I found a 1-click exploit in South Korea's biggest mobile chat app
stulle123.github.io
stulle123.github.io
For some context, you can't live in South Korea and not use Kakao, even your grandma has it.
So the fact that they have so many holes in their security is a cause for concern.
You grandma isn't going to know a fishy link when she sees one, especially with this exploit where domain looks legitimate.
A contributing factor is the hierarchical work culture in Korea. You boss gives you a deadline for a feature which is treated an non-negotiable so you cut corners to get it out. Your boss can't 'see' security vulnerabilities, but can see a UI. So you get told "good job" and then get given the next unachievable deadline.
This all amounts to an app full of security holes, and until Kakao stock drops because of it, they're not going to address it.
Kakao used to be a cool startup, but they've been trying hard to emulate the chaebol once they became successful.
This is very much not the case - Startups are quite big in SK because the government gives them lots of funding.
Source: I worked at a South Korean startup. Fair warning to other foreigners, you will have to make _a lot_ of sacrifices.
They need funding mainly because otherwise the govt sector and chaebol would outlive them. It greatly depends on the exact circumstances though. (Source: Had been in several startups with varying degrees of funding.)
> Fair warning to other foreigners, you will have to make _a lot_ of sacrifices.
Mainly because most if all people in Korean startups are necessarily Koreans. The same thing happens whenever many members share the same background, not just the nationality.
Exactly. All that funding and the associated paperwork, not to mention the adverse incentives it brings to the table, help to turn the Korean startup ecosystem into yet another old-fashioned, government-controlled economic sector.
We all call each other the same honorifics, make our offices cute and comfy, and try not to have a visible hierarchy. But at the end of the day, it's the government that tells you which projects will be funded and when you should submit screenshots of the deliverables. Angels? Yeah, they exist, but where do you think half of their money comes from?
Source: also a South Korean startup.
As a foreigner living in Seoul, working for US startups, and eyeing creating a US-styled startup in Seoul in the future, what are the sacrifices you have in mind?
On the security side though: I don't think it is a work culture at the play because major IT companies in South Korea---often referred as to the initialism 네카라쿠배, for Naver, Kakao, LINE, Coupang and Baemin operated by Woowa Bros---are known for much better work culture and higher compensation than the nation average [1]. It is probably more like that these apps are domestic and hadn't been scrutinized enough compared to globally popular apps.
[1] But still lower than US or even some Korean startups in my experience.
south America and most of Africa was taken over by metabook whatsapp. you can't even schedule government appointments without one (which then require a mobile phone number, which then require all the data each govt require for a mobile phone sim purchase)
Europe requires sms plus a apple/google validated app and stock phone. you can't access most eu or eu commission or local gov services without it.
but it all started with "it's fine, i still have X fall back working". but we only cry about china dystopian techno state...
Which European central government services require you to use an online service or app, with no voice, paper on in-person fallback. I can think of one in the UK - my council's resident's parking permit system
try the SSO solution for all things eu commission for starters
https://webgate.ec.europa.eu/cas/login
you have the option of two badly coded apps, which refuse to run on android without stock rom and google play services. it gatekeeps both internal services as well as access to public grant offers and financial help.
it used to accept sms, and it still show in some flows, but is forbidden on most common cases now.
The GP comment said "Europe" not the EU and the UK is in Europe so a valid counter example.
The main govt services I know of that require mobile apps are lcoal govt ones for parking. Everything else works in a web browser. As far as private sector services go I know of Virgin Money and supermarket loyalty cards.
I haven't interacted with the EU sites other than just looking up random things (so no login required).
But French government services (both national and local) work perfectly on my Firefox/Linux PC without any kind of interaction with my phone. I've never actually tried this, but I don't see why they wouldn't work on any phone browser, stock or otherwise.
I haven't tried them all, obviously, but I'm thinking vehicle registration, voter registration and tax service (both personal and corporate).
They have an SSO scheme, France Connect, which is used for multiple services, so I expect that if it worked for the ones I've used, it'll work for the others, too.
