Live data from Hacker News

South Korea’s online security dead end

palant.info

141–144 of 144 posts

Re: South Korea’s online security dead end

#141
post #41

Earlier quoted context omitted.

Korean banking apps usually are disabled in rooted Android, probably because in rooted Android the integrity of the binary cannot be verified.

GrapheneOS is not rooted though. Are all of them doing SafetyNet checks too, not just root checks?

I don't think korean banks run safetynet. They roll their own checks with varying levels of strictness. Most of them were fooled by Magisk Hide, but not all.

Re: South Korea’s online security dead end

#142
post #37

Earlier quoted context omitted.

There's a curious absence of Korean banking apps on this GrapheneOS compatibility list: https://privsec.dev/posts/android/banking-applications-compa... Does it mean none are usable on a modern clean Android? Or is there a total Samsung monoculture? Something else?

I live in Korea and run the latest GrapheneOS on Pixel 6. I have 6 different banking apps (Citi, IBK, Woori, etc.) installed and all of them work flawlessly. I also have a few government apps running and they work as well. There are definitely some apps that don't run on it (Donbaekjeon, Busan's local payment app being one) but overall they work.

fyi, yes, samsung monoculture is very strong. No foreign phone brands, especially Chinese, have gained significant market share (except apple ofc). Samsung with their 70% market share has been the undisputed champion in S. Korea for probably the whole post-iPhone era, even in the budget segment. Romming community does exist here and quite vibrant for its size but Samsung pumping out literal truckload of phone models (not to mention their carrier-locked variants which are more common like in the US), Knox (ew) and general public sentiment against modifying their devices means it's not really visible.

Re: South Korea’s online security dead end

#143
post #37

Earlier quoted context omitted.

There's a curious absence of Korean banking apps on this GrapheneOS compatibility list: https://privsec.dev/posts/android/banking-applications-compa... Does it mean none are usable on a modern clean Android? Or is there a total Samsung monoculture? Something else?

I live in Korea and run the latest GrapheneOS on Pixel 6. I have 6 different banking apps (Citi, IBK, Woori, etc.) installed and all of them work flawlessly. I also have a few government apps running and they work as well. There are definitely some apps that don't run on it (Donbaekjeon, Busan's local payment app being one) but overall they work.

Thank you for these comments!

It's great to hear that the compatibility situation isn't that bad in Korea. Have you considered submitting the apps to https://privsec.dev/posts/android/banking-applications-compa...? Otherwise people might make the same mistake as me (look at the list and assume it's impossible to use an alternate OS)

Re: South Korea’s online security dead end

#144
It is interesting to see a proprietary, very poor and insecure imitation of Nitpicker's xray mode[0].

Note this is written by Norman Feske, who later went on to develop Genode[1], and continues to be its main developer today.

0. http://demo.tudos.org/nitpicker_tutorial.html

1. https://www.genode.org/

Post reply on HN