Live data from Hacker News

S. Korean Banks Fall Victim to Biggest Cyber Attack in Two Years

businessweek.com

21–29 of 29 posts

Re: S. Korean Banks Fall Victim to Biggest Cyber Attack in Two Years

#21
post #2

Do North Korea have the expertise to do such attack? It sounds to me more likely that supporters of North Korea did it (say groups inside China).

A large chunk of NK's income comes through a group called Room 39. They are the experts in Money Laundering, Drug trafficking and cyber warfare.. They also make the best fake dollars around, distributed using restaurant chain Pyongyang.

http://en.wikipedia.org/wiki/Room_39

http://en.wikipedia.org/wiki/Pyongyang_(restaurant_chain)

Re: S. Korean Banks Fall Victim to Biggest Cyber Attack in Two Years

#22
post #12
post #10

Bit confused.. "A possible cyber attack temporarily shut down computer networks" ... "Operations at the two banks were back to normal later in the afternoon and it was still unclear what caused the disruptions" So it might have been a cyber attack. It might not. "President Park Geun Hye’s administration created a cyber crisis headquarters to investigate whether North Korea is behind the outages" I would have thought…

Because this is exactly the scenario that plays out every time North Korea "attacks" South Korea. No one ever owns it, just like with the submarine http://www.bbc.co.uk/news/10129703 . It's an "accident" or it's inconclusive. Also, neither side wants to conclusively blame the other, because hey, they're still at odds. Stepping a single foot into the DMZ without permission can get you shot at. SK is probably trying to…

I would think it has little to do with the benefit of the doubt and everything to do with retaliation and escalation.

If the South found that the North definitely sunk a South submarine, the people would (more loudly) call for retaliation. And while everyone is certain what that would lead to, no-one's quite sure where it would end and no-one doubts that the losses for all involved will massively dwarf the loss of a single ship.

And there's always the possibility that the South really was in the wrong. That their ship had violated an agreement by doing something they'd rather not publicize.

(Not unlike the subdued US reaction to the EP3/Mig-21 collision in 2001. Were the US 'innocent' the rhetoric would have sounded much different than it did. But even then, the risks of escalation far outweigh the losses at hand.)

Re: S. Korean Banks Fall Victim to Biggest Cyber Attack in Two Years

#24
post #17

Expect more of the same from South Korea in the weeks, months, and (unfortunately) years to come. These massive attacks have been happening for many years now, and nobody seems to have learned a thing. The latest news here in Korea says that bank employees' PCs were infected through a compromised third-party package management system. Only two years ago, 35 million accounts at one of South Korea's most popular social…

A year ago we looked into how feasible it would be to expand operations of our company beyond the US. Because we have a Korean-born Korean as a core team member, it was placed very high on the list of countries to explore. That spot lasted about fifteen minutes. By law in South Korea, you have to use an ActiveX plugin (and therefore IE) to process eCommerce transactions [1].

Looking it up just now to see what has changed in six months, I see that it's not strictly true anymore. The official policy allows for other browsers, but none of the steps necessary to allow those browsers have occurred.

[1] http://gadgets.ndtv.com/internet/news/how-south-korea-became...

Re: S. Korean Banks Fall Victim to Biggest Cyber Attack in Two Years

#25
post #17

Expect more of the same from South Korea in the weeks, months, and (unfortunately) years to come. These massive attacks have been happening for many years now, and nobody seems to have learned a thing. The latest news here in Korea says that bank employees' PCs were infected through a compromised third-party package management system. Only two years ago, 35 million accounts at one of South Korea's most popular social…

the attackers broke into the update servers of a popular antivirus software, which was used on employees' PCs.

Are you referring to Ahnlab?

I'm convinced that Ahnlab's virus scanner software is itself a form of spyware. Wouldn't surprise me at all if it has been used as an attack vector.

Re: S. Korean Banks Fall Victim to Biggest Cyber Attack in Two Years

#27
post #25
post #17

Expect more of the same from South Korea in the weeks, months, and (unfortunately) years to come. These massive attacks have been happening for many years now, and nobody seems to have learned a thing. The latest news here in Korea says that bank employees' PCs were infected through a compromised third-party package management system. Only two years ago, 35 million accounts at one of South Korea's most popular social…

the attackers broke into the update servers of a popular antivirus software, which was used on employees' PCs. Are you referring to Ahnlab? I'm convinced that Ahnlab's virus scanner software is itself a form of spyware. Wouldn't surprise me at all if it has been used as an attack vector.

No, I'm referring to the Nate/Cyworld incident, in which an update to the Alyak (알약) antivirus program, developed by ESTsoft, was regarded as a prime suspect. Alyak is extremely popular in Korea, due to the fact that it is free and comes bundled with Alzip (알집), a popular compression utility. IMO the entire Altools (알툴즈) family of programs is utter shit. Their entire domain is blacklisted in every PC I manage.

Ahnlab is a much more respectable company, and I have yet to hear of a major security incident where Ahnlab software was implicated. Their V3 line of software are clearly not the best in the industry, but I would be very surprised if they were any worse than other antiviruses.

Edit: According to the latest news, today's malware was disguised as a component of an antivirus program sold by Hauri, Inc. (하우리)

Re: S. Korean Banks Fall Victim to Biggest Cyber Attack in Two Years

#28
post #24
post #17

Expect more of the same from South Korea in the weeks, months, and (unfortunately) years to come. These massive attacks have been happening for many years now, and nobody seems to have learned a thing. The latest news here in Korea says that bank employees' PCs were infected through a compromised third-party package management system. Only two years ago, 35 million accounts at one of South Korea's most popular social…

A year ago we looked into how feasible it would be to expand operations of our company beyond the US. Because we have a Korean-born Korean as a core team member, it was placed very high on the list of countries to explore. That spot lasted about fifteen minutes. By law in South Korea, you have to use an ActiveX plugin (and therefore IE) to process eCommerce transactions [1]. Looking it up just now to see what has cha…

Yep, the official policy now allows for other browsers, and even encourages banks to implement web standards. But nobody is willing to implement the software that is necessary to port the current public key infrastructure to non-Windows, non-IE platforms, simply because there is not much money to be made. Some of the large banks have come up with half-baked cross-platform services to appeal to rich kids with Macs, but payment gateways have not changed at all.

Only geeks use Chrome here, and I'm probably the only person in my town who uses Firefox. Mobile, of course, is a very large market, but banks just write their own Android & iOS apps and call it a day.

Re: S. Korean Banks Fall Victim to Biggest Cyber Attack in Two Years

#29
post #28
post #24

Earlier quoted context omitted.

A year ago we looked into how feasible it would be to expand operations of our company beyond the US. Because we have a Korean-born Korean as a core team member, it was placed very high on the list of countries to explore. That spot lasted about fifteen minutes. By law in South Korea, you have to use an ActiveX plugin (and therefore IE) to process eCommerce transactions [1]. Looking it up just now to see what has cha…

Yep, the official policy now allows for other browsers, and even encourages banks to implement web standards. But nobody is willing to implement the software that is necessary to port the current public key infrastructure to non-Windows, non-IE platforms, simply because there is not much money to be made. Some of the large banks have come up with half-baked cross-platform services to appeal to rich kids with Macs, bu…

Oh well, another country where it is a matter of (little) time until visa/mastercard/16 digit number cards breaks through.

I don't understand these people's reasoning. Relentless innovation is how you become and stay the best. Kicking down the competition, secure in your market position is how you die. It may take a bitcoin, but sooner or later these companies are doomed.

Post reply on HN