13 ms·
Disclaimer. I am Korean and currently live in Korea. Online banking in Korea is very poor, so even though I code on Linux and macOS, I use Windows for internet
by r2vcap 4y ago
Disclaimer. I am Korean and currently live in Korea. Online banking in Korea is very poor, so even though I code on Linux and macOS, I use Windows for internet banking.
As in many other countries, banking in Korea is a state-regulated industry. However, Korea's regulatory system rule downs to the smallest detail.
For example, in the Digital Signature Act(전자서명법), a content that allows only digital certificates in the form of files called authorized certificates(공인인증서) to be used for certification was added in 1999. (The contents were revised only in 2020.) As a result, most banking was accessible only using IE and Active-X. Now that Active-X cannot be used, various software is installed using separate installation files.
Korea's financial regulators are strict, but Korean politicians and media are paternalistic, so if there's a problem with finance, most of them try to side with financial consumers. For example, the issue of password leakage due to a keylogger installed on a user's PC is considered to be a bank problem, not a user problem. For this reason, banking websites require all kinds of security software, such as keylogger checking programs and firewalls. (This problem is gradually being mitigated.)
The problem with Korean security software is that the buyer of the security software (in this case, the bank) only requires that it meet the requirements of laws and regulatory authorities, so there is little room for improvement. Security software can be delivered only after CC certification (CC 인증) issued by the National Intelligence Service(국가정보원). By the way, the NIS is interested in which encryption algorithm is used (whether Korean algorithms such as SEED, ARIA, LEA, etc.), but it is not interested in whether Visual Studio Runtime is 2008 or 2019.
Also, financial institutions do not take cybersecurity issues seriously. For example, when I was in the security industry, a financial company asked for security software for ATMs running Windows XP SP2. Even at that time, Windows XP was EOL, and our security software was only supporting Windows XP SP3 or later. Significantly, the company suffered a cyber attack a few years ago that paralyzed its entire financial services for several days.
Most of the things I mentioned here refer to Korean-language materials, so giving references is somewhat limited.
- xwolfi 4y agoI work in Hong Kong, in the securities industry. We interact a lot with Korean laws, and all of APAC, and Korea is special in that they enjoy nonsensical rules that provide no protection to anyone except the politicians who came up with them and can argue they did do "something". It's, I think, even worse than China's philosophy, because China is young and pretentious in capitalism, while Korea seems more dishonest and cowardly.
- kragen 4y agothis is a cautionary tale for people who hope that government regulation will solve the current computer security disaster outside korea you cannot solve problems by giving authority to people who are motivated to solve them, but do not understand what the problem is, so that they can tell the people who do understand the problem what to do anyone who has dealt with pci-dss presumably knows this but that is a much smaller group than all south koreans think of that the next time someone contrasts bitcoin with the heavily regulated conventional banking system
- MBCook 4y agoIsn’t this an issue of mandating the means and not the ends? If the regulations said banks had to be secure by ‘taking all due care’ and follow ‘best practices’ and such, this wouldn’t be such an issue. That gives room for improvements and for problematic standards to be weeded out over time. It sounds like the government instead said banks had to be secure by using (for example) SSL 1.0 with a 64-bit key. Because the specified the exact how, that’s what banks did. And when that how was broken the law wasn’t changed, so banks still do the old thing. And when the old thing (Active-X) stopped working they invented new ways to do the old thing with local proxies. Because the law says they must and are safe if they do. This is the danger of legislating an exact how. It may be the right thing sometimes, but it can also go sideways.
- kragen 4y agothat just leaves the courts to decide what the best practices are, and what due care is or isn't, which i think is actually what happened in south korea that would be great if judges were hackers and legislators weren't, but that isn't the current situation
- likecarter 4y agoIn court, you bring in experts (usually professors from reputable universities) to state best practices. Judges don't act as experts in a trial.
- userbinator 4y agoFor example, the issue of password leakage due to a keylogger installed on a user's PC is considered to be a bank problem, not a user problem. In other words, they're authoritarians at heart. They want complete control over the environment and don't want users to have any personal responsibility.
- bobkazamakis 4y ago[flagged]
- pessimizer 4y agoIn non-authoritarian countries like the US, the users are responsible for all of the bank's losses.
- astrange 4y agoThey certainly aren’t. That’s what FDIC / Reg E / Reg NMS and co are for. US financial regulation is pretty customer friendly.
- LadyCailin 4y agoAnd who do you think pays if the FDIC is activated?
- astrange 4y agoNot the specific customers of the failed bank. And not really anyone else either. You'd lose more wealth in a financial crisis than you would from the government printing money to refill the FDIC fund.
