TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

TouchEn nxKey: A keylogging anti-keylogger solution

196 pointsby curling_gradover 2 years ago

14 comments

maeilover 2 years ago
&gt; The real number of users is likely considerably higher, the software being installed on pretty much any computer in South Korea.<p>This is a bit of an exaggeration. Plenty of young people hate this stuff enough that they do all of their banking through their phone and if they absolutely must do it on a pc, they either use an old disused laptop, do it at work, do it at an internet cafe (not that those don&#x27;t bring risks) or make sure to remove the spyware the second they&#x27;ve completed the task at hand.
评论 #34309938 未加载
评论 #34312278 未加载
评论 #34309789 未加载
pvgover 2 years ago
The first part was discussed on HN a few days ago and provides some background&#x2F;context:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34231364" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34231364</a>
kweingarover 2 years ago
I am very grateful for the modern web. It used to be commonplace to install a bunch of executables that interacted with the browser and took instructions from random websites (Flash, Silverlight, Java applets).<p>I have my reservations with the browserfication of software (and the restriction of browser extensions), but at the same time it is absolutely for the best that normal users just run sandboxed phone apps and browsers these days. Hopefully South Korea will retire this tool soon.
评论 #34308660 未加载
choegerover 2 years ago
I will bring this up the next time, someone laments about the lack of digitalization compared to other nations.
评论 #34313297 未加载
评论 #34309908 未加载
goranmoominover 2 years ago
A bit more context for people who don’t live in South Korea (I’m a South Korean):<p>Everybody knows that the systems are <i>absurd</i>. Most newer systems don’t require the use of such anti-keylogger programs. This is basically a countrywide legacy that we’re figuring our way out for ~30yrs.<p>This started in the 90s where South Korea got high speed internet everywhere, and people demanded internet banking… when IE didn’t ship 128-bit AES support due to export laws.<p>The South Korean govt submitted a law to enforce encryption for such services (i.e. an custom algorithm called SEED and 128-bit or higher keys were required), and without IE support, these encryption were developed in ActiveX. (For who don’t know, it was a COM-based solution to load native code from IE.) Laws and protocols are sticky, and even after IE shipped better encryption, these stayed.<p>When the anti-keylogger idea was first proposed, it was simple: the anti-keylogger could ship with the encryption support. It was when IE didn’t have a yes&#x2F;no dialog to ask whether to load native code or not; everything felt easy, and at that point everybody got locked into this legacy mess where nobody could use different browsers other than IE.<p>When IE added confirmation dialogs, banks instructed customers to press yes. When IE deprecated ActiveX, banks didn’t remove their 20-yr old code straight away; people were advised to turn on ActiveX support from advanced settings (they added step-by-step instructions to help people), and when MS finally ripped out ActiveX, banks just copied their ActiveX components into a separate executable that runs a localhost server. (And that explains the hastily coded JSON support, the never-updated libraries, and so on that the article shows.)<p>Every time MS tried making running untrusted native code harder, the banks and customers got used to it… until it became acceptable to install 2~3 different executables for each bank, each running a server on a different port.<p>Thanks to smartphones, newer solutions now develop all of the encryption code in JS, and the legacy now runs in JS without native code. Still legacy, but it’s been much better for the last 5yrs.
评论 #34314933 未加载
评论 #34315104 未加载
snvzzover 2 years ago
It is interesting to see a proprietary, very poor and insecure imitation of Nitpicker&#x27;s xray mode[0].<p>Note this is written by Norman Feske, who later went on to develop Genode[1], and continues to be its main developer today.<p>0. <a href="http:&#x2F;&#x2F;demo.tudos.org&#x2F;nitpicker_tutorial.html" rel="nofollow">http:&#x2F;&#x2F;demo.tudos.org&#x2F;nitpicker_tutorial.html</a><p>1. <a href="https:&#x2F;&#x2F;www.genode.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.genode.org&#x2F;</a>
评论 #34338653 未加载
lxgrover 2 years ago
From the article:<p>&gt; The current approach is for the websites to use WebSockets API to communicate with the application directly.<p>Is this really current best practice? I know of a handful of applications that implement webapp to native app communication like this, but it doesn&#x27;t seem especially stable&#x2F;portable to me, considering that it usually uses some ephemeral port that applications have no way of globally reserving.<p>Also, how does HTTPS work in this scenario? Wouldn&#x27;t there be a self-signed certificate or mixed content warning in many cases?
评论 #34321721 未加载
tlranfdnjsrorover 2 years ago
@palant:<p>Probably just some minor temporary weirdness but &gt; Host palant.info not found: 3(NXDOMAIN)
评论 #34312077 未加载
评论 #34314526 未加载
fomine3over 2 years ago
eval() is banned on Firefox Addon, that could be a reason why they stop using.
评论 #34321743 未加载
tgsovlerkhgselover 2 years ago
It&#x27;s interesting how long they could get away with such horrible practices despite having a neighbor up north that a) won&#x27;t hesitate to use cybercrime to fund their country b) probably wouldn&#x27;t mind causing some random disruption even if it can&#x27;t profit from it.
评论 #34314226 未加载
评论 #34315108 未加载
ThrowAgainover 2 years ago
Between this and <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Shutdown_law" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Shutdown_law</a> South Korea sounds like pretty oppressive country to live in.
评论 #34308312 未加载
评论 #34308266 未加载
评论 #34308378 未加载
评论 #34308752 未加载
评论 #34308581 未加载
评论 #34308320 未加载
leshenkaover 2 years ago
Is two-factor security an alien concept to South Korean banking system? At least via SMS? But either way if they&#x27;re going to make everyone install an application, why not OTP generator?
评论 #34308015 未加载
评论 #34308483 未加载
stargtmailover 2 years ago
All the People I&#x27;ve met in South Korea want Independence day from these disasters. They scream every day including today.
评论 #34308172 未加载
wkat4242over 2 years ago
Wow this is such a fail. It tries to fix a security issue but creates a much bigger hole in the entire system.
评论 #34308326 未加载