12 ms·
South Korea’s online security dead end
- richbell 4y agoThis reminds me of krebsonsecurity's experience attempting to contact the FSB. https://krebsonsecurity.com/2021/06/adventures-in-contacting-the-russian-fsb/ https://krebsonsecurity.com/2021/06/adventures-in-contacting... A lot of countries seemingly did not have access to American encryption technologies or did not trust them — arguably for good reasons[0] — which has lead to this hodge-podge of homegrown security. [0] https://www.washingtonpost.com/graphics/2020/world/national-security/cia-crypto-encryption-machines-espionage/ https://www.washingtonpost.com/graphics/2020/world/national-...
- deleted 4y ago[deleted]
- wmf 4y agoThe problems aren't with cryptography though; they're basic software engineering failures.
- richbell 4y agoThey're problems with cryptography insofar as they are problems that can be traced back to a distrust of Western cryptography and a desire to create domestic security products.
- himinlomax 4y agoYeah I found his problem in the first line of the article > KrebsOnSecurity recently had occasion to contact the Russian Federal Security Service (FSB), the Russian equivalent of the U.S. Federal Bureau of Investigation (FBI). The FSB is not equivalent to the FBI, it's the successor to the KGB. If it's equivalent to any other country's org, look to the Gestapo.
- michael1999 4y agoThis is the world the Clipper-chip minds offer us. I'm happy we dodged that bullet.
- deleted 4y ago[deleted]
- r2vcap 4y agoDisclaimer. I am Korean and currently live in Korea. Online banking in Korea is very poor, so even though I code on Linux and macOS, I use Windows for internet banking. As in many other countries, banking in Korea is a state-regulated industry. However, Korea's regulatory system rule downs to the smallest detail. For example, in the Digital Signature Act(전자서명법), a content that allows only digital certificates in the form of files called authorized certificates(공인인증서) to be used for certification was added in 1999. (The contents were revised only in 2020.) As a result, most banking was accessible only using IE and Active-X. Now that Active-X cannot be used, various software is installed using separate installation files. Korea's financial regulators are strict, but Korean politicians and media are paternalistic, so if there's a problem with finance, most of them try to side with financial consumers. For example, the issue of password leakage due to a keylogger installed on a user's PC is considered to be a bank problem, not a user problem. For this reason, banking websites require all kinds of security software, such as keylogger checking programs and firewalls. (This problem is gradually being mitigated.) The problem with Korean security software is that the buyer of the security software (in this case, the bank) only requires that it meet the requirements of laws and regulatory authorities, so there is little room for improvement. Security software can be delivered only after CC certification (CC 인증) issued by the National Intelligence Service(국가정보원). By the way, the NIS is interested in which encryption algorithm is used (whether Korean algorithms such as SEED, ARIA, LEA, etc.), but it is not interested in whether Visual Studio Runtime is 2008 or 2019. Also, financial institutions do not take cybersecurity issues seriously. For example, when I was in the security industry, a financial company asked for security software for ATMs running Windows XP SP2. Even at that time, Windows XP was EOL, and our security software was only supporting Windows XP SP3 or later. Significantly, the company suffered a cyber attack a few years ago that paralyzed its entire financial services for several days. Most of the things I mentioned here refer to Korean-language materials, so giving references is somewhat limited.
- xwolfi 4y agoI work in Hong Kong, in the securities industry. We interact a lot with Korean laws, and all of APAC, and Korea is special in that they enjoy nonsensical rules that provide no protection to anyone except the politicians who came up with them and can argue they did do "something". It's, I think, even worse than China's philosophy, because China is young and pretentious in capitalism, while Korea seems more dishonest and cowardly.
- Roark66 4y agoOh boy... Once I saw this: >This starts with a simple fact: some of these applications are written in the C programming language, not even C++. I had to stop reading and come here to see if anyone else got annoyed by it. Seriously? "not even c++" are we still in 1990s?
- ronsor 4y agoLinux is written in C. Much of its basic userland is also written in C, including any graphical subsystems such as X11/Wayland.
- rippercushions 4y agoWriting the critical parts of a OS kernel in C is sensible. Browser extensions, not so much. As the author notes, they're not just being snobby about languages, the main issue with C from a security POV is the total lack of memory safety and the consequent vulnerability to buffer overflows.
- Kamq 4y ago> the main issue with C from a security POV is the total lack of memory safety and the consequent vulnerability to buffer overflows. Sure, but C++ also has these issues, so the "not even C++" doesn't exactly make sense.
- Too 4y agoAt least c++ has unique_ptr and friends. Standard containers like string, vector and map also reduce the amount of manual fiddling with fundamentals you need to do yourself, greatly reducing the mistake-surface. But yeah, in the end both of them are very dangerous tools, compared to other alternatives.
