IPinside: Korea’s Mandatory Spyware
palant.info
palant.info
From https://palant.info/2023/01/02/south-koreas-online-security-... :
> I’ve heard about South Korea being very “special” every now and then. I cannot claim to fully understand the topic, but there is a whole Wikipedia article on it. Apparently, the root issue were the US export restrictions on strong cryptography in the 90ies. This prompted South Korea to develop their own cryptographic solutions.
> It seems that this started a fundamental distrust in security technologies coming out of the United States. So even when the export restrictions were lifted, South Korea continued adding their own security layers on top of SSL. All users had to install special applications just to use online banking.
> Originally, these applications used Microsoft’s proprietary ActiveX technology. This only worked in Internet Explorer and severely hindered adoption of other browsers in South Korea.
Wowsa!
The problem came from U.S. cryptography export regulation which makes exportable cryptographic algorithm feasible to crack. Bundled Internet Explorer didn't support good algorithms on SSL.
So, South Korea government wanted to add another security layer. They wanted to state "good to go" algorithm (just like FIPS did), so they built and recommended the encryption algorithm, SEED. And it required ActiveX, because 128 bits cryptography on JavaScript was infeasible then.
The real problem of South Korea is, the slowness of deprecation.
They deprecated ActiveX (and created NPAPI or WebSocket on localhost) in 2014. After Microsoft deprecated Windows XP, they established "Windows XP Task Forse" to respond security issues with Windows XP computers on government agencies. Yeah, this was fairly late, considering MS declared the Windows XP deprecation schedule in 2007.
IE/ActiveX/Java Applet/etc algorithms aren't still completely deprecated in Korea. NEIS, a giantic service used by every K-12 school to record and manage education-related information, still uses the technology based on Internet Explorer by using IE compatibility mode of MS Edge. Repeat, EVERY K-12 school teacher and staff uses this service, with IE compatibility mode.
I want South Korea to adapt new technology and deprecate old one more in due course. I mean, they should accept TLS provides decent end-to-end encrpytion, and they should recognize Triple DES is deemed unsafe algorithm.
This happened here in Brazil as well, perhaps for similar reasons. Most banks require users to install a "security module" in their computers in order to even log into the bank website. Everyone does this unquestioningly, there's even packages for Linux.
In my experience, this software caused massive performance issues. I tried to figure out why by reverse engineering one of these things and it turned out it had a Windows driver that intercepted every single network connection. Literally indistinguishable from malware but this is apparently considered acceptable because banks have a "legitimate interest" in preventing fraud or whatever.
We have a GDPR-like law in effect now, not sure if banks can get away with this anymore. I certainly hope not.
To quote myself…
> Everybody knows that the systems are absurd. This is basically a countrywide legacy that we’re figuring our way out for ~30yrs.
> When the idea was first proposed, it was when IE didn’t have a yes/no dialog to ask whether to load native code or not.
> When IE first added ActiveX confirmation dialogs, banks instructed customers to press yes. When IE deprecated ActiveX, banks didn’t remove their 20-yr old code straight away; people were advised to turn on ActiveX support from advanced settings (they added step-by-step instructions to help people). When MS finally ripped out ActiveX, banks copied their ActiveX components into a separate executable that runs a localhost server.
I’m sure that if it wasn’t iPhones, South Korea would have been locked into this legacy for a lot longer. (In fact, we once had versions of these programs for Android as well! iOS didn’t allow this (thankfully).)
And yes, this might seem silly considering the garbage fire revealed by TFA, but maybe they can use this crisis to jump one extra generation over that security threat too ?
Or: they provide .pkg file to install similar program.
Most of them want sudo. They use root permission for various purpose, but the most impressive one for me was registering their CA certificate on Firefox root store, to support WebSocket over TLS to localhost on Firefox.
This basically reveals that the pretext of this being primarily about increasing security of the connection is not really what it is about.
From having read about this, I think it is completely fair to classify this as spyware.
At the end of the day, it's up to the S. Korean govt. or regulator to make the changes necessary to get rid of this nonsense. The govt./regulators have other issues to deal with so these S. Korean 'tech' companies get to make a mess of citizens' computers and privacy. It's been well over 2 decades of crappy S. Korean software like the keyloggers and whatnot and no end in sight.
If S. Korean citizens cared, they would force the politicians to do something and it would change. They don't, so it doesn't change.
A LOT of Korean citizens cared and got angry with this issue. So governments, agencies, and. yeah, "security companies", finally decided/declared to deprecate ActiveX-fu softwares and follow Web Standard.
We didn't expect WebSocket on localhost.
First of all, thank you very much for informing about this issue. I still remember reading the article you wrote back in 2007, and it really helped me navigate this situation.
I doubt that people in South Korea care so little about it however. Otherwise articles citing an unnamed “famous hacker” about how all of this isn’t really bad and how I misunderstand the domestic security market wouldn’t have been necessary. It seems that lots of uncomfortable questions are being asked right now.
Whether this will be sufficient to produce some real change for the better is a different question of course. I sincerely hope that it will.