The private sector can be more of a clow show, though, especially some banks.
If only that happened only in SK.
It definitely happens in the west too. Maybe its worse in SK because of the culture, but its definitely not unique. The problem of the boss or the customer seeing the UI but not security issues is universal.
If you've ever spent a few years at any decent-sized white collar company in the US (tech, finance, consulting) you know it's the same in the west. Especially FAANGs. All these mid-level engineers are just yes-men trying to suck up to their VPs to get in the next promo cycle. The western companies just have better marketing about "flat hierarchies" but it's all PR talk and lip service. Some PM or SVP drops some mandate and no one ever has the balls to question it, they just grumble and do it.
The saddest part is that these tech bros actually believe the marketing they are fed about their company cultures, and it breeds this shallow superiority complex and so whenever something negative about Asian companies comes up, you get comments like this citing this 'go-to' rationale about hierarchy.
It's actually kind of sad these guys don't have the self-awareness to critically examine what they are told vs. what reality is.
I was forced to make an account on the mobile chat app in order to log into their rideshare app, on a recent trip to Seoul. The UX was not great... not to mention that it was mostly in Korean. I had a lot of trouble. They didn't strike me as the most professional operation..
KakaoTalk, KakaoTaxi, KakaoBank even (bank obvs not for foreigners without local ID numbers).
The Kakao Metro map app is the best of its class too.
Suffice it to say: for foreigners without a Korean ID number it’s a definite no and with a Korean ID it’s a likely no.
And good news: they’re not called “ARCs” anymore. No more “Alien Registration Card” extraterrestrial stigma. Now it’s just the regular stigma.
However, I have yet to read that any of the online banks have changed their procedure to take advantage of these changed regulations.
It also accepts non-Korean credit cards, while most online apps in South Korea do not.
It's rather inconvenient for non-Koreans but you were never the intended audience nor is there much care for foreigners these days-there is growing hostility towards foreign tourists who have flocked to Japan and Korea in recent years.
the grandparent has invented a fake problem (data regionalization, as though it cannot be addressed with regulation) and has conflated a nationalist-socialist desire to replace a foreign private enterprise with a nationalized public one. it's nationalist because it assumes that the nation needs to own it, and socialist because at the national level a public solution is proposed.
the solution, in turn, doesn't actually solve the regionalization problem unless the state organization running the nationalized ride share app is required through further legislation to keep the data local -- the same legislation that would be needed to regulate private entities, except now it's the government regulating itself since the public national ride share app is operated and owned by the government, and is now open to all the problems of corruption that plague every command economy.
But by all means, be more like North Korea, South Korea. Just nationalize everything. You don't want American influence. Those American monopolies and American dollars have really made you worse off in the last seventy years. /s
Data sovereignty/regionalization is not a fake problem. Many governments around the world are trying to keep foreign companies from accessing their citizens data.
A sovereign country wants to create its industry by keeping foreign companies out isn't communism. Much of the West does this already and uses regulation/fines/antitrust lawsuits to keep em down.
Most countries are incapable of this and when they do try they do a worse job.
My government has a website that allows you to fetch a person’s voting centre by knowing their ID number. Our ID numbers are sequential. Therefore you can use that website to get approximate location for literally everyone.
My government also has a website to request passports online. I was playing with it and it turns out they have an open GraphQL endpoint that lets me query billing transactions for _everyone_.
But sure the software was made in my country.
Approximate address, surely. Addresses are ... usually not very secret in the first place, though? It'd be absolutely fascinating if your government not only tracked everyone's location but assigned their voting center by current location, but, well,
That's exactly what happens in Turkiye. I assume GP is there.
The voting centre is typically the closest public school to where you live.
So when I say location here I mean the neighborhood where you live.
Also the main concern isn’t the government. They clearly already have the data and will always have that data. They also have the actual address of people.
The main concern is literally anyone can access the data and this thread is about countries protecting PII lol.
