South Korea Still Paying The Price For Embracing Internet Explorer A Decade Ago
techdirt.com
techdirt.com
http://www.kanai.net/weblog/archive/2007/01/26/00h53m55s
Why was SEED developed in the first place?
South Korean legislation did not allow 40 bit encryption for
online transactions (and Bill Clinton did not allow for the
export of 128 bit encryption until December 1999) and the
demand for 128 bit encryption was so great that the South
Korean government funded (via the Korean Information
Security Agency) a block cipher called SEED.http://www.w3.org/2012/webcrypto/
If you are interested in helping to get S. Korea off Active-X, your help in getting WebCrypto developed and standardized is probably the best thing you can do (as a developer.)
(I work for Mozilla but not on DOMCrypt.)
The problem is that the law still requires these websites to use "firewall" and "anti-keylogger", so they just implemented those programs for Mac and Linux in NSAPI form. This is still far from "web standard", but at least they are trying. =(
See http://en.wikipedia.org/wiki/Export_of_cryptography_in_the_U...
By classifying it as a munition and using those laws. Which don't apply to books like "Applied Cryptography" by Bruce Schneier, due to the First Amendment. Even if they have source code printed in their appendices.
Oh, you mean effectively? Uh... I suppose we'll have to get back to you on that.
By classifying it as a munition...
Oh, you mean effectively? Uh...
Back in the day, someone printed up a T-shirt that had a 4-line Perl script that did RSA and so was a munition. (Later reduced to 3 lines.) There was a barcode that contained the bits for the script, which you could use to automatically read the program into a properly configured computer, so the T-Shirt was indeed a munition under those regulations.
As always, the cause is that you are never smart enough to roll your own encryption standard. Any time someone asks you to roll your own encryption pinch yourself and smash your head on the desk, if you still want to code it smash your head again.
What is insane and scary is that anyone is forced to use the governments encryption app.
Do you have any source to back that up? I talked to some security people and they used to tell me, although ActiveX is a pain, we are having much less damage from Internet banking. I'd love to have something that says this isn't the case.
> That and the government's encryption app is closed source and not peer reviewed.
The encryption algorithm itself (SEED) is open and is peer reviewed.
This is where Korea's rather boneheaded form of nationalism causes problems:
> "The Korean government took a great deal of pride in that breakthrough security technology," Kim said. "They wanted it to be widely used in Korea."
is there any other form?
Remember the Clipper chip?
A warning to governments who put forms in ms office formats on their web sites.
They have all the precedents and all the advice that they could ever want, all pointing to the disastrous effects of centralisation and monopolies and yet they keep pushing for them. I, for one, find it hard to sustain the belief that these kinds of decisions are 'innocent mistakes'.
Unfortunately the more likely explanation is that they care a lot more about their own power enhancement than about the general benefits of their subjects. I don't even mean any particular government. This is endemic for them all.
Additionally, in the particular case of encryption, they are terrified that someone might criticise them behind their backs and thus they keep trying to control encryption.
Mandating standards is one of the things that a government should do. The Korean government did a job with downsides in this case, but given that the decision was taken in the nineties, it was not that bad.
At the time, the US government had embargoed all the cryptography with keys that had more than 40 bits. What Koreans attempted was to workaround this limitation.
Even at the time of the embargo, there was PGP and it worked just fine. The problem was, and is, the close relationship between the bankers (and other monopolists) and the government(s), whereby the public is forced to use what they mandate, rather than the other way round.
In a different world, it would not be technically difficult for people to download an open source application a la GPG, generate and keep their own private keys, and the governments, banks, and software monopolists working with it, rather than against it. The banks could look up their customers' public keys to establish secure communications and the big software producers could make it easier to use. All it needs is some goodwill, sadly lacking as it weakens centralised control.
Do I think that it would have been better if no government intervention had occurred? I have no reason to believe that.
A bylaw was created that said government Web sites must
accommodate at least three different Web browsers
They do; IE6, IE7 and IE8.Moreover, the ministry of education is a big costumer of MSFT, giving kids and teenagers early exposure to MS tools (think the 90s, where not every kid had a computer at home).
The problem is that the tech sucks. It's based on two components:
* A keychain code generator (if you lose/forget it then you're screwed)
* A Java applet where you enter the code from the keychain code generator
So, if you either don't have your code generator device with you or are on something without Java (like a smartphone or tablet), then you're screwed.
