Live data from Hacker News

South Korean telecom company attacks torrent users with malware

tomshardware.com

21–30 of 158 posts

Re: South Korean telecom company attacks torrent users with malware

#21
post #10

South Korean internet had been one of the best and fast network in the world; especially up to the point before KT was privatized. After privatization, three internet service providers have been focusing on exploiting profits, not on making better and faster network infrastructure because they don't have to.

wouldnt competition naturally produce better products if there are 3 providers? from what i remember services from companies, or really any type of services were top notch in korea. due to culture, competition, etc. also noting pricing in general is very high in korea

There's no economic motivation to compete. The motivation is to raise prices slightly, wait for the other two companies to follow suit as a signal, then to raise prices again. If you raise and someone doesn't follow, backtrack to the previous level. This is assuming that they don't just have a meeting and set prices over drinks.

Re: South Korean telecom company attacks torrent users with malware

#22

>Police officials acted on the information and discovered it came from KT’s own data center south of Seoul. ... They’ve since identified and charged 13 individuals, including KT employees and subcontractors directly connected to the malware attack last November,... I'm actually very impressed. If this happened in the US, the police wouldn't care about it at all, and would just tell everyone affected that "it's a civi…

This makes sense because the US does not have a set of laws that criminalize Computer Fraud and Abuse

Maybe you're joking, but they certainly do. They'll happily use them against individuals too.

But against a large company? I'll believe it when I see it.

Re: South Korean telecom company attacks torrent users with malware

#23

>Police officials acted on the information and discovered it came from KT’s own data center south of Seoul. ... They’ve since identified and charged 13 individuals, including KT employees and subcontractors directly connected to the malware attack last November,... I'm actually very impressed. If this happened in the US, the police wouldn't care about it at all, and would just tell everyone affected that "it's a civi…

This makes sense because the US does not have a set of laws that criminalize Computer Fraud and Abuse

Selective enforcement of broad-scoped laws via prosecutorial discretion is how real power works and how the status quo is maintained.

Re: South Korean telecom company attacks torrent users with malware

#24

>Police officials acted on the information and discovered it came from KT’s own data center south of Seoul. ... They’ve since identified and charged 13 individuals, including KT employees and subcontractors directly connected to the malware attack last November,... I'm actually very impressed. If this happened in the US, the police wouldn't care about it at all, and would just tell everyone affected that "it's a civi…

I think you're too optimistic. My reading is that the police is investigating low-level employees and subcontractors. I.e., profit for the corporation, consequence for the employees. And especially subcontractors. (Workplace discrimination against subcontractors has been a hot topic in Korea: subcontractors literally die in factories because they're pushed to handle dangerous tasks while "regular employees" get cushy desk jobs.)

Re: South Korean telecom company attacks torrent users with malware

#25
post #7
post #2

Unsurprisingly, terrible Korean internet strikes again. ISPs try to charge companies insane fees because customers want to connect to their servers. Company decides to use peer-ro-peer instead so the ISP starts installing spyware on customer computers. Makes me wonder where this myth of "good Korean internet" even came from if everything ends up so bandwidth constrained. Is it because all the customers and services a…

Another memory from the terrible South Korean Internet is how the national banks required customers to log in using Internet Explorer because of mandatory ActiveX blobs of code.

They have such weird constraints. Even Coupang Play refuses to load their video when I'm on Linux, which makes no sense at all.

Re: South Korean telecom company attacks torrent users with malware

#26
post #5

Earlier quoted context omitted.

Bittorrent normally hash checks all content against metadata in the torrent file so a simple MITM wouldn't be enough to inject malicious data unless the torrent metadata itself is being sent in the clear.

I had the same thought, i'm very confused about the details of the attacks. As an ISP if they detect you doing it, and they control DNS servers, maybe they mark your account for death, and they could like randomly hijack you going to google.com to some download for malware, and unsuspecting user clicks accept? Not sure, i'm curious how they pulled this off.

Any http exe-file download could be hijacked if you are an ISP. Maybe KT have some "dailup login" app the user needs to login with?

Re: South Korean telecom company attacks torrent users with malware

#27
post #2

Unsurprisingly, terrible Korean internet strikes again. ISPs try to charge companies insane fees because customers want to connect to their servers. Company decides to use peer-ro-peer instead so the ISP starts installing spyware on customer computers. Makes me wonder where this myth of "good Korean internet" even came from if everything ends up so bandwidth constrained. Is it because all the customers and services a…

How is this not criminal?

Re: South Korean telecom company attacks torrent users with malware

#28

Unfortunately, it's not explained in the article how the malware was actually sent to users. I wonder how they did it.

I reckon they used a good old fashioned honeypot. Seed a torrent of some random popular content that also contains malware payload, and let users download it.

Re: South Korean telecom company attacks torrent users with malware

#29

Earlier quoted context omitted.

This makes sense because the US does not have a set of laws that criminalize Computer Fraud and Abuse

Maybe you're joking, but they certainly do. They'll happily use them against individuals too. But against a large company? I'll believe it when I see it.

The US law about this is the Computer Fraud and Abuse Act, it's clearly a joke. We're all in agreement it's not really used against large companies.

Re: South Korean telecom company attacks torrent users with malware

#30

Earlier quoted context omitted.

This makes sense because the US does not have a set of laws that criminalize Computer Fraud and Abuse

Maybe you're joking, but they certainly do. They'll happily use them against individuals too. But against a large company? I'll believe it when I see it.

[flagged]
Post reply on HN