Wow. That's... a rather unconventional security architecture.
Wow. That's... a rather unconventional security architecture.
Actually it was rather inevitable, partially because of the U.S. gov that time. The Korean gov wanted to grow e-commerce/e-banking in 1999 but the American gov did not allow to export cipher higher than 40 bits. As a result the Korean gov had to develop its own 128 bits cipher (SEED).
It was even before AES/SSL/TLS were introduced so the whole crypto stack was implemented using ActiveX.
I would say it was quite pioneer in 1999 but since then the gov don't even dare to replace the crypto policies. Now we are stuck at this in 2020.
That's amazing it's still used per policy, I never would have imagined.
Edit: clarification on which parts were blocked and internationally available.
That thing exactly was export-restricted and was available only in U.S. and Canada: https://jeffpar.github.io/kbarchive/kb/159/Q159709/
But it was true that SSL was introduced before 1999. Thanks for the correction.
However, I think the present situation is possibly the better one as a siloed, South Korea only web, separate and distinct from the rest of the Web, would end up being a much harder one to eventually migrate to the regular global web ecosystem vs. the current problem of just getting banks to stop using SEED and moving users to modern browsers.
There are two major factors in the ubiquity of HWP:
1. Its use of the de facto standard format in the SK government (the de jure standard is the ODF since 2007, but its use is virtually nonexistent). This stems from the fact that it was the most viable word processor supporting Hangul the script back in 1990s.
2. Its excellent support of table-based layout. HWP is a decent word processor in comparison to MS Word, and in some cases it is even superior. Koreans used to produce lots of documents based on tables [1] and HWP's UX was specially tailored to them. MS Word lagged behind for a long time, probably because this use case is not common in English worlds.
[1] You can search for "이력서" (résumé) to see what I mean. Even a plain document tends to be styled in this way.
> I would say it was quite pioneer in 1999 but since then the gov don't even dare to replace the crypto policies. Now we are stuck at this in 2020.
AFAIK, the government removed the SEED-only policy some time ago (in the early 2010s) but it’s the price of the system infrastructure that makes them keep using the old, ActiveX based systems.
I’m personally thankful for smartphone’s to come, as the banks started to consider implementing support for other operating systems. If it wasn’t the abundance of smartphones, I believe there might have not been any non-windows/IE support. Its much better nowadays, with multiple startups in the finance space like Toss, Kakao, etc...
1: Or, more probable, support for modern web browsers on any OS, but with (2FA) authentication handled through proprietary and required Android or IOS apps.
That’s actually a pretty accurate explanation of currently what’s happening, but it’s much better than before as macOS/Linux support is also coming too.
> That's not quite as bad of course, but it's still limiting in terms of software freedom.
I’m not the person who hates programs that aren’t open source or “free”, so for me just being able to tell my friends to use macOS or Linux is a pretty great progression.
We're moving in that direction in the Netherlands with our national citizen's accounts (DigiD: mandatory if you want to file taxes, gain access to your health care records, or handle your insurance digitally).
https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...
https://en.m.wikipedia.org/wiki/Superfish
https://www.eff.org/deeplinks/2015/11/superfish-20-now-dell-...