Internet Explorer becomes Korean election issue
theregister.co.uk
theregister.co.uk
https://blog.mozilla.org/gen/2007/02/27/the-cost-of-monocult...
https://blog.mozilla.org/gen/2007/09/21/update-on-the-cost-o...
https://blog.mozilla.org/gen/2012/11/15/2012-update-to-the-2...
I recently had a chance to speak with some of our Korean community members and the sad reality is that Ahn Lab was/is part of the problem (they sell plugins to Korean companies who need them, which is unfortunate for a security company).
Ahn seems to be a savvy politician. He's campaigning on whatever works. I am told that he does not really care about the browser monopoly in Korea (which makes sense, sadly.)
Before the export restrictions, browsers outside the US were restricted to 40-bit RC4 (which could be hacked in a matter of days) instead of 128-bit version that was available within the US. So I think it is fair to say that it was not just some busybody wanting everyone to use his/her crypto standard.
There is no argument for passing legislation forcing everyone to use it even when better alternatives exist.
SEED is implemented in NSS (Firefox's network security backend)[0] as of 2010. I'm not sure whether or not that removes the dependency on IE, though.
Edit: looks like it's implemented in OpenSSL as well[1].
[0]: https://bugzil.la/453234 [1]: https://www.openssl.org/docs/apps/ciphers.html#SEED_ciphersu...
This is the end result of the encryption-thing, so getting rid of that would be a proper step forward, but wouldn't solve the problem itself. By now IE it's systemic :[
Likewise, a law mandating cryptography should say that banks, and other organizations that deal in sensitive data, must use cryptography algorithms and practices that are 'generally accepted' by cryptographers as being secure.
But the cipher is only one part of a very complicated situation. E-commerce in Korea is still very much crippled in non-Windows platforms, because:
1. In Korea, the standard way for individuals to authorize an online transaction is to sign it with an RSA key that is associated with an X.509 certificate that is issued by one of a handful of official bodies. (Korea was actually quite forward-looking when they made these rules. This was in the late 90s!) There are also detailed regulations about where in your Windows filesystem your keys can be stored. So there needs to be a graphical interface that displays all keys found in your filesystem, accepts a passphrase, produces a signed transaction in a certain format, and feeds it back to the web page you're on. That's a lot of work for a browser plugin to do, especially when you want to make it platform-independent. And we all know that the UI for client certificates is terribly broken in most browsers.
2. In addition, the client must be running a firewall software that meets certain requirements (Windows Defender doesn't qualify), as well as some sort of anti-keylogging software for the duration of the transaction processing (Big Bro looking after your own safety, how grateful). These rules were made because some lawmakers got scared by keyloggers or something. Not sure how effective they are, but most banks and online merchants supply these software as ActiveX controls. The thing is, you need administrator privileges in order to run firewalls and keyboard drivers. Even in Windows, online banking doesn't work unless you're using an admin account. I'm not sure whether this would be even possible with standard browser plugins on OSX and Linux. AFAIK, the consensus among Korean open-source developers seems to be that both requirements are completely pointless and therefore not worth trying to meet.
As a result of these and other complications, most banks restrict non-Windows, non-IE clients to relatively harmless tasks like viewing your balance. If you want to engage in risky kinds of banking, like paying bills and sending money to other people, you must augment your supposedly inferior security with additional (again, legally mandated) protections, such as a one-time password generator. I actually think that this is headed in the right direction -- OTPs offer fantastic security -- but the current state of affairs makes non-IE users continue to feel like second-class customers. Even with an OTP, some tasks are still off-limits to Linux users.
(it might not be possible because of patents, etc. but the government should -of course- be able to fund it.)
Or the alternative is better, wait until someone finds a flaw in this 'standard' (shouldn't be too hard) and have fun with it.
As a matter of fact, in Korea, every e-commerce site is required by law to use TLS. Even if you don't sell anything online, you must use TLS if you're for-profit and you have any sort of login system. It's been the law since last August. CAs have been making a lot of money lately.
That's interesting. As an American programmer, it seems obvious to me that merchants and credit card providers would find it in their interests to prevent fraud and credit card theft. Do you have any insight in to why Koreans feel differently about that? Is there something different about the legal system that makes civil liability for unauthorized card use an insufficient motivation to use reasonable security measures?
The potential liability for not encrypting usernames and passwords is probably negligible compared to the liability for not encrypting payment details. So in the absence of government regulation, there's not enough financial incentive for merchants to encrypt non-money-related stuff.
The unusual IE dependency is now hurting the Korean internet industry, as both the established brands and the startups in Korea develop for IE, their services end up failing to go beyond the Korean market. Hard to globalize your offering when you have to start satisfying a peculiar domestic market, and when you grew up using ActiveX and IE most of your life.