- palant 4y agoDisclaimer: I am the author of this article. Not really. With C++, you don’t have to use manual memory management. In the typical scenario, C++ objects take care of memory without the developer having to think about it. And you have all kinds of smart pointers for the more complicated scenarios. That doesn’t mean of course that there are no buffer overflows in C++, or use-after-free bugs. There is still plenty of room for mistakes. But C++ code following best practices tends to have far fewer vulnerabilities than comparable C code.
- second_brekkie 4y agoI live in Korea. In my experience pretty much everyone I know uses banking apps which you can do everything through, not online banking through a browser. You would hope that these would be somewhat more secure as this may have required a 're-write' as the article suggested. Though even with mobile apps you sometimes have to install some 3rd party 'anti-virus' software that probably amounts to spyware. But hey you can either lump it or leave it. They do at least try to make you feel like it's secure. To set up mobile banking you need at least 3 different passwords and need to perform 2fa 3 times as well. They have 'front end' security too, such as each time you enter a pass code the keyboard is in a different arrangement.
- flotzam 4y agoThere's a curious absence of Korean banking apps on this GrapheneOS compatibility list: https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos https://privsec.dev/posts/android/banking-applications-compa... Does it mean none are usable on a modern clean Android? Or is there a total Samsung monoculture? Something else?
- ravel-bar-foo 4y agoKorean banking apps usually are disabled in rooted Android, probably because in rooted Android the integrity of the binary cannot be verified.
- _8j50 4y agoFor threat actors that target Korean users their favorite software to exploit for initial access is HWP (Hangul Word Processor). It's MS Word for Korean users. If you are being sent official docs of any kind, chances are it is a .hwp file that needs the program. Banking and internet access affects consumers but HWP is used by more interesting espionage/sabotage targets. https://www.fireeye.com/content/dam/fireeye-www/global/en/blog/threat-research/FireEye_HWP_ZeroDay.pdf https://www.fireeye.com/content/dam/fireeye-www/global/en/bl... I just looked up CVEs for it. I only see 2 in 2017. This is not a good thing, a complex word processor, even if it was rewritten in a memory safe language would have at least some low level non-memory vulns in 6 years!
- nibbleshifter 4y ago10 years ago for work we assessed a similar client side software solution (a "secure browsing" pile of ActiveX and C++) for protecting banking sites users. Absolute steaming garbage. Its "anti keylogging" functionality could be bypassed trivially, as could its various screen hijacking tricks designed to defeat some methods used by the banking trojans that were common at the time. I see that snake oil industry lives on in Korea :/ Very excited to see the results of OP's work (the disclosures).
- rgmerk 4y agoThis smells terrible, I agree, but the proof of the pudding is in the eating. Are there any stats comparing levels of banking-related cybercrime in South Korea with other jurisdictions?
- joshuaissac 4y agoLarge banks in the UK used to promote an application called Trusteer Rapport that secured the connection between the bank's server and the user's computer. It was not mandatory like the Korean apps, just strongly suggested. I can see that some banks still offer it.
- glebd 4y agohttps://www.reddit.com/r/sysadmin/comments/4iq2pp/trusteer_rapport_no_more/ https://www.reddit.com/r/sysadmin/comments/4iq2pp/trusteer_r...
- gkanai 4y agoI was working at Mozilla in 2007 when I first brought this issue to the wider (i.e. beyond S. Korea) Internet. My post from then was widely covered by Slashdot and Boing Boing and other tech sites. S. Korea clearly doesn't care to 'fix' this because they've had more than enough time to do so. https://archive.is/ermII https://archive.is/ermII CNet back in 2007: https://www.cnet.com/tech/tech-industry/about-south-koreas-dependency-on-microsoft/ https://www.cnet.com/tech/tech-industry/about-south-koreas-d... https://it.slashdot.org/story/07/01/26/1455224/why-south-korea-is-shackled-to-windows https://it.slashdot.org/story/07/01/26/1455224/why-south-kor...
- varenc 4y agoI poked around the install page for Citibank's required software and it's pretty fascinating: https://www.citibank.co.kr/CusSecnCnts0100.act?P_name=ASTx https://www.citibank.co.kr/CusSecnCnts0100.act?P_name=ASTx Some quick observations: - That page intentionally disables right-click! Just by putting `oncontextmenu="return false"` on the <body> tag. This gives me flashbacks to the late 90s when this technique was used to make it harder for users to copy images or inspect HTML source. Browsers all have built in developer tools so pretty silly seeing it now. - The JS included on that page is a mix of heavily obfuscated code[0] and completely unminified code with all the internal comments left in[1]. - I was impressed that the required software seems to support Fedora and Ubuntu/Debian as well as macOS and Windows. - One of the installations is checked by making a JSON-P call (another old tech flashback!) to `https://lx.astxsvc.com:55921/ASTX2/hello https://lx.astxsvc.com:55921/ASTX2/hello?...`. This works because lx.astxsvc.com resolves to 127.0.0.1 so you're just hitting your localhost. Presumably the installed software checks the referer header to ensure only citibank is making these requests. [0] https://www.citibank.co.kr/aB-IFIZu8Pd7Zd1yjboonwGx/uYfEz6DpV1/WSo8YwE/Eg8HF/UNmUiI https://www.citibank.co.kr/aB-IFIZu8Pd7Zd1yjboonwGx/uYfEz6Dp... [1] https://www.citibank.co.kr/3rdParty/wizvera/veraport/install20/install_internal.js https://www.citibank.co.kr/3rdParty/wizvera/veraport/install...