As you point out it's hard and few can do it, so getting more common open source platforms would be a natural evolution. Then relying on global providers that act as a service developer instead of a service owner would still be a huge difference.
Everyone in this thread seems to thinks government is able to get things done. That is not what my last 40 years of life has shown me.
In America, before the Internet took off, every year everyone would get a book called the "white pages" that had the name, address, and phone number, of everyone who lived in their city.
The American view of privacy is that "openness makes for a civil society".
Although one can argue that hasn't been working out well for us lately ..
Likewise, marriages are publicly recorded and accessible online, as are all property purchases, births, deaths, and even property tax payments.
Though for some reason we consider income taxes to be super secret. Everything else is public, but not those! (How much cash someone put down to buy a house? Public. How much money that person makes? Not public. How much money everyone donates to politicians? Public.)
Lots of Russian stuffs on the Internet come through Telegram, meanwhile China has Weibo and TikTok, Korea does its thing in KakaoTalk and Facebook/Insta, Japan uses LINE along Twitter/Insta instead, so on and so forth. Everyone could be on Facebook, but that isn't what is going on.
The Interweb isn't so global, and English isn't the lingua franca of all communications. It's just the perception one experiences through an American door, though the Web do tend to be more developed in en-US.
I think some tiny amount of protectionism can be necessary to get a domestic industry started, when it is important for reasons beyond giving access to the best products like national security. Especially in edge cases like competing with foreign companies with the backing of their state government or an international market that has degenerated to a monopoly. But ultimately free trade makes better products and international consumers richer and is the desired end goal, not every nation rewriting the same tech stack and providing local flavors of software solving similar problems.
Why not? Isn't Diversity good? Wouldn't it be nice to have multiple colors, implementations of things rather than the monopolistic (and probably American) beige?
That whole process works in reverse too, where I have to reach parity with the large multinational company on all the features the domestic audience cares about. That last step is usually the first one to be missed when a government hands a monopoly on a tech vertical to a local company with protectionist policies. (And often they don’t just do it to insulate them from foreign competition, they will end up insulating them from domestic too as an artifact of the way these relationships reinforce themselves)
So, the state should intervene to help level the playing field to reach fair competition. In practice though it rarely stops there and instead works to insulate the domestic company from any competition. Which results in inferior products.
It is not diversity to have many people reinventing and maintaining essentially the same wheel. Exceptionally, this is necessary for national security purposes, but in the common case this is actually a poor deal for local consumers who prop up a worse product.
iMessage is a better experience and also degrades gracefully to sms for people who aren’t on the platform, unlike almost all other messaging apps where I have to make sure they have the app installed.
Facebook messenger has like 50% market penetration with its own suite of features. Snapchat is next and offers a very different user experience.
Apps without compelling reasons to exist like Google allo lose.
Why do you think foreign companies are automatically better? Is American software written by non-Americans automatically best? I find this to be incredibly arrogant.
Not to mention the colossal waste of effort in engineering hours, the disparity in quality between rich and poor countries, etc.
Reuse is good. I would rather see open data and open protocols too, but look at Cambridge analytica, a scandal that was a direct consequence of giving people control over their data!
Most of its hardware and yes US has slapped tariffs on Korean EVs to boost their own.
Koreans prefer Naver over Google because its interface offers a lot more than Google. It's more of a portal site with social verification.
Largely agree with this, but this
> do not have access to Korean data
> safeguard PII of its citizens
Is incredibly ironic on a post "I found a 1-click exploit in South Korea's biggest mobile chat app". Zerodium pays $1 million for a WhatsApp (the Western equivalent of Kakaotalk) one-click exploits. As a consequence, any new exploits must be incredibly involved, else they'll already have been cashed in (and patched after being reported/exploited). Whereas this Kakaotalk exploit is trivial.
Americans share their PII with the FAANGs, us in Korea share it with the entire world because, as this article shows, security is absolutely atrocious.
