Live data from Hacker News

South Korea’s online security dead end

palant.info

121–130 of 144 posts

Re: South Korea’s online security dead end

#121
post #105

Earlier quoted context omitted.

In court, you bring in experts (usually professors from reputable universities) to state best practices. Judges don't act as experts in a trial.

That is also how the legislative process works, and is likely how the Koreans got in to this mess in the first place. Experts at the time identified IE6 and ActiveX as dominating the market and standardised on them^. If the web had converged on IE and ActiveX it wouldn't look as stupid as it does now. Back at the time it was arguably clever, it only looked ill-advised if you were a free-market thinker. ^ The cynic in…

this is an excellent point

i had not thought of this

Re: South Korea’s online security dead end

#122
post #85

Earlier quoted context omitted.

the clueless regulation is the problem, not capitalism once you're competing by lobbying for regulation what you're doing isn't capitalism anymore

So the US isn't doing capitalism anymore? If your system is based on the idea that "those with more money have more power", then those people using that power to stop competitors sounds like an entirely logical outcome to me. "Doing capitalism" means running your company with profit as your goal, and if the best way to profit is lying, bribing, preventing competition, exploiting workers and destroying the environment…

nobody has ever done pure capitalism; social systems are always a messy mix of modalities

but some societies are more capitalist than others, like those where markets rather than regulators make collective choices, and those tend to be the more prosperous and competent societies

'running your company with profit as your goal' predates capitalism by several millennia, and for that reason among others it is totally inadequate as a definition of capitalism

quoting wikipedia:

Capitalism is an economic system based on the private ownership of the means of production and their operation for profit.[1][2][3][4] Central characteristics of capitalism include capital accumulation, competitive markets, price system, private property, property rights recognition, voluntary exchange, and wage labor.[5][6] In a market economy, decision-making and investments are determined by owners of wealth, property, or ability to maneuver capital or production ability in capital and financial markets—whereas prices and the distribution of goods and services are mainly determined by competition in goods and services markets.

market competition is fundamental to capitalism. calling a competition-prohibiting government decree like this 'capitalist' because private companies presumably lobbied for it last millennium is like calling iran or venezuela today 'democratic' because their dictatorships were voted in by their citizens many years ago

you say, 'capitalism [can] be, to some extent, prevented from doing those harms by strong regulation' but in fact in this case the strong regulation is what is doing the harm, not whatever vestiges of capitalism remain after the regulators removed competitive markets, voluntary exchange, price signals, and private-sector decision-making

Re: South Korea’s online security dead end

#123
post #118
post #35

Earlier quoted context omitted.

this is a cautionary tale for people who hope that government regulation will solve the current computer security disaster outside korea you cannot solve problems by giving authority to people who are motivated to solve them, but do not understand what the problem is, so that they can tell the people who do understand the problem what to do anyone who has dealt with pci-dss presumably knows this but that is a much sm…

> think of that the next time someone contrasts bitcoin with the heavily regulated conventional banking system Just watching the largest fraud trial in history unfold over at FTX. Bitcoin deals with any and all questions of fraud by dumping them on the victim. No help and no recourse. Very libertarian, but of course routinely results in people losing life changing amounts of money.

there have been plenty of larger frauds and outright thefts in history (i'd point at our own sovereign default and mass confiscation of dollar bank accounts, respectively, in 02001), but the culprits were never brought to trial because they were the government

Re: South Korea’s online security dead end

#124
post #123
post #118

Earlier quoted context omitted.

> think of that the next time someone contrasts bitcoin with the heavily regulated conventional banking system Just watching the largest fraud trial in history unfold over at FTX. Bitcoin deals with any and all questions of fraud by dumping them on the victim. No help and no recourse. Very libertarian, but of course routinely results in people losing life changing amounts of money.

there have been plenty of larger frauds and outright thefts in history (i'd point at our own sovereign default and mass confiscation of dollar bank accounts, respectively, in 02001), but the culprits were never brought to trial because they were the government

> mass confiscation of dollar bank accounts, respectively, in 2001

Argentina?

Re: South Korea’s online security dead end

#125
post #124
post #123

Earlier quoted context omitted.

there have been plenty of larger frauds and outright thefts in history (i'd point at our own sovereign default and mass confiscation of dollar bank accounts, respectively, in 02001), but the culprits were never brought to trial because they were the government

> mass confiscation of dollar bank accounts, respectively, in 2001 Argentina?

yup

Re: South Korea’s online security dead end

#126
post #37

Earlier quoted context omitted.

There's a curious absence of Korean banking apps on this GrapheneOS compatibility list: https://privsec.dev/posts/android/banking-applications-compa... Does it mean none are usable on a modern clean Android? Or is there a total Samsung monoculture? Something else?

Korean banking apps usually are disabled in rooted Android, probably because in rooted Android the integrity of the binary cannot be verified.

Which is funny because rooted android users can easily make any app believe it isn't rooted. Had to do that recently with the French identity app.

Re: South Korea’s online security dead end

#127
post #29

Oh boy... Once I saw this: >This starts with a simple fact: some of these applications are written in the C programming language, not even C++. I had to stop reading and come here to see if anyone else got annoyed by it. Seriously? "not even c++" are we still in 1990s?

> are we still in 1990s?

I wouldn't be surprised if a lot of this was written in the 90s or early 00s originally, and then "minimally maintained" only when required.

Re: South Korea’s online security dead end

#128
post #95

This mirrors the situation in China, likely for similar reasons. To this day, I can only do online banking with Internet Explorer 11. When logging in, of course the password field doesn't permit pasting. I have a couple ActiveX controls and certs installed, but I've forgotten which ones so I'll just have to keep that old laptop around. The one bright spot is that large transactions do require a USB dongle. At least o…

Maybe 5 years ago, but now nobody uses web-based online banking any more in China. Most banks have decent mobile apps now, which have much better usability than the web-based ones. The IE situation is irrelevant now.

It doesn't bother you that your phone has the ability to make large, life-altering transactions?

Hmm the app for my bank is 2/5 stars and somehow 360MB. I'll avoid it unless I absolutely need it.

Re: South Korea’s online security dead end

#129

Earlier quoted context omitted.

It is worth mentioning that to make a bank transfer in Korea (used to[1]) require 3 factor authentication: the user's website password, the user's PIN, the user's encryption certificate signature/공인인증서, and two randomly selected codes from a paper numbers card (보안카드: https://file2.nocutnews.co.kr/newsroom/image/2013/07/02/2013... ), which users are instructed to never copy or digitize. Of all these solutions, the num…

btw, this paper card approach was replaced by physical hardware OTP tokens (lasting multiple years until they have to be replaced), it’s as secure as the supply chain (which is also a factor for paper cards), so I’m not sure why Korea still clings to this as tokens are obviously a net gain in ops cost

The Canada Revenue Agency does something similar, where instead of TOTP they ask you to print a grid of alphanums and they ask you for combinations.

The only problem is I think they're only good for a couple months at which point you need to do verification by mailed token which is a royal pain in the ass

Re: South Korea’s online security dead end

#130
post #120

Earlier quoted context omitted.

I wouldn't say that American digital banking is that bad at this point. SMS 2FA is pretty robust, as biometrics on the phones reduce the number of SMSes sent.

In germany most banks don't do this anymore due of security reasons.

I can't say about most, but my N26 DE account requires SMS authentication as well.
Post reply on HN