Live data from Hacker News

South Korea’s online security dead end

palant.info

11–20 of 144 posts

Re: South Korea’s online security dead end

#11
This mirrors the situation in China, likely for similar reasons.

To this day, I can only do online banking with Internet Explorer 11. When logging in, of course the password field doesn't permit pasting. I have a couple ActiveX controls and certs installed, but I've forgotten which ones so I'll just have to keep that old laptop around. The one bright spot is that large transactions do require a USB dongle.

At least one other website I've used (perhaps Alipay?) required you to install a browser plugin simply to be able to "securely" enter your PIN.

Rewinding back to 2014, the brand new government website for buying train tickets[0] didn't have an SSL cert signed by any of the trusted authorities. If you wanted to buy tickets securely, you needed to download a zip file (over http) that contained 1) a self-signed root cert, and 2) a Microsoft Word document explaining how to add this to your OS's trusted root cert store and how this is totally legit and secure.

[0] https://www.techinasia.com/chinas-official-train-ticket-site...

Re: South Korea’s online security dead end

#12
This always bothered the hell out of me when interacting with Korean websites, especially online banking. I believe in addition to the factors that the article listed, there are several laws in place that mandate this chicanery, at least for banking.

Re: South Korea’s online security dead end

#13

This mirrors the situation in China, likely for similar reasons. To this day, I can only do online banking with Internet Explorer 11. When logging in, of course the password field doesn't permit pasting. I have a couple ActiveX controls and certs installed, but I've forgotten which ones so I'll just have to keep that old laptop around. The one bright spot is that large transactions do require a USB dongle. At least o…

> At least one other website I've used (perhaps Alipay?) required you to install a browser plugin simply to be able to "securely" enter your PIN.

Straight-up government malware right there.

Re: South Korea’s online security dead end

#14
post #3

Overall an interesting post, thanks for sharing. Nitpick for OP (@palant): on mobile Safari (haven't checked any desktop browsers), the images embedded into the post appear stretched out vertically (i.e., too "slim"). It is still technically readable, but very noticeable and jarring. This only applies to the images when embedded, opening direct image URLs in a dedicated browser tab renders them properly without any s…

[deleted]

Re: South Korea’s online security dead end

#15

This mirrors the situation in China, likely for similar reasons. To this day, I can only do online banking with Internet Explorer 11. When logging in, of course the password field doesn't permit pasting. I have a couple ActiveX controls and certs installed, but I've forgotten which ones so I'll just have to keep that old laptop around. The one bright spot is that large transactions do require a USB dongle. At least o…

[deleted]

Re: South Korea’s online security dead end

#16
post #10
post #9

Very interesting read. I'm looking forward to the details in the followups (1/9, 1/23, 3/6). However, I'm surprised that there are no KR banks who build their reputation on their technical acuity and who have eliminated (or avoided) reliance on these types of applications. The markets I'm familiar with tend to have a few banks who have a reputation for good websites, good apps, etc. Or perhaps that bit of context was…

Disclaimer : I am the author of this article. I think that this issue is really universal across all banks in Korea. I was told (but couldn’t confirm) that this is a liability question. Supposedly, there was a court ruling that held a bank liable for a customer’s losses due to lack of security precautions. So now all of them implement “security precautions” to avoid liability. Thank you for the hint, I fixed the typo…

Thanks for the writeup.

Do you think getting out of this mess could be as simple as government regulationL: banking (and government and other necessary websites) are not allowed to require installation of plugins or other software to log in.

Re: South Korea’s online security dead end

#17
post #16
post #10

Earlier quoted context omitted.

Disclaimer : I am the author of this article. I think that this issue is really universal across all banks in Korea. I was told (but couldn’t confirm) that this is a liability question. Supposedly, there was a court ruling that held a bank liable for a customer’s losses due to lack of security precautions. So now all of them implement “security precautions” to avoid liability. Thank you for the hint, I fixed the typo…

Thanks for the writeup. Do you think getting out of this mess could be as simple as government regulationL: banking (and government and other necessary websites) are not allowed to require installation of plugins or other software to log in.

That’s in fact what I suggest in my blog post. But I am pretty certain that it is far from simple. I’m told that the previous Korean government already tried to tackle this issue and failed. It’s a huge and complicated mess.

Re: South Korea’s online security dead end

#18
post #10
post #9

Very interesting read. I'm looking forward to the details in the followups (1/9, 1/23, 3/6). However, I'm surprised that there are no KR banks who build their reputation on their technical acuity and who have eliminated (or avoided) reliance on these types of applications. The markets I'm familiar with tend to have a few banks who have a reputation for good websites, good apps, etc. Or perhaps that bit of context was…

Disclaimer : I am the author of this article. I think that this issue is really universal across all banks in Korea. I was told (but couldn’t confirm) that this is a liability question. Supposedly, there was a court ruling that held a bank liable for a customer’s losses due to lack of security precautions. So now all of them implement “security precautions” to avoid liability. Thank you for the hint, I fixed the typo…

aside: I think the year on the dates is wrong :)

Re: South Korea’s online security dead end

#19
post #9

Very interesting read. I'm looking forward to the details in the followups (1/9, 1/23, 3/6). However, I'm surprised that there are no KR banks who build their reputation on their technical acuity and who have eliminated (or avoided) reliance on these types of applications. The markets I'm familiar with tend to have a few banks who have a reputation for good websites, good apps, etc. Or perhaps that bit of context was…

Are there any US banks that are actually secure? AFAIK they're all using SMS 2FA or worse.

Re: South Korea’s online security dead end

#20
This reminds me of krebsonsecurity's experience attempting to contact the FSB.

https://krebsonsecurity.com/2021/06/adventures-in-contacting...

A lot of countries seemingly did not have access to American encryption technologies or did not trust them — arguably for good reasons[0] — which has lead to this hodge-podge of homegrown security.

[0] https://www.washingtonpost.com/graphics/2020/world/national-...

Post reply on HN