- curling_grad 4y agoDisabling right click is kind of a Korean web tradition. Almost every dated websites (including personal blogs) have done that.
- palant 4y agoDisclaimer: I’m the author of this article. Did you notice the plain HTTP (no SSL) download URLs for the “security software”? If not, you are missing out!
- varenc 4y agoI didn't! The download URLs on that page all seemed to be HTTPS for me, though my browser might be forcing the HTTPS connection or something. Or it's just the macOS versions. I'd 100% believe there's plain HTTP requests in there somewhere. I was trying to get the JS to serve me the software for other OSes but was struggling since it seems to do more than just a User-Agent check. Fortunately that JS is the totally unobfuscated kind. btw, love your article! Such an interesting obscure little corner of the world of technology. Hope to read more.
- intoxicat3d 4y agoyou know what, it has been dead end from the beginning when govern has tried to regulate what to use for security lol...
- smsm42 4y ago> Nowadays, a typical Korean banking website will require five security applications to be installed before you are allowed to log in Note to self: never move to Korea. Or at least never use Korean bank (can you survive on cash and Bitcoin?)
- GauntletWizard 4y agoI was just there for two weeks, and while I used my card a lot, I don't think there's anything I couldn't have done with cash. For that matter, I had no problem using my American bank, though obviously if I were being paid in Won that would be less of an option.
- kyaru 4y agoKorea will not change unless it is fatally affected. Someone needs to shake it off.
- nokya 4y agoI see two candidate alternatives to your "Getting out of the dead end": 1. Give SK a few months/years until it realizes it is losing billions revenue nationally due to hacking by foreign entities and it will naturally invest in its application security landscape. 2. Reconsider your position on SK's current situation by factoring actual risk in the equation (likelihood of threat, in particular). What you seem to have discovered are client-side vulnerabilities that would require direct network access to the client machines to be exploited (i.e., no firewall, no NAT, no etc.). First, these limitations greatly reduce the attack surface and second, they may actually cost the attacker more to exploit than simply sending a well-crafted message with an attachment to click on. I would be much more convinced by your conclusions if you added elements that would support the hypothesis that the situation is similar (or worse) server-side. (edit: removed ugly formatting)
- giaour 4y ago> What you seem to have discovered are client-side vulnerabilities that would require direct network access to the client machines to be exploited We don't know what a user has installed on their local machine, so a bank mandating that users install an application with known vulnerabilities has reduced its security posture to whatever client-side chicanery is happening on a given computer. This may shift liability (i.e., it's not the bank's fault if malware intercepts traffic sent to a localhost web server) but does not improve security. As a user, you might be able to use software with known client-side vulnerabilities safely by constructing isolated sandbox environments for each permutation of required client-side "security" software, but it's unrealistic to expect everyday users to do so.
- chihuahua 4y agoRegarding 1 - SK has apparently been doing this since the 1990s. If it was just a matter of time before they realize this is a bad idea, I think they've had enough time to figure it out.
- palant 4y agoNote: I am the author of this article. Where did you get the idea that direct network access is required? To quote the article: “large applications interacting with websites in complicated ways.” Most attacks can be launched by an arbitrary website. And given the number of people affected, this is way worse than any individual server being vulnerable. Besides, I’m definitely not going to look for server-side vulnerabilities without permission.
- filoleg 4y agoOverall an interesting post, thanks for sharing. Nitpick for OP (@palant): on mobile Safari (haven't checked any desktop browsers), the images embedded into the post appear stretched out vertically (i.e., too "slim"). It is still technically readable, but very noticeable and jarring. This only applies to the images when embedded, opening direct image URLs in a dedicated browser tab renders them properly without any stretching. I suggest checking CSS, but that's just my first guess and could be entirely wrong. I think just keeping the same horizontal size of images, but reducing the vertical size, would make it much more aesthetically pleasing + readable.
- deleted 4y ago[deleted]
- black7375 4y agoOne of the reasons for maintaining is to transfer consumers to security responsibility.