It's pretty hard to find places you can order in Korea, or from Korea, that don't require a Korean phone number. There are services and stores that exist just to buy things from other places in Korea and reship or resell them to people both in and out of the country, just because people don't have Korean phone numbers.
Even online purchases like audiobooks often requires a local phone number.
They sure make it hard to spend for any non Korean to spend money.
And it's not every site, there are some huge retailers (www.aladin.co.kr for example) that do not require it. So it's got to be just that most websites never bothered to build a checkout process that works without a phone number?
The website silently mangled my phone number into a local number.
I had to e-mail them and tell them "hey, this is not actually my phone number, just some number from your own country that may or may not exist."
The phone number is typically required for real-name verification. Pair that with the low character limit above and a lot of stuff just breaks.
I think non-Korean customers just are not much of a consideration for Korean companies unfortunately.
I know sometimes it's because of legacy ASCII protocols in finance/airlines (but sometimes it's just bad databases/regexes). I know how to fix it, but please just don't say in the error message that my name is "invalid".
What I heard was that payment providers charge higher fees for allowing foreign cards, so website owners (who focus on domestic business anyways) just won't bother.
Here at least that doesn't seem to be the blocking issue. Or at least I often see foreign CC payment options in the list, but if you try to use the option you still need a Korean phone number in the checkout process (and they confirm with an SMS, you can't just type in whatever.)
Not that banks in other countries are much better with their reliance on mandatory (or nearly mandatory) smartphone apps.
They used to have an actual object generating numbers, but to save money they moved to SMS, claiming it was to follow an EU regulation (which I've read, and mandates the exact opposite).
A few of the newer online only banks are simply mandating their apps, making them exclusive to people who own (recent-ish) Android or IOS smartphones.
They aren't going back to SMS though. That's really a thing of the past now.
Not only that, but typically also their device ID features. So, for example, your banking app won't work on LineageOS with some free re-implementations of GApps.
https://wiki.lineageos.org/gapps
https://www.reddit.com/r/degoogle/comments/h06x5i/bank_app_w...
For me, mandating a mobile app is a deal breaker.
"Open" GApps for custom Android builds are not open re-implementation. It was a middle ground between ROM communities and Google reached some decade ago, to disallow inclusion in the ROM and limit redistribution to forms and channels agreed upon.
Every bank app I've looked at here is full of annoying spyware and plugs for third party services. Even on the home screen.
Apparently they do not think anything is wrong with taking an app that is supposed to be your personal wallet, and putting ads in it. Watch you can't turn off, and which keot growing. I complained, but they never did anything. And yes, putting integration for third party services that you can't turn off and which appear right between your own accounts, those are ads, and someone is making money off that.
So I stopped using it. They can go f themselves. It's bad enough that they charge you to hold on to your own money... but worse, they don't even treat you as the customer anymore.
I have multiple bank accounts with different banks and upgrading my phone is an absolute nightmare because of apps like this.
TOTP was great as I could generate codes on multiple devices and back up my setup codes. Now I’m forced to use my phone, a device that is easily lost or stolen, and restoring a new phone from a backup generally doesn’t transfer the keys for these types of apps (for “security” I guess) so nightmare is probably putting it nicely.
I’m surprised more people aren’t complaining about all of this proprietary/DIY security. Rolling your own is almost always a bad idea - we have open standards for a reason.
Mostly because it costs them money and doesn't allow them to collect data.
They wouldn't care that it's not encrypted.
What data? This is your bank, they already know exactly when what for what amount you're buying because you're doing it with their card. There's no other data they can reasonably get away with collecting.
As it says in the article, the application doesn’t check at all which website connects to it. It seems that they rely on their obfuscation, hoping that only eligible websites will be able to decrypt the data. Which, quite frankly, is a stretch.
Yes, developing such an application would be fairly easy. From what I understand however, South Korea has laws against reverse engineering. So openly distributing this application would probably be risky, asking for lawsuits. Which doesn’t mean of course that no cybercrime gang (particularly those specializing in banking fraud) has such an application.
To me this reads as not mandatory in the broadest scope, but needs to be on whatever device people use for online banking.
Losing access to several necessary systems basically makes it mandatory.
Even if you could buy a burner device to access those systems, the average person will not - and that's the problem here.
Quite a few people living in South Korea say exactly that: they keep an old laptop around only for online banking. And they try to avoid whatever else requires IPinside and similar applications.
This solves the issue at least partially on the individual level. But most people will in fact not do this.
To me this ambiguity leaves the door open for challenges to the label "mandatory spyware" as a blanket label. With the ambiguity open, a plausible scenario is this: Only banks enforce IPInside, and Koreans can access full banking services from their mobile Android and iOS devices (with IPInside installed), meaning their laptops and PC's wouldn't need IPInside installed. Meaning: the label mandatory would be an overstatement. I'm not against the label mandatory, if... These gaps in knowledge are filled in with more info (forgive me if I it was clearly stated in the article for all to see! I read it the best I could but on mobile so who knows what I missed).
It may be better than when authoritarian countries do it because the consequences are not that severe, but that's far from accepting it.
If anything, it reveals just how many things are not up for voting in our democracy - because people will definitely vote down spyware whose obvious target is us.