Google launched in 1998. Naver didn't launch search until 2000. Copying American tech companies but targeting your own market is a common theme (see China, Latin America, Southeast Asia, etc.). Let's not pretend it's not the case here or Korea is somehow special.
Yahoo was before Google and Japan has been on Yahoo forever. Yahoo is American but they engorged on it in Japan.
Google is just a copy of a copy.
Koreans and Japanese were definitely ahead of the West in both phone and internet uptake.
I think it’s great how these managed to thrive, despite increased competition from multinational companies. In many other countries, local tech companies seem to have become nearly irrelevant over the past decade, which is a sad to see.
Funnily it lead to creation of PC F2P gaming culture too for some reason.
>Due to restrictions on the export of cryptography from the United States, standard 128-bit SSL encryption was unavailable in Korea. Web browsers were only available to Koreans with weakened 40-bit encryption. In the late 1990s, the Korea Internet & Security Agency developed its own 128-bit symmetric block cipher named SEED and used ActiveX to mount it in web browsers. This soon became a domestic standard, and the country's Financial Supervisory Service used the technology as a security screening standard. ActiveX spread rapidly in Korea. In 2000, export restrictions were lifted, allowing the use of full-strength SSL anywhere in the world. Most web browsers and national e-commerce systems adopted this technology, while Korea continued to use SEED and ActiveX.
https://en.wikipedia.org/wiki/Web_compatibility_issues_in_So...
However, in better-run and not-so-corrupt societies like Korea, it's not necessary and probably downright harmful.
South Korea was under varying levels of dictatorship from the Korean War until the Sixth Republic in 1987. Roh Tae-woo, the first president after authoritarian rule, was imprisoned for corruption. Roh Moo-hyun, the President from 2003-2008 was investigated for corruption and died by suicide rather than face charges. Lee Myung-bak, his successor, was imprisoned for corruption. Park Geun-hye, his successor, was imprisoned for corruption.
I don't know that South Korea is the poster child for a "better-run and not not-so-corrupt" society.
It's not a poster child, but the US sets such a low bar that SK looks great by comparison.
Note also that the US isn't so visibly corrupt at the federal level; it's at the local levels where it's really no better than the typical poster children for corrupt countries. Taxis are a completely local (municipal) issue.
The Korean government explicitly chooses companies for these things. And those companies, Chaebols like Samsung, choose the laws.
If these Korean apps were so good, you would expect them to penetrate foreign markets. But they don't.
https://www.techdirt.com/2023/12/06/dumb-telecom-industry-ba...
Just like how British car companies collapsed when foreign competition entered the market on equal footing, these companies will disintegrate if forced to compete.
https://www.latimes.com/world/la-xpm-2010-dec-01-la-fg-south...
Dumb reasoning. Their apps are targeted at Korean life on purpose. Their app being good or bad is irrelevant.
The reason American apps penetrate the world usually is because America is a superpower that has almost colonised the web.
I live in the USA and EU, and the reason that I prefer a Samsung display in almost all cases is because it is the best product. Korea has not colonized us, but the product is often superior, so that is why I buy it.
Why is it that Korean software cannot do the same? I find it very interesting, and I mean to ask this in a very neutral/curious way.
That's not the same for most internet apps.
They can do the same, they don't want to nor need to.
No way, LG displays are better.
(In case it's not obvious, there's a joke here.)
Apps on the other hand strongly reflect the philosophy of usage, control, privacy etc, and the design aesthetic of their creators. Different countries/cultures have radically different philosophies, and old countries have aesthetics that go back thousands of years. Using apps from the creators of a different culture almost certainly causes significant friction with your own culture's philosophy and aesthetics.
To give a related example. I don't know Korea, but many in the English speaking world are marginally know of Japanese TV shows - you know with the crazy antics. Imagine that you were forced to consume only that form of TV, and how jarring that would be compared to your own philosophical and aesthetic inclinations. The same with Apps.
The internet wasn't some terra nullius that America took over.
>(you are using the word to invoke implications of historical atrocities, etc.)
