TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

IPinside: Korea’s Mandatory Spyware

331 pointsby pat-jayover 2 years ago

17 comments

guntherhermannover 2 years ago
I think this requires some prior knowledge.<p>From <a href="https:&#x2F;&#x2F;palant.info&#x2F;2023&#x2F;01&#x2F;02&#x2F;south-koreas-online-security-dead-end&#x2F;" rel="nofollow">https:&#x2F;&#x2F;palant.info&#x2F;2023&#x2F;01&#x2F;02&#x2F;south-koreas-online-security-...</a> :<p>&gt; I’ve heard about South Korea being very “special” every now and then. I cannot claim to fully understand the topic, but there is a whole Wikipedia article on it. Apparently, the root issue were the US export restrictions on strong cryptography in the 90ies. This prompted South Korea to develop their own cryptographic solutions.<p>&gt; It seems that this started a fundamental distrust in security technologies coming out of the United States. So even when the export restrictions were lifted, South Korea continued adding their own security layers on top of SSL. All users had to install special applications just to use online banking.<p>&gt; Originally, these applications used Microsoft’s proprietary ActiveX technology. This only worked in Internet Explorer and severely hindered adoption of other browsers in South Korea.<p>Wowsa!
评论 #34517514 未加载
评论 #34518321 未加载
评论 #34517229 未加载
评论 #34516677 未加载
评论 #34516627 未加载
评论 #34516909 未加载
gkanaiover 2 years ago
I&#x27;m the one who originally first wrote about the situation in S. Korea in the 90s when I was working for Mozilla and we noticed that Firefox had almost no market share there.<p>At the end of the day, it&#x27;s up to the S. Korean govt. or regulator to make the changes necessary to get rid of this nonsense. The govt.&#x2F;regulators have other issues to deal with so these S. Korean &#x27;tech&#x27; companies get to make a mess of citizens&#x27; computers and privacy. It&#x27;s been well over 2 decades of crappy S. Korean software like the keyloggers and whatnot and no end in sight.<p>If S. Korean citizens cared, they would force the politicians to do something and it would change. They don&#x27;t, so it doesn&#x27;t change.
评论 #34517087 未加载
评论 #34517156 未加载
KVFinnover 2 years ago
Just generally, Korea seems to have some weird legacy internet stuff.<p>It&#x27;s pretty hard to find places you can order in Korea, or from Korea, that don&#x27;t require a Korean phone number. There are services and stores that exist just to buy things from other places in Korea and reship or resell them to people both in and out of the country, just because people don&#x27;t have Korean phone numbers.<p>Even online purchases like audiobooks often requires a local phone number.<p>They sure make it hard to spend for any non Korean to spend money.<p>And it&#x27;s not <i>every</i> site, there are some huge retailers (www.aladin.co.kr for example) that do not require it. So it&#x27;s got to be just that most websites never bothered to build a checkout process that works without a phone number?
评论 #34517278 未加载
评论 #34517498 未加载
评论 #34518015 未加载
Freak_NLover 2 years ago
This used to be done in South Korea by (ab)using ActiveX. This looks like a continuation of a bad practice.<p>Not that banks in other countries are much better with their reliance on mandatory (or nearly mandatory) smartphone apps.
评论 #34516995 未加载
canbusover 2 years ago
IPinside sounds a bit like a really weird medical condition
评论 #34517246 未加载
评论 #34517039 未加载
评论 #34517810 未加载
O_O1over 2 years ago
As a Korean, great contents with big nodding
quenixover 2 years ago
I enjoyed this read very much. Hidden gems like these are why I love visiting HN!
tinus_hnover 2 years ago
I don’t see how this service checks if the website is supposed to be using it. So it seems any website can get all this information and use it to track users.
评论 #34516806 未加载
评论 #34516816 未加载
megousover 2 years ago
The issue also is (for the banks depending on the application) that they can&#x27;t trust aplication running on the user&#x27;s computer. This begs for opensource implementation that returns plausible fake data. :)
评论 #34517018 未加载
评论 #34517055 未加载
Slightedover 2 years ago
South Korea. Be specific about it.
评论 #34524121 未加载
wiz21cover 2 years ago
The title should mention South Korea explicitely because without that we may believe that North Korea is included in the story.
评论 #34517012 未加载
评论 #34517457 未加载
评论 #34520459 未加载
KirillPanovover 2 years ago
Here in the US the authorities just use the Intel ME and AMD PSP. No messy sidecar software needed!
评论 #34516804 未加载
poulpy123over 2 years ago
South Korea for people would thing &quot;duh it&#x27;s obvious they have spywares&quot;
O_O1over 2 years ago
Good contents with nodding as Korean.
fomine3over 2 years ago
JSONP! It’s been a while
vgb2k18over 2 years ago
&gt; When a banking website in South Korea wants to learn more about you, it will make a JSONP request to localhost:21300. If this request fails, the banking website will deny entry and ask that you install IPinside LWS Agent first. So in South Korea running this application isn’t optional.<p>To me this reads as not mandatory in the broadest scope, but needs to be on whatever device people use for online banking.
评论 #34516728 未加载
hunglee2over 2 years ago
Korea is not authoritarian but a democracy - this is ok
评论 #34516636 未加载
评论 #34516905 未加载
评论 #34516824 未加载