- bob1029 4y ago> This prompted South Korea to develop their own cryptographic solutions. I've had an opportunity to interact directly with Korean security culture in my time working for Samsung. I am sure there exists more secure examples out there, but I saw some extremely bad practices like trivially-reversible password shuffling used throughout the entire org. Anyone with access to a certain manufacturing database and knowledge of a particular stored procedure could immediately reverse all passwords and typically use them to go sideways into other engineering/facility systems. They always seemed substantially more interested in the theatrical aspects of security than focusing on any first principles. Lots of time was spent talking about reactionary crap like a fleet of hardware ARP sniffers installed throughout the network. Not a lot of time was spent talking about PBKDFs, system boundaries and determinism.
- black7375 4y agoIn 1999, the adoption of its own 128bit algorithm was reasonable. - https://en.wikipedia.org/wiki/SEED https://en.wikipedia.org/wiki/SEED - https://en.wikipedia.org/wiki/ARIA_(cipher) https://en.wikipedia.org/wiki/ARIA_(cipher) Of course, it's close to technology debt now.
- gred 4y agoVery interesting read. I'm looking forward to the details in the followups (1/9, 1/23, 3/6). However, I'm surprised that there are no KR banks who build their reputation on their technical acuity and who have eliminated (or avoided) reliance on these types of applications. The markets I'm familiar with tend to have a few banks who have a reputation for good websites, good apps, etc. Or perhaps that bit of context was omitted, and these types of banks do exist in KR? Note for the author: small typo at "requires outmost care".
- palant 4y agoDisclaimer: I am the author of this article. I think that this issue is really universal across all banks in Korea. I was told (but couldn’t confirm) that this is a liability question. Supposedly, there was a court ruling that held a bank liable for a customer’s losses due to lack of security precautions. So now all of them implement “security precautions” to avoid liability. Thank you for the hint, I fixed the typo. Not being a native speaker, I had to ask a search engine what I did wrong in this sentence. :-)
- yongjik 4y ago> Supposedly, there was a court ruling that held a bank liable for a customer’s losses due to lack of security precautions. You already wrote as much in the article, but (AFAIK) the reality is even worse: there were court rulings that exonerated banks, as long as they followed the standard "security practices." Some hacker from China could access the bank's website from a suspicious IP, drain all the money from a poor guy's account, but the bank has zero obligation to do anything as long as it mandated that all users install half a dozen security plugins all the time.
- xorcist 4y ago> security plugins A contradiction in terms of epic proportions.
- acchow 4y agoThanks for the writeup. Do you think getting out of this mess could be as simple as government regulationL: banking (and government and other necessary websites) are not allowed to require installation of plugins or other software to log in.
- physicles 4y agoThis mirrors the situation in China, likely for similar reasons. To this day, I can only do online banking with Internet Explorer 11. When logging in, of course the password field doesn't permit pasting. I have a couple ActiveX controls and certs installed, but I've forgotten which ones so I'll just have to keep that old laptop around. The one bright spot is that large transactions do require a USB dongle. At least one other website I've used (perhaps Alipay?) required you to install a browser plugin simply to be able to "securely" enter your PIN. Rewinding back to 2014, the brand new government website for buying train tickets[0] didn't have an SSL cert signed by any of the trusted authorities. If you wanted to buy tickets securely, you needed to download a zip file (over http) that contained 1) a self-signed root cert, and 2) a Microsoft Word document explaining how to add this to your OS's trusted root cert store and how this is totally legit and secure. [0] https://www.techinasia.com/chinas-official-train-ticket-site-travel-harder-holidays https://www.techinasia.com/chinas-official-train-ticket-site...
- WiSaGaN 4y agoMaybe 5 years ago, but now nobody uses web-based online banking any more in China. Most banks have decent mobile apps now, which have much better usability than the web-based ones. The IE situation is irrelevant now.
- physicles 4y agoIt doesn't bother you that your phone has the ability to make large, life-altering transactions? Hmm the app for my bank is 2/5 stars and somehow 360MB. I'll avoid it unless I absolutely need it.
- WiSaGaN 4y agoThen you probably don't use your phone as 2FA for any "large, life-altering transactions"?
- ThePowerOfFuet 4y ago> At least one other website I've used (perhaps Alipay?) required you to install a browser plugin simply to be able to "securely" enter your PIN. Straight-up government malware right there.
- prottog 4y agoThis always bothered the hell out of me when interacting with Korean websites, especially online banking. I believe in addition to the factors that the article listed, there are several laws in place that mandate this chicanery, at least for banking.
- snvzz 4y agoIt is interesting to see a proprietary, very poor and insecure imitation of Nitpicker's xray mode[0]. Note this is written by Norman Feske, who later went on to develop Genode[1], and continues to be its main developer today. 0. http://demo.tudos.org/nitpicker_tutorial.html http://demo.tudos.org/nitpicker_tutorial.html 1. https://www.genode.org/ https://www.genode.org/