8 ms·
IPinside: Korea’s Mandatory Spyware
- hunglee2 4y agoKorea is not authoritarian but a democracy - this is ok
- Darmody 4y agoI've never heard around here that spying is good when a democracy does it. It may be better than when authoritarian countries do it because the consequences are not that severe, but that's far from accepting it.
- largepeepee 4y agoBad take. If anything, it reveals just how many things are not up for voting in our democracy - because people will definitely vote down spyware whose obvious target is us.
- calgoo 4y agoSo lets ignore the government part of this. Anyone can create a webpage that collects this information, which means that a non government hacker (or another government like N. Korea or China) can setup online services that people from South Korea wants to access. They can then use this collected information to impersonate the S. Korean person.
- BlueTemplar 4y agoWhat government part ? Aren't these mostly (?) privately/publicly owned banks ?
- Freak_NL 4y agoThis used to be done in South Korea by (ab)using ActiveX. This looks like a continuation of a bad practice. Not that banks in other countries are much better with their reliance on mandatory (or nearly mandatory) smartphone apps.
- LtWorf 4y agoMy italian bank relies on SMS for 2nd factor. They used to have an actual object generating numbers, but to save money they moved to SMS, claiming it was to follow an EU regulation (which I've read, and mandates the exact opposite).
- Freak_NL 4y agoEstablished Dutch banks grudgingly keep their 'readers': small pieces of cheap hardware which can generate OTP's by reading the chip on your debit card and verifying the PIN. It works, but the banks are trying really hard to move everybody to their apps, and they are increasingly making that route the one with less friction (e.g., by selecting the app option as default on every transaction and by making it look like the app is the only way in their communication with the customers without explicitly saying so). A few of the newer online only banks are simply mandating their apps, making them exclusive to people who own (recent-ish) Android or IOS smartphones. They aren't going back to SMS though. That's really a thing of the past now.
- LtWorf 4y ago> They aren't going back to SMS though. That's really a thing of the past now. Mostly because it costs them money and doesn't allow them to collect data. They wouldn't care that it's not encrypted.
- sofixa 4y ago> doesn't allow them to collect data. What data? This is your bank, they already know exactly when what for what amount you're buying because you're doing it with their card. There's no other data they can reasonably get away with collecting.
- guntherhermann 4y agoI think this requires some prior knowledge. From https://palant.info/2023/01/02/south-koreas-online-security-dead-end/ https://palant.info/2023/01/02/south-koreas-online-security-... : > I’ve heard about South Korea being very “special” every now and then. I cannot claim to fully understand the topic, but there is a whole Wikipedia article on it. Apparently, the root issue were the US export restrictions on strong cryptography in the 90ies. This prompted South Korea to develop their own cryptographic solutions. > It seems that this started a fundamental distrust in security technologies coming out of the United States. So even when the export restrictions were lifted, South Korea continued adding their own security layers on top of SSL. All users had to install special applications just to use online banking. > Originally, these applications used Microsoft’s proprietary ActiveX technology. This only worked in Internet Explorer and severely hindered adoption of other browsers in South Korea. Wowsa!
- hosteur 4y ago> Originally, these applications used Microsoft’s proprietary ActiveX technology. This only worked in Internet Explorer and severely hindered adoption of other browsers in South Korea. This basically reveals that the pretext of this being primarily about increasing security of the connection is not really what it is about. From having read about this, I think it is completely fair to classify this as spyware.
- mathieuh 4y agoIf at any point a government tells you they are doing something to increase security, or to be tough on crime, or to protect children, it is almost certain they are lying to your face and in fact just want more ways to spy on people.
- numpad0 4y agoMore likely a massive and internally unrecognized incompetence than some black project from sneaky agencies. I remember some experts in 2000s fighting months to convince banks that TLS with self signed certificate is the way to get customers scammed.
- vgb2k18 4y ago> When a banking website in South Korea wants to learn more about you, it will make a JSONP request to localhost:21300. If this request fails, the banking website will deny entry and ask that you install IPinside LWS Agent first. So in South Korea running this application isn’t optional. To me this reads as not mandatory in the broadest scope, but needs to be on whatever device people use for online banking.
