Live data from Hacker News

TouchEn nxKey: A keylogging anti-keylogger solution

palant.info

31–40 of 60 posts

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#31
post #28

> The real number of users is likely considerably higher, the software being installed on pretty much any computer in South Korea. This is a bit of an exaggeration. Plenty of young people hate this stuff enough that they do all of their banking through their phone and if they absolutely must do it on a pc, they either use an old disused laptop, do it at work, do it at an internet cafe (not that those don't bring risk…

> or make sure to remove the spyware the second they've completed the task at hand. Yup. The problem is that those spywares are not cleanly uninstalled and leave junks on the disk. Some independent developers even created a dedicated tool for removing those "security" software to solve the problem.

Like you're saying, there's tools for that. Google autocompletes "은행 설치" (bank installation) to "은행 설치 프로그램 삭제" (bank installed programs removal) and the very first link immediately is the homepage of the tool you're talking about, so it doesn't require much inside knowledge to use. Of course the majority of people doesn't bother with this but quite a lot of people do. Even if many of those do so for non-security reasons, e.g. gamers who are afraid the crapware will slow their computer down.

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#32
post #18

Between this and https://en.wikipedia.org/wiki/Shutdown_law South Korea sounds like pretty oppressive country to live in.

Like Japan, it's a "one and a half party state"; while there are multiple parties and free elections, in practice one party wins a majority almost all the time and there's very little space for diverse viewpoints.

What is it that causes countries to become like this?

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#33
post #4

I will bring this up the next time, someone laments about the lack of digitalization compared to other nations.

Not a great example since this really is purely a Korean thing not seen elsewhere. Afaik Brazil had similar issues for very long but they've finally been fixed in the last few years (maybe a Brazil-based user can chime in).

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#34
post #28

> The real number of users is likely considerably higher, the software being installed on pretty much any computer in South Korea. This is a bit of an exaggeration. Plenty of young people hate this stuff enough that they do all of their banking through their phone and if they absolutely must do it on a pc, they either use an old disused laptop, do it at work, do it at an internet cafe (not that those don't bring risk…

Disclaimer: I am the author of this article.

I wrote this sentence three months ago. Since then people already pointed out that mobile banking is being used as escape hatch. The question is still: how many people do this? Everyone younger than 30? Or only 80% of them? Or only people who are moderately tech-savvy?

Are there any reliable statistics on that?

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#35
post #34
post #28

> The real number of users is likely considerably higher, the software being installed on pretty much any computer in South Korea. This is a bit of an exaggeration. Plenty of young people hate this stuff enough that they do all of their banking through their phone and if they absolutely must do it on a pc, they either use an old disused laptop, do it at work, do it at an internet cafe (not that those don't bring risk…

Disclaimer : I am the author of this article. I wrote this sentence three months ago. Since then people already pointed out that mobile banking is being used as escape hatch. The question is still: how many people do this? Everyone younger than 30? Or only 80% of them? Or only people who are moderately tech-savvy? Are there any reliable statistics on that?

Not a real statistic, but everyone I know in South Korea use their phones for personal banking. Especially people who aren't tech-savvy.

At first it might have been because mobile apps were easier to use than the crap they had to go through on a PC. Nowadays, though, there is no need to compare because mobile is the default choice anyway. Younger people don't even bother trying it on a PC. Older people, on the other hand, skipped the PC era altogether and went straight to smartphones. I don't think my mother has ever done any banking on a PC, but she has a bank app on her phone.

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#36
post #35
post #34

Earlier quoted context omitted.

Disclaimer : I am the author of this article. I wrote this sentence three months ago. Since then people already pointed out that mobile banking is being used as escape hatch. The question is still: how many people do this? Everyone younger than 30? Or only 80% of them? Or only people who are moderately tech-savvy? Are there any reliable statistics on that?

Not a real statistic, but everyone I know in South Korea use their phones for personal banking. Especially people who aren't tech-savvy. At first it might have been because mobile apps were easier to use than the crap they had to go through on a PC. Nowadays, though, there is no need to compare because mobile is the default choice anyway. Younger people don't even bother trying it on a PC. Older people, on the other…

Yes, statistically speaking “everyone I know” is unfortunately not a good sample. :-)

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#38

@palant: Probably just some minor temporary weirdness but > Host palant.info not found: 3(NXDOMAIN)

$ dig @8.8.8.8 palant.info [...] palant.info. 1800 IN A 94.130.151.233 [...]

https to that IP works (after ignoring the stern warnings) so maybe the phenomenon is limited to my ISP in Germany or some of their DNS servers.

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#39
post #28

> The real number of users is likely considerably higher, the software being installed on pretty much any computer in South Korea. This is a bit of an exaggeration. Plenty of young people hate this stuff enough that they do all of their banking through their phone and if they absolutely must do it on a pc, they either use an old disused laptop, do it at work, do it at an internet cafe (not that those don't bring risk…

This is also used by some payment processors (probably belongs to banks).

I can relate as I was in Korea some months ago and in order to buy some concert tickets the platform required me to install that shitty thing. I end up not buying the tickets as it was not possible to me to install anything in my corporate machine.

As you said, my friend point out people don't have it installed in their personal computers but use a third party one which brings more insecurity.

Re: TouchEn nxKey: A keylogging anti-keylogger solution

#40
A bit more context for people who don’t live in South Korea (I’m a South Korean):

Everybody knows that the systems are absurd. Most newer systems don’t require the use of such anti-keylogger programs. This is basically a countrywide legacy that we’re figuring our way out for ~30yrs.

This started in the 90s where South Korea got high speed internet everywhere, and people demanded internet banking… when IE didn’t ship 128-bit AES support due to export laws.

The South Korean govt submitted a law to enforce encryption for such services (i.e. an custom algorithm called SEED and 128-bit or higher keys were required), and without IE support, these encryption were developed in ActiveX. (For who don’t know, it was a COM-based solution to load native code from IE.) Laws and protocols are sticky, and even after IE shipped better encryption, these stayed.

When the anti-keylogger idea was first proposed, it was simple: the anti-keylogger could ship with the encryption support. It was when IE didn’t have a yes/no dialog to ask whether to load native code or not; everything felt easy, and at that point everybody got locked into this legacy mess where nobody could use different browsers other than IE.

When IE added confirmation dialogs, banks instructed customers to press yes. When IE deprecated ActiveX, banks didn’t remove their 20-yr old code straight away; people were advised to turn on ActiveX support from advanced settings (they added step-by-step instructions to help people), and when MS finally ripped out ActiveX, banks just copied their ActiveX components into a separate executable that runs a localhost server. (And that explains the hastily coded JSON support, the never-updated libraries, and so on that the article shows.)

Every time MS tried making running untrusted native code harder, the banks and customers got used to it… until it became acceptable to install 2~3 different executables for each bank, each running a server on a different port.

Thanks to smartphones, newer solutions now develop all of the encryption code in JS, and the legacy now runs in JS without native code. Still legacy, but it’s been much better for the last 5yrs.

Post reply on HN