No, I'm using it to invoke it's actual definition and the meaning it holds. Not everyone is an American political weirdo.
Love how the word "colonise" is thrown out without any thought.
Please tell us one example where America enacted a hostile takeover of a Korean site, and extracted its resources solely for the benefit of American interests.
>Please tell us one example where America enacted a hostile takeover of a Korean site
I don't think you understand what the word colonise means nor what my comment means...
And it is also partially owned by Softbank.
Would that indiciate that Korean software companies are only able to penetrate one economy at a time?
That would be a very weird, but interesting thing to investigate.
So I am simply surprised. My knowledge must be incredibly out of date.
And I don't think it takes conspiracy theories to explain it, maybe users don't like platforms that isn't dominated by similar users of their primary language, or maybe there are something else that prevent app experiences optimized for two distinct cultures at the same time.
With some amusing exceptions: doctors are exclusively on WhatsApp; older (60+) people are often only on WhatsApp (and pre-Microsoft Skype before that).
Having traveled extensively in these places, I always theorized it was due to UX behavior aligning well with the local languages. While the countries WhatsApp dominates speak different languages, they all use the Latin alphabet. In Russia and APJC there are many non-Latin alphabets used and those languages may also use different directions for writing/reading than Romance and Germanic languages.
What does the seemingly very common-sense fact that a South Korean app was "mostly"(?) in Korean have to do with the UX or with it not being "professional"?
What language were you expecting the South Korean app to be in, French?
Imagine supporting the most common language in the world. CRAZY right?
https://developer.apple.com/documentation/xcode/supporting-m...
Why are you fixating on supporting the 2nd most popular language, shouldn't it support the 1st most popular language first? Or why not jump straight to the 3rd?
also, if you add internationalization support for 1 language in your app, it’s trivial (these days) to add other languages. My point is they should just add support for other languages, like chinese, japanese, english, etc.
More users = more money?
>Kakaotalk is in English, French, German, Indonesian, Italian, Japanese, Korean, Portuguese, Russian, Simplified Chinese, Spanish, Thai, Traditional Chinese, Turkish, Vietnamese (https://apps.apple.com/us/app/kakaotalk/id362057947)
I used it earlier this year in Korea, although it did have a hard to get to setting to change your language, many many things were still in Korean.
It is very difficult to navigate, but I asked for help and a native was able to figure it out.
Still more usable than Google Maps though, which will only give you a not so good train schedule. No walking directions at all.
Localization is hard, even for companies that spend a lot of time and effort on it.
It isn't just string replacements!
(X) Positional *tracking* is brittle, equal battalions in range XNUMX it expenditure a time effort per batch on item.
Object is incorrectly threaded return request is here.
[FINE] [Returns] [Add...]That's interesting, because Google Maps here in Japan is absolutely fantastic: train schedules are always correct (and updated with delays etc.), walking directions are good, etc. I guess having a big office here in Tokyo is a big part of this.
my point is it seems like good business sense. strange they haven’t done this.
Can you elaborate on how easy it is, please? Say for a web application or a native Linux application?
Booth android and iOS app building frameworks will try to force you into using variables for every rendered string (allowing you to change them easily and in one place - f.ex. based on user / device settings).
To wit: une appli en Français serait facile à comprendre pour un anglophone.
UX patterns are different in Asia by the way.
Also majority of tourists to Korea do not speak English, so it’s a little weird you think English should be prioritized over other Asian languages
I would be interested in elaboration on this.
> so it’s a little weird you think [thing they definitely did not say they think]
Uh huh.
I hear this comment time and time and time again and I wonder where it comes from, I'm happy to show literally years and years of uber receipts from South Korea.
> Similarly, even though the messenger app does have integration with its payment platform (cleverly named KakaoPay), the service itself lives in a dedicated app.
