or if they messed up, move to another bank. Sue them. Report to BNM. Claim insurance. Users still have some control over that. Meanwhile SMS....did I need to repeat that? ZERO.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There is no TLDR. Security is important. Either read the whole thing and understand, or ignore it.</description>
            <author>thewan</author>
            <category>Kopitiam</category>
            <pubDate>Wed, 24 Aug 2022 00:32:12 +0800</pubDate>
        </item>
        <item>
            <title>Front page article inaccuracy</title>
            <link>http://forum.lowyat.net/topic/5226264</link>
            <description>I don&amp;#39;t use facebook, so I can&amp;#39;t comment on the article itself and decide to post here. I hope I&amp;#39;m not wrong in doing so.&lt;br /&gt;&lt;br /&gt;The article &lt;a href='https://www.lowyat.net/2021/261454/this-audiophile-grade-ssd-looks-too-good-to-be-true/' target='_blank'&gt;This “Audiophile Grade” SSD Looks Too Good To Be True&lt;/a&gt; contains a false statement that shows how lazy Malaysians have become in checking their own linked sources. It is one thing that this happens in forums/social media. But in this case this is an article/news piece by a reputable site like Lowyat.net. The following quote of the article is what I have issue with:&lt;br /&gt;&lt;!--QuoteBegin--&gt;&lt;div class='quotetop'&gt;QUOTE&lt;/div&gt;&lt;div class='quotemain'&gt;&lt;!--QuoteEBegin--&gt;At the time of writing, the original poster of the device said that they were already sampling drives to a select number of forum members, but a majority of them lost contact with the maker, almost immediately after receiving the product. &lt;!--QuoteEnd--&gt;&lt;/div&gt;&lt;!--QuoteEEnd--&gt;&lt;br /&gt;&lt;br /&gt;I have read the source of the above article, which originates from a forum thread &lt;a href='https://audiophilestyle.com/forums/topic/62753-nvme-ssd-designed-for-audiophiles/' target='_blank'&gt;here&lt;/a&gt;. As shown in the beginning of the thread, the discussion started around April of 2021. Your article mentions that they lost contact with the maker after receiving the product. However if you go to the latest page of the thread, you can see that the original poster who looks like is the representative of the product, is posting replies as recent as last Sunday (19th December 2021). There is no &amp;quot;lost of contact&amp;quot;. He is posting replies and acknowledging feedback. Your article is implying that the person is scamming his community by doing a &amp;quot;hit and run&amp;quot;. (Whether the product itself is a scam or not it doesn&amp;#39;t matter in this context). &lt;a href='https://audiophilestyle.com/forums/topic/62753-nvme-ssd-designed-for-audiophiles/?do=findComment&amp;comment=1173341' target='_blank'&gt;Link to latest post by author&lt;/a&gt; as of this post date.&lt;br /&gt;&lt;br /&gt;I&amp;#39;m not endorsing/protecting nor do I care about this product being snake oil or not. What I would like to highlight is the failure of even our local news sites reading their own sources before hastily posting articles. What if this was an article of a really important issue with our local community? Would you also give that article the same treatment of not checking your sources?.&lt;br /&gt;&lt;br /&gt;</description>
            <author>thewan</author>
            <category>Serious Kopitiam</category>
            <pubDate>Tue, 21 Dec 2021 15:05:23 +0800</pubDate>
        </item>
        <item>
            <title>Malicious Android app steals Malaysian bank info</title>
            <link>http://forum.lowyat.net/topic/5220647</link>
            <description>A fake Android app is masquerading as a housekeeping service to steal online banking credentials from the customers of eight Malaysian banks.&lt;br /&gt;&lt;br /&gt;The app is promoted through multiple fake or cloned websites and social media accounts to promote the malicious APK, &amp;#39;Cleaning Service Malaysia.&amp;#39;&lt;br /&gt;&lt;br /&gt;This app was first spotted by MalwareHunterTeam last week and was subsequently analyzed by researchers at Cyble, who provide detailed information on the app&amp;#39;s malicious behavior.&lt;br /&gt;&lt;br /&gt;&lt;!--QuoteBegin--&gt;&lt;div class='quotetop'&gt;QUOTE&lt;/div&gt;&lt;div class='quotemain'&gt;&lt;!--QuoteEBegin--&gt;&amp;quot;cleaningservicemalaysia.apk&amp;quot;: 7845bb247dbfad94018047afbb2f5e1d9e54752b620d995033c695d9a2d104a0 pic.twitter.com/wx6nM2GFdX&lt;br /&gt;&amp;nbsp; &amp;nbsp; — MalwareHunterTeam (@malwrhunterteam) November 25, 2021&lt;!--QuoteEnd--&gt;&lt;/div&gt;&lt;!--QuoteEEnd--&gt;&lt;br /&gt;&lt;br /&gt;Sos and more technical info:&lt;br /&gt;&lt;br /&gt;&lt;a href='https://www.bleepingcomputer.com/news/security/malicious-android-app-steals-malaysian-bank-credentials-mfa-codes/' target='_blank'&gt;https://www.bleepingcomputer.com/news/secur...ials-mfa-codes/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;But we Malaysians love SMS and despise app based MFA...and Security keys are too expensive for us, not to mention our banks don&amp;#39;t use them either. Oh well.&lt;br /&gt;&lt;br /&gt;</description>