- shkkmo 4y agoThe FDIC is funded by insurance premiums that banks pay that are then invested an generate returns. Thus it comes out of the returns the bank generates using your money to invest, and then also from the returns the FDIC generates investing the premiums. In the case of a black swan event, the US Gov might have to step in to increase funding, but that is not how the FDIC normally operates.
- ravel-bar-foo 4y agoIt is worth mentioning that to make a bank transfer in Korea (used to[1]) require 3 factor authentication: the user's website password, the user's PIN, the user's encryption certificate signature/공인인증서, and two randomly selected codes from a paper numbers card (보안카드: https://file2.nocutnews.co.kr/newsroom/image/2013/07/02/20130702103512398463.jpg https://file2.nocutnews.co.kr/newsroom/image/2013/07/02/2013...), which users are instructed to never copy or digitize. Of all these solutions, the numbers card gives me the most peace of mind: even if my machine is fully compromised and all my passwords and certificates stolen, the attacker would likely need very long-term access (or access to the bank's server) to get all 35 numbers from the card. (If the attacker compromises the card by attacking the bank, I trust attackers will reveal themselves going after larger accounts). As long as I keep this piece of laminated plastic private and visit a bank branch to replace it every 17 to 35 transactions, I can have some peace of mind, at least regarding my bank account. [1] There have since been efforts to streamline mobile payments, which I avoid because it leaves the phone as a single point for compromise.
- maxgashkov 4y agobtw, this paper card approach was replaced by physical hardware OTP tokens (lasting multiple years until they have to be replaced), it’s as secure as the supply chain (which is also a factor for paper cards), so I’m not sure why Korea still clings to this as tokens are obviously a net gain in ops cost
- zinekeller 4y agoAs pointed out, legislation detailing the exact measures needed to be done. I guess they copied over the idea of European TANs but they never found out about hardware OTPs.
- kijin 4y agoI dunno where you got the idea that South Korea still clings to paper-based number cards, but OTP tokens have been in use for the better part of a decade here. Nowadays you don't even need hardware tokens, since it's considered OK to replace them with mobile apps that use TPM to manage keys.
- cameronh90 4y agoIn the UK, the bank is also usually responsible for any unauthorised transfer, yet our banks are generally quite digitally enabled. Some banks solve the transfer authorization issue using an external bit of hardware that you type the transaction details into and it gives you a signature OTP.
- martinald 4y agoI honestly dont know much much longer the banks can continue to refund people for fraud. The scale of it is enormous - £600m last year (which is likely to be the floor of it as I imagine it doesn't all get reported correctly). If it continues growing (~40% y/y) at this kind of rate then it will soon outstrip any profits from retail banking (which is pretty low margin as it is compared to banks investment and commercial arms). I wouldn't be surprised if we see UK banks exiting retail banking because of this.
- bee_rider 4y agoI’m not sure how to understand that £600m in the grand scheme of things. If they are making billions of pounds in profit for example, maybe it is just the cost of doing business. Of course, exponentials being exponentials, if they continue along long enough they always eat the universe.
- pjc50 4y agoUK banking still looks pretty profitable: https://www.theguardian.com/business/2022/oct/25/hsbc-interest-rates-profits https://www.theguardian.com/business/2022/oct/25/hsbc-intere... The banks will be made to keep reimbursing people. They are, after all, in control of the system and the people with most information about what might be fraudulent.
- hunter2_ 4y ago> Security software can be delivered only after CC certification I wonder if the author should extend the 90-day disclosure window to account for this red tape.
- gruez 4y ago>Korea's financial regulators are strict, but Korean politicians and media are paternalistic, so if there's a problem with finance, most of them try to side with financial consumers. For example, the issue of password leakage due to a keylogger installed on a user's PC is considered to be a bank problem, not a user problem. Isn't this also the case in the US? You're generally not liable for fraudulent transactions, as long as you took "reasonable" measures to prevent the fraud from happening. Given the technical ineptitude of the average person, banks/regulators will rarely blame the consumer.
- pigtailgirl 4y ago-- dont know who you bank with but fyi - shinhan - charles schwab and kakao all work well on os x that who I use! --
- sandos 4y agoSo if keyloggers are such an issue I must assume that they don't even use any kind of 2-factor system?
- Abishek_Muthian 4y agoWoah, I thought Indian banks blocking right clicks on their website as "security" measure was obsurd. You mentioned about PC environments, What's up with mobile? Specifically with Android & iOS; Do you have to install rootkits there too for online financial transaction?