Just like WeChat, KakaoPay is fully integrated in KakaoTalk to the extent that the large majority of users use KakaoPay only through KakaoTalk. The existence of the separate KakaoPay app doesn't have much of an impact. You can transfer money, receive money, and make payments through KakaoTalk, without using the KakaoPay app.
User sends message via client. Client fumbles the recipient id. Message ends up at the wrong recipient.
Examples: incorrect recipient ID attached to contact in list where users selects recipient. Buggy selection of multiple targets in the selection UI due to incorrect touch event handling. Incorrect deletion of previously selected and then deselected recipient from recipient array of multitarget message. Or if working low level even a good old off by one error and reading out of bounds data for the recipient list (though that one hopefully should trigger a faulty send request due to other stuff no longer matching). There is endless examples.
The server can't really safeguard against the client providing a legitimate send request even though the user intended to send it to another recipient.
Yeah, I don't know how they manage to get bugs like that, but it's happened
And Telegram has been so far the most reliable, feature full and easy to use chat app I have had to use.
And in an Apples-to-Apples comparison, WhatsApp fared far worse than Telegram on privacy, and not to mention its parent company.
The only benefit I can think of WhatsApp has is claiming to be encrypted by default. So I dont need to press an extra button. I just have to take their word for it.
I'd like to see that comparison. Considering that WhatsApp is end-to-end encrypted, and Telegram persistently stores almost all of their users' messages on their backend in a way that lets them read them, I find that very hard to believe.
> So I dont need to press an extra button.
Nobody presses an extra button, especially not one that opts you out of multi-device support.
I don't think it's reasonable to expect them to actually be e2e encrypted.
Espacially since Zuckerberg has many years of poor track record for privacy, and made the famous quote "they trust me the dumb fucks"
For contacts: I have no expectations of any contact privacy on WhatsApp. It's known and documented [1] that they upload your entire phone book for contact matching. Private set intersection would be better, but I don't see anything sneaky going on.
Audio, video, cameras: What are you referring to?
> What makes the true believers so sure their WhatsApp chats are really E2E encrypted and FB cant decrypt them and isnt scanning at the edge?
The amount of scrutiny they're under from security researchers worldwide, and the fact that many governments are currently throwing a fit about not being able to gain access to the data either.
2016 Audio: they listened to what you did through your microphone until they got caught
https://www.nbc4i.com/news/spying-secrets-is-facebook-eavesd...
2019: Facebook caught activating camera without permission, to spy on you
https://www.pcmag.com/news/facebook-app-caught-activating-ph...
2020: Facebook a year later still secretly using your camera to spy on you, this time through Instagram
https://news.ycombinator.com/item?id=24514433
This is the company you are now trusting with the mere claim that WhatsApp is end-to-end secured.
2018: Facebook, not satisfied with getting its own users’ data only, bought and hijacked a VPN app in order to — wait for it — bypass encryption that millions of people trusted for ALL SITES ON THE INTERNET in order to analyze traffic and be able to get the dirt on its competitors!
https://arstechnica.com/tech-policy/2018/08/facebook-violate...
Now about WhatsApp…
Oh yeah… it’s already sending a lot of telemetry to Facebook:
https://www.wired.com/story/whatsapp-instagram-facebook-data...
And has been since 2016:
https://www.wired.com/story/whatsapp-facebook-data-share-not...
Oh, but at least the content of your messages is not analyzed by FB? Well, as far as we know that might be true, but if the other user flags your convo, it is in fact sent to Facebook:
https://www.propublica.org/article/how-facebook-undermines-p...
But wait, there’s more. Sometimes the mask slips due to People You May Know, which is the carefully guarded mix of “secret” algorithms that has helped Facebook aggressively grow beyond 100 million people:
https://medium.com/hackernoon/facebook-is-reading-my-encrypt...
https://gizmodo.com/people-you-may-know-a-controversial-face...
Mark Z knows what’s up:
https://www.theguardian.com/technology/2016/jun/22/mark-zuck...
https://amp.theguardian.com/technology/2018/apr/17/facebook-...
Telegram has NEVER tried to do any of these types of things.
