{"id":258,"date":"2008-02-10T20:22:37","date_gmt":"2008-02-10T12:22:37","guid":{"rendered":"http:\/\/wp.jiinjoo.com\/?p=258"},"modified":"2008-02-10T20:22:37","modified_gmt":"2008-02-10T12:22:37","slug":"maybank-common-login-service-2-banks-1-name","status":"publish","type":"post","link":"https:\/\/wp.jiinjoo.com\/?p=258","title":{"rendered":"Maybank Common Login Service &#8211; 2 Banks, 1 Name"},"content":{"rendered":"<p>Yes I did it!<\/p>\n<p>I finally got the common login service working!<\/p>\n<p>Thanks to the nice branch lady in Damansara Jaya branch who was patient with my convoluted request (ugh forgot name liao&#8230;). The availability of this service turns out to be one of the most complicated application process I&#8217;ve go through.<\/p>\n<div style=\"float: right; padding: 2px 0px 2px 5px;\"><img decoding=\"async\" src=\"http:\/\/www.maybank.com.sg\/images\/mb2u_logo.gif\" alt=\"Maybank Logo\" border=\"0\" \/><\/div>\n<p>There are a potential market of 1 million people like me, Malaysia, work in Singapore, remits money back. Maybank is one of those banks who came and say &#8211; hey, you can hold a Maybank Malaysia account and still do internet banking friom Singapore in you have a Maybank Singapore account. Turns out that these two Maybanks are so autonomous, that operationally they are completely separated. Someone actually had to build a authentication broker between them to enable such a service.<\/p>\n<p>And thus the complicated thing began. I opened a Maybank Malaysia account several months ago, then when I came back to SG, I opened a Maybank Singapore account. That was the easy part, except the fact that I couldn&#8217;t get a hand phone number registered in Malaysia (the number of boxes in the form couldn&#8217;t fit +65) for OTP &#8211; One Time Password. They gave me a fall back &#8211; use the phone banking facility to call a 03 (Selangor &#8211; not toll free) number to get OTP. Fine. After that, following a number of instructions on the Maybank Malaysia website I arrived on Maybank Singapore&#8217;s website, asking me to submit some weird form for application to this common login service.<\/p>\n<p>Fine, fill in all sorts of funny detail submit. Waited for 3 months (they say wait till customer service get back) &#8211; in fact totally forgot about it. Then one fine day, realize that they haven&#8217;t come back to me, I try the same process again. The screen looks slightly different (requesting an extra OTP step) but nevertheless the eventual &#8220;wait for customer service to call&#8221; is the same.<\/p>\n<p>Voila!~ They called back the next day. The cheerful guy said: &#8220;Me from Maybank Singapore, your Maybank Malaysia account got problem.&#8221; Right &#8211; and what kind of problem? &#8220;No idea, you ask Maybank Malaysia.&#8221; Right &#8211; you&#8217;re both Maybanks and all you get is a generic error status from the other side?<\/p>\n<p>Fine, it&#8217;s almost Chinese New Year, knowing that phone customer service is going to cost a bomb calling from Singapore, so I decided to go home. Visited the branch and luckily I found someone who understands the problem (after talking to a few). The lady got in touch with the main support team and found out that: <em>My Maybank Malaysia Internet Banking has been deactivated<\/em>.<\/p>\n<p>Ah that&#8217;s nonsense! I couldn&#8217;t get my handphone registered in the first place &#8211; because it&#8217;s a Singapore number (with a phone banking fall back). That&#8217;s why there&#8217;s no activities for 3 months! And now they tell me that I gotta login to Maybank Malaysia (maybank2u.com.my) every 2 to 3 months to &#8220;prevent that from happening&#8221;. Alamak bullshit! This is just an account for remitting money that will be useful maybe once every 6 to 12 months &#8211; for what I login every 2 to 3 months?<\/p>\n<p>Nvm, cancel the Internet banking and reapply from the ATM. Done. Went home, go through the same process again (apply from Maybank Singapore) and wala! Service is off at night! ARGH &#8211; where got Internet Banking turn off after midnight one&#8230; People who rely on Internet Banking is precisely because their lives are so busy that they can&#8217;t go figure out all these chores in the day. They only logon when they are home and done with the day&#8217;s job. Nvm, \u5fcd.<\/p>\n<div style=\"float: left; padding: 2px 5px 2px 0px;\"><img decoding=\"async\" id=\"image257\" src=\"http:\/\/wp.jiinjoo.com\/wp-content\/uploads\/2008\/02\/sg-pj.JPG\" alt=\"sg-pj.JPG\" border=\"0\" \/><\/div>\n<p>After a long and arduous drive back to SG, I quickly make use of the available time before dinner to go through the process: Login on SG, confirm with an OTP, click on MY, request another OTP, get a Confirmation Code, login to MY, request another OTP, click enable the common login service. And even as I became an expert at this process, I have to give it 2 or 3 go, because the OTP and confirmation code step doesn&#8217;t seem to agree (maybe the OTP propagation from one bank to another is slower than my typing &#8211; the nuance is needed from one end to agree with the other).<\/p>\n<p>Now I can just login to one side, and see the other side.<\/p>\n<p>Coming from a system architecture perspective, I thought this is one of the most ridiculous cross authentication ever designed. It&#8217;s not that it&#8217;s &#8220;wrong&#8221;, OTPs for 2FA (2 factor authentication), and passing of nuance from system A to system B etc. are all &#8220;correctly&#8221; designed, but the definition of the &#8220;system&#8221; is totally wrong &#8211; to be including the customer in the picture.<\/p>\n<p>The main problem stems from a lack of a central authority, and common 3rd party that they trust &#8211; so they end up trusting the customer as the resource to pass information back and forth. After all, it&#8217;s the customer&#8217;s account right? If they can&#8217;t pass it back properly, or their phone was hijacked by another person, the bank can&#8217;t be held liable at that point right? Oh ya &#8211; that dreaded OTP is a requirement in S&#8217;pore but not in M&#8217;sia, but the dongle thing doesn&#8217;t exists in M&#8217;sia &#8211; what a perfect chance to confuse people even more!<\/p>\n<p>What would have been a cleaner process and easier process is to make one side the &#8220;authority&#8221;. A simple gesture like, fill up the form after logging in to Malaysia side (since there&#8217;s no OTP), and &#8220;agree&#8221; with a single OTP from Singapore side, or just logging in to Singapore side normally and clicking on a &#8220;I agree&#8221; link. The respective authentication process and mutual trust should be handled in the backend. Human beings should also be cut out of the registration process &#8211; totally redundant! Unless you&#8217;re telling me that you do background checks on the accounts (Whoa, too much money this guy, cannot let him move money out of SG&#8230;)<\/p>\n<p>Anyway, I believe all these &#8220;can be better&#8221; suggestions are ultimately business decisions. Just keep the customer service quality that I&#8217;m experiencing and I&#8217;ll still be a happy money launderer, powered by 2 Maybanks. Muahahahaha&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yes I did it! I finally got the common login service working! Thanks to the nice branch lady&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,2],"tags":[],"class_list":["post-258","post","type-post","status-publish","format-standard","hentry","category-malaysia","category-technology","content-wrap"],"_links":{"self":[{"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=\/wp\/v2\/posts\/258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=258"}],"version-history":[{"count":0,"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=\/wp\/v2\/posts\/258\/revisions"}],"wp:attachment":[{"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.jiinjoo.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}