Thankfully the use of BankID isn't required by law so a few banks offer other way more practical ways of authentication. My bank sends a random code to my cell phone through SMS that I have to enter in a normal web form. Much simpler and works everywhere.
Although in general I agree with the premise you put forward, it shouldn't be a principal applied without thought.
GSM is a standard. No one specified or forced any particular implementations on anyone, as far as I know. Unlike this South Korea SEED approach.
The problems of monopolies arising through network effects, and the negative effects of the lock-in that results, are familiar enough.
But then it goes on to talk about the problems of a monopoly that was created not by network effects, but because of governmental dictate.
The lesson here ought to be that government ought not to be so heavy-handed, because it can't change its own regulations quickly enough to address the naturally-changing business and technological environment.
Let's assume Microsoft had nothing to do with convincing South Koran government it would be a great idea to use a government dictate to further their network effects.
The real lesson here is that governments should never get in bed with the private sector and, when they do, both sides should be punished. Severely.
Oh, that's why Chinese sellers don't respond to complaints about their web site not working in FF. They think you are a lunatic fringe.
Most "good" laws in this area would specify the desired outcome (secure online transactions), and let people devise their own methods.
An analogy: this is like the Korean government mandating banks use a specific model of vault door (Securico 2000), where the rest of the world merely state "banks must ensure vaults are secured to a reasonable standard". If a fault exists in the Securico 2000, most banks will (eventually) update, lest they be sued for negligence in event of someone breaking into the bank and stealing valuable property. Korean banks would be perfectly safe from legal recourse, since they are following state law.
Of course, this is not unique to government-mandated technology. Monopoly groups can cause the same distortion e.g. Verified by Visa.
Denmark has quasi-standardized on a two-factor online security solution, NemID, which works fairly well, and is now used for login to most government services and most banks. Previous to the government getting involved, there were some truly horrid ActiveX and Java plugin solutions in use at most banks. The actual technology is developed by a private company, though; it was selected for implementation by the government, but not developed in-house.
First they tried to push digital signatures on everyone, with the idea that people should use their personal certificate to login to banks and government systems. However the banks would have none of it, because of the bad user interface (ever tried to use client-side certificates in any browser).
They then adopted a system that was a mix of systems already in use by a number of banks. Key-cards to be distributed by snail-mail and entered trough a Java plugin. Why they didn't go for a Javascript solutions is sad, but I would guess that some banks (such as Danske Bank) would have trouble adjusting.
So the lesson is probably that (some) governments are good at standardizing already (good) practices.
PS: Also note that some Companies (like Telmore, one of the largest online shops), who offered the old system (client-side certificates), won't use the new because of the absurd cost associated. (They have to pay per registered user, not by how much each user is using the system)
And anyone who manages to get their method entrenched can grow a de facto monopoly, with pretty much the same result as in this case.
At the very least, a "good" law should provide a standard interface and mandate interoperability.
From a users perspective this is really bad, since you have no idea if the installed programs are valid and what they actually do.
In addition to that I once tried using my bank's online banking app for the iPhone. It took me quite a while to figure out why it wasn't working, because you cannot actually use it without going to the bank and receiving a valid encryption key for your access.
Then there's online purchases in South Korea, which are of course most of the time limited to IE only again as well. It also often requires having a South Korean cellphone number, since activation codes are sent via text message instead of email.
Setting up an account for a website service also means providing a Korean ID number, due to their online access policies. Overall it took me the course of a day simply trying to order something from outside Korea and then failing at the last step due to the site not accepting foreign credit cards.
Overall the online experience for South Korean sites is extremely bad. If you're not using a Windows PC there, then you're out of luck without using VMs or a separate Windows partition on it.
I don't think it matters if he wins or loses. He can catapult this issue up high enough to trigger another governmental [over-re]action to undo the damage done.
Are you kidding?! A Windows monoculture is on the basis of his businesses.
Maybe. At least for the particular case of an online purchase from a South Korean vendor. But when you look at a company like Samsung Electronics, which is "the world's-largest IT producer" according to Wikipedia, and makes very popular Android devices, I'm not too concerned about innovation in South Korea.