So, given a choice, would I trust Zuck and co, or a guy who literally had to flee Russia because at great personal cost he had refused disclose the identities of the Maidan protestors, and losing his company to their Mail.ru conglomerate?
https://www.forbes.com/profile/pavel-durov/
https://www.quora.com/Why-was-Pavel-Durov-so-careless-in-his...
https://www.cnn.com/2016/02/23/europe/pavel-durov-telegram-e...
The answer is: neither (although Pavel Durov is like 1000x more trustworthy in my opinion).
https://itc.ua/en/news/durov-boasts-that-telegram-employs-ab...
I prefer open source software
https://community.intercoin.app/t/web3-moxie-signal-telegram...
And here’s why:
https://community.qbix.com/t/the-global-war-on-end-to-end-en...
- list the problems
- link to sources
- backup the source instead they happen
We forget too easily, and PR works wonders. I used to have such a list for Microsoft, but:
- I have to pull it of every time we talk about the new MS, because people think they are good guys now. They already forgot.
- People don't think it could have been that bad.
- I have to rewrite the list, I can't link to it. Or expand it. And I have to justify its existence and credibility because MS PR is so strong now.
- The links are disappearing from the web, so my previous proofs are fading away, slowly being replaced by references everywhere singing MS praises and stating how a saint Gates is.
The powerful are rewriting history, literally.
karmicarchive.com is available, just saying.
Russian can't affect my life as much as my gov.
The Signal one somebody has posted in the adjacent thread was definitely real and horrible though: https://news.ycombinator.com/item?id=27950763
The fact that at least two heavily-used messengers got one of the most essential things in instant messaging wrong is nightmare fuel I didn't need to have in my life :(
IT is just a series of security breaches.
> is nightmare fuel I didn't need to have in my life :(
It's a weird reaction. All software have always been like that as far as I remember.
xz: A sophisticated supply chain attack. These are known, scary, and we don't have great ways to prevent them yet.
Apparently half of all popular instant messengers at some point making the same kind of trivial but catastrophic off-by-one error: Not rocket science to prevent. I was hoping at least high-stakes apps would have better QA.
> is nightmare fuel I didn't need to have in my life :(
And if you are a developer and your software is used in any decent scale, you are unlikely to be the exception.
Holy crap !
> You must be a Korean living at home and abroad
https://bugbounty.kakao.com/home
Would have been worse if author submitted this expecting to get paid. But found out it’s limited to SK citizens.
Side note: the payouts are extremely low:
> … minimum of 50,000 won (~35 USD) to a maximum of 10 million won (~7.1K USD)
Is it for long-term game or short term gain for a small group of people
Talk about discouragement for research. KakaoTalk is huge -- the equivalent of WhatsApp for EU people or LINE in Japan. Many foreigners learning Korean use KakaoTalk to chat, so this definitely affects people outside of the country. Restricting payment to just Koreans is objectively a terrible decision, as it endangers their users for no discernible reason.
It'd be like finding a person who doesn't use electricity.
I feel that doesn't really describe it well, one should look into the respective product listings for these companies to get a proper idea of the scope of potential damages that could occur.
https://www.kakaocorp.com/page/service/service
https://line.me/en/#allProduct
WhatsApp is only just getting into the complete ecosystem side of things with Meta Pay. Google as a company is probably more representative of scale
The really interesting thing, IMO, is where Facebook went off the rails. They have the moat with literal billions of people using their apps already, they got real names, addresses, location data, in some cases (legacy Whatsapp users, people who ever ran ads) payment data, Facebook already has sort of a "shop" solution with Marketplace... but they don't seem to be attractive at all, or doing anything innovative. It's all Metaverse or whatever.
Meta's public perception was semi-centered around Zuck, not nearly to the same degree, but I can easily imagine that if they didn't pull back a bit, they would have had a hard time continuing forward with that prior image.
Not saying they can't go forwards now, just that they are being careful, to try and make a more solid, longer lasting brand. As opposed to the burn-everything approach of X.