- Neoshadow42 4y agoRight, but the banking website was one example of an system that might force IPinside installation. Losing access to several necessary systems basically makes it mandatory. Even if you could buy a burner device to access those systems, the average person will not - and that's the problem here.
- palant 4y agoDisclaimer: I’m the author of this article. Quite a few people living in South Korea say exactly that: they keep an old laptop around only for online banking. And they try to avoid whatever else requires IPinside and similar applications. This solves the issue at least partially on the individual level. But most people will in fact not do this.
- vgb2k18 4y agoIn the article I cannot see Android and iOS mentioned. I also can't discern if banks alone, or banks and other vital services require IPInside. This logic is going somewhere so hear me out please! (and this is meant to be a humble query, I hope it comes across that way). To me this ambiguity leaves the door open for challenges to the label "mandatory spyware" as a blanket label. With the ambiguity open, a plausible scenario is this: Only banks enforce IPInside, and Koreans can access full banking services from their mobile Android and iOS devices (with IPInside installed), meaning their laptops and PC's wouldn't need IPInside installed. Meaning: the label mandatory would be an overstatement. I'm not against the label mandatory, if... These gaps in knowledge are filled in with more info (forgive me if I it was clearly stated in the article for all to see! I read it the best I could but on mobile so who knows what I missed).
- quenix 4y agoI enjoyed this read very much. Hidden gems like these are why I love visiting HN!
- canbus 4y agoIPinside sounds a bit like a really weird medical condition
- dotancohen 4y agoI prefer to read it as the killing of Intellectual Property.
- Traubenfuchs 4y agoWell there is a condition called vesicoureteral reflux where pee from the bladder flows back to the kidneys (it should not) and that could be interpreted as IPinside...
- IYasha 4y agoin Japan it sounds like Yaranaika... )
- KirillPanov 4y agoHere in the US the authorities just use the Intel ME and AMD PSP. No messy sidecar software needed!
- mschuster91 4y agoNeither of these are exposed to the wide Internet.
- consp 4y agoI thought the ME could access the pcie bus and thus network cards (if not embedded into the SoC)? Maybe I was misinformed.
- mschuster91 4y agoIt can, yes, but under ordinary circumstances remote websites cannot access the ME/PSP.
- KirillPanov 4y agooh my sweet summer child...
- CyberDildonics 4y agoPatronizing someone is not evidence that they're wrong.
- tinus_hn 4y agoI don’t see how this service checks if the website is supposed to be using it. So it seems any website can get all this information and use it to track users.
- palant 4y agoDisclaimer: I’m the author of this article. As it says in the article, the application doesn’t check at all which website connects to it. It seems that they rely on their obfuscation, hoping that only eligible websites will be able to decrypt the data. Which, quite frankly, is a stretch.
- mschuster91 4y agoThe idea was that random, unauthorized websites can access the JSONP endpoint but can't use the data because it is encrypted. Which, as the author explained, might have worked - had they not completely botched the encryption by using an extremely short asymmetric key for one set of data and symmetric keys for the other two pieces.
- gkanai 4y agoI'm the one who originally first wrote about the situation in S. Korea in the 90s when I was working for Mozilla and we noticed that Firefox had almost no market share there. At the end of the day, it's up to the S. Korean govt. or regulator to make the changes necessary to get rid of this nonsense. The govt./regulators have other issues to deal with so these S. Korean 'tech' companies get to make a mess of citizens' computers and privacy. It's been well over 2 decades of crappy S. Korean software like the keyloggers and whatnot and no end in sight. If S. Korean citizens cared, they would force the politicians to do something and it would change. They don't, so it doesn't change.
- jinseokim 4y agoDisclaimer: I'm Korean. A LOT of Korean citizens cared and got angry with this issue. So governments, agencies, and. yeah, "security companies", finally decided/declared to deprecate ActiveX-fu softwares and follow Web Standard. We didn't expect WebSocket on localhost.