            <author>thewan</author>
            <category>Kopitiam</category>
            <pubDate>Thu, 02 Dec 2021 03:26:45 +0800</pubDate>
        </item>
        <item>
            <title>[WTS] DeepCool Maelstrom 240t AIO Liquid Cooler</title>
            <link>http://forum.lowyat.net/topic/4521875</link>
            <description>&lt;b&gt;Item(s):&lt;/b&gt; DeepCool Maelstrom 240t AIO Liquid Cooler (AM4 Ready)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Package includes:&lt;/b&gt; Full package in the box&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Price:&lt;/b&gt; RM 220&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Warranty:&lt;/b&gt; 1 Month personal. Its a new cooler as replacement from DeepCool, RMA near the end of its warranty so no more warranty from DeepCool&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Dealing method:&lt;/b&gt; COD anywhere accessible in/around KL by train preferable. Postage maybe possible.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Location:&lt;/b&gt; Putrajaya&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Contact method/details:&lt;/b&gt; PM&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Item(s) conditions:&lt;/b&gt; Brand New inside box replacement from DeepCool for RMA.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Picture:&lt;/b&gt; Its in the box, PM if you want picture of the box. I can show you picture of the RMA receipt if required.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Reason for sale:&lt;/b&gt; Got a replacement cooler while waiting for RMA.&lt;br /&gt;&lt;br /&gt;&lt;a href='http://www.gamerstorm.com/product/CPULIQUIDCOOLER/2016-03/1286_4946.shtml' target='_blank'&gt;Website&lt;/a&gt;</description>
            <author>thewan</author>
            <category>Casings &amp;amp; PSUs Garage Sales</category>
            <pubDate>Sat, 10 Feb 2018 15:45:35 +0800</pubDate>
        </item>
        <item>
            <title>[WTS] Imported Calvin Klein Cortlandt Collection</title>
            <link>http://forum.lowyat.net/topic/4063464</link>
            <description>&lt;b&gt;Item(s):&lt;/b&gt; Imported Calvin Klein Cortlandt Collection 28&amp;quot; Spinner - Silver &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Package includes:&lt;/b&gt; Luggage (Silver Color)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Price:&lt;/b&gt; Now RM600.00 Negotiable. Reference price can be googled/checked below from amazon link. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Warranty:&lt;/b&gt; As provided by Calvin Klein. You may contact them on their FB/Twitter/email.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Dealing method:&lt;/b&gt; COD around KL, Putrajaya/Cyberjaya. Anywhere in between need to contact 1st. Shipping outside these areas via Poslaju&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Location:&lt;/b&gt; Putrajaya&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Contact method/details:&lt;/b&gt; PM Me or reply here.&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Item(s) conditions:&lt;/b&gt; Brand New, just arrived from USA via Fedex. Shipping box opened to inspect item but item not removed, item is still inside protective plastic.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Picture:&lt;/b&gt; [attachmentid=7596149][attachmentid=7596156][attachmentid=7596157] [attachmentid=7596184]&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Reason for sale:&lt;/b&gt; Extra, Realize don&amp;#39;t need it.&lt;br /&gt;&lt;br /&gt;You can see pictures on how the Luggage looks like from &lt;a href='https://www.amazon.com/Calvin-Klein-Cortlandt-Inch-Upright/dp/B00KTAG4WO?th=1' target='_blank'&gt;Amazon&lt;/a&gt;. Interested buyers may request for pictures of the luggage and I will PM them the pictures.</description>
            <author>thewan</author>
            <category>Garage Sales</category>
            <pubDate>Fri, 23 Sep 2016 22:14:20 +0800</pubDate>
        </item>
    </channel>
</rss>