They have the time to spend: X isn't going to ever trend upwards in public perception, Google is already there in every aspect, so the only option is to play catch-up to Google and not worry about anything else.
The way those "superapps" grow the "apps" is middle management doing his personal projects on corporate microservice infrastructure and IC hire upper management succumbing to bureaucracy. Thanks to bureaucracy, some brand integrity is maintained, and that kind of makes money anyway as company side gigs. After it goes garbage in and out of translation, the whole company doings end up on BBC as Oriental wonder superapps.
SoftBank subsidiary owns LINE. So do Masayoshi Son even know how many individual sub-apps there are or who's under who running what? I highly doubt it. And I also highly doubt a control freak like Musk can even bear that kind of situation; he'd personally dragged out a server rack out of an NTT datacenter without going through rituals and ceremonies, which made a web article by itself. None of superapp operators seem to have that kind of boss.
As a general example, department stores are much healthier in Japan and Korea, whereas in the US they were hollowed out by specialty clothing retailers, specialty makeup retailers, etc. and then finally kicked over by online shopping.
Not only that, here in Japan some of the biggest department stores also operate their own train lines, and own all the real estate around the stations. It's an extremely different way of running a business than in the US.
But they also don't have the shareholder/activist investor pressure that Western companies face.
To achieve "superapp" size, you need to have either a strong leader personality driving the push by their sheer will and vision and especially with enough authority/financial power to overrule investors - people like Steve Jobs, Jeff Bezos, Elon Musk or Mark Zuckerberg - or you need to be one of the Asian ultra-conglomerate/"chaebol" companies that have absurd amounts of money flowing through them that enterprising middle managers can divert.
Unfortunately, with the exception of the visionaries I mentioned, corporate America and Europe just doesn't have many company founders with both clear visions and a backbone, and there's (partially "thanks" to de-conglomerisation trends of the 90s and later like with German giant Siemens) nothing at all left that comes even close to the diversification of revenue that Samsung has.
Does Zuck find the idea boring? Is that why he rather do something flashy like "Metaverse"? It's the obvious model to go for and East-Asia has already made that clear since a decade ago.
Even bloody MSN Messenger 15 years ago was more of a super app than WhatsApp.
Now finally Musk says he's going to give it a go, but I reckon he'll struggle because X's penetration, as high as it is, is nowhere near WhatsApp. He's also extremely late in the game, so much that unless he starts buying up incumbents (maybe that's what he needs the $56 bn pay package for), the barriers are now incredibly high. When WeChat, KakaoTalk and Line started branching out, there was no huge incumbent in the areas they competed in.
But hey at least they actually took action…
KakaoTalk is huge. Can't do anything in Korea without it.
https://iclg.com/practice-areas/cybersecurity-laws-and-regul...
I'm German... our politicians, at least most of them are a bunch of pathologically technologically incompetent buffoons. A lot of that was masked during the Merkel era because she herself was a literal nuclear physics doctorate, but now that she's gone, it's painfully obvious what's going on.
It's similar to how weapons designed to be used against people are regulated differently from tools that merely happen to be usable as weapons.
In the concrete case of sharing tools to explore the attack surface of KakaoTalk, this is not a crime under §202c StGB as long as you do not intend them to be used to hack accounts you do not own.
Good luck to the prosecution trying to prove that you did intend to hack other people's accounts when you can point to this blog post where the author demonstrates hacking their own account and reports the vulnerability to get it fixed.
I think people who get convicted of one of the "preparation to commit a crime" crimes mostly:
1. fail to come up with any alternative explanation for their behavior
2. put their plans in writing or told someone about their intentions
Theoretically.
Unfortunately, judges who are actually fit in IT topics are rare, especially in the criminal courts. They tend to rather believe what the prosecutor tells them. I'm just happy we don't have US-style juries because that would be even worse given our collective love as a society for faxes and writing information on highly processed dead trees (i.e. paper).