- palant 4y agoDisclaimer: I am the author of this article. First of all, thank you very much for informing about this issue. I still remember reading the article you wrote back in 2007, and it really helped me navigate this situation. I doubt that people in South Korea care so little about it however. Otherwise articles citing an unnamed “famous hacker” about how all of this isn’t really bad and how I misunderstand the domestic security market wouldn’t have been necessary. It seems that lots of uncomfortable questions are being asked right now. Whether this will be sufficient to produce some real change for the better is a different question of course. I sincerely hope that it will.
- wiz21c 4y agoThe title should mention South Korea explicitely because without that we may believe that North Korea is included in the story.
- LtWorf 4y agoI was in doubt after reading "Korea", but after "mandatory spyware" I was certain it was going to be South Korea.
- grishka 4y agoThey don't have internet access in North Korea, do they?
- petre 4y agoOnly the priviledged. The rest use Kwangmyong = like Facebook's Free Basics but operated by KCC. https://en.m.wikipedia.org/wiki/Kwangmyong_(network) https://en.m.wikipedia.org/wiki/Kwangmyong_(network)
- TheRealPomax 4y agoI assume you then read the article, so... no problem here?
- megous 4y agoThe issue also is (for the banks depending on the application) that they can't trust aplication running on the user's computer. This begs for opensource implementation that returns plausible fake data. :)
- palant 4y agoDisclaimer: I am the author of this article. Yes, developing such an application would be fairly easy. From what I understand however, South Korea has laws against reverse engineering. So openly distributing this application would probably be risky, asking for lawsuits. Which doesn’t mean of course that no cybercrime gang (particularly those specializing in banking fraud) has such an application.
- TheFattestNinja 4y agoI was wondering just that. Get the private key, spoof the data to be the "real" ip of your neighbor whom you have, do bank crimes. Ta-dan, you get him in troubles.
- O_O1 4y agoGood contents with nodding as Korean.
- O_O1 4y agoAs a Korean, great contents with big nodding
- KVFinn 4y agoJust generally, Korea seems to have some weird legacy internet stuff. It's pretty hard to find places you can order in Korea, or from Korea, that don't require a Korean phone number. There are services and stores that exist just to buy things from other places in Korea and reship or resell them to people both in and out of the country, just because people don't have Korean phone numbers. Even online purchases like audiobooks often requires a local phone number. They sure make it hard to spend for any non Korean to spend money. And it's not every site, there are some huge retailers (www.aladin.co.kr for example) that do not require it. So it's got to be just that most websites never bothered to build a checkout process that works without a phone number?
- Tijdreiziger 4y agoI once ordered something online from an EU country. I entered my phone number (from another EU country) in the international format (+xx xxxxxxxxx). The website silently mangled my phone number into a local number. I had to e-mail them and tell them "hey, this is not actually my phone number, just some number from your own country that may or may not exist."
- soohyung 4y agoYou'd be surprised, there are many sites that don't even support names longer than some arbitrary limit like 5 or 10 characters because Korean names are typically 3 to 4 characters long. The phone number is typically required for real-name verification. Pair that with the low character limit above and a lot of stuff just breaks. I think non-Korean customers just are not much of a consideration for Korean companies unfortunately.
- cycrutchfield 4y agoIt goes both ways. Some US sites don’t allow spaces or hyphens in given names.
- msm_ 4y agoMost US websites I deal with throw a random error when I give them my name. And it's not even weird, just one non-ascii character. Especially annoying since they always say something to the effect of "Write your legal name here, exactly as it's on your documents, do check twice it's the same". I know sometimes it's because of legacy ASCII protocols in finance/airlines (but sometimes it's just bad databases/regexes). I know how to fix it, but please just don't say in the error message that my name is "invalid".
- poulpy123 4y agoSouth Korea for people would thing "duh it's obvious they have spywares"
- Slighted 4y agoSouth Korea. Be specific about it.
- kevwil 4y agoThis. I was so confused, like "Korea is not a place; South Korea and North Korea are both places, and are vastly different, so what are you on about?" level of overthinking.
- fomine3 4y agoJSONP! It’s been a while