Skip to content

Comment on IPinside: Korea’s Mandatory Spywareparent

Comments

I’ve also wrote a comment on the context of how these ugly programs got adopted on [0].

To quote myself…

Everybody knows that the systems are absurd. This is basically a countrywide legacy that we’re figuring our way out for ~30yrs.
When the idea was first proposed, it was when IE didn’t have a yes/no dialog to ask whether to load native code or not.
When IE first added ActiveX confirmation dialogs, banks instructed customers to press yes. When IE deprecated ActiveX, banks didn’t remove their 20-yr old code straight away; people were advised to turn on ActiveX support from advanced settings (they added step-by-step instructions to help people). When MS finally ripped out ActiveX, banks copied their ActiveX components into a separate executable that runs a localhost server.

I’m sure that if it wasn’t iPhones, South Korea would have been locked into this legacy for a lot longer. (In fact, we once had versions of these programs for Android as well! iOS didn’t allow this (thankfully).)

[0]: https://news.ycombinator.com/item?id=34313137

Of course one issue here is while it's probably acceptable for South Koreans to trust Chrome, Windows, MacOS, Android and iOS (and also Intel and Ryzen CPUs), it's probably not for their biggest companies (including banks ?) and their government whose security threat likely includes US espionage.

And yes, this might seem silly considering the garbage fire revealed by TFA, but maybe they can use this crisis to jump one extra generation over that security threat too ?

What about people using Apple computers? Were they simply advised to borrow something capable of running Windows from a friend?

It was common 5~10yrs ago to either have a spare Windows laptop or buy Parallels Desktop for handling bank/govt things. Nowadays, macOS got common enough that some of these ugly programs now have a macOS-specific version. :( Some even have downloadable deb/rpm Linux binary packages.

Some softwares: Yes. People with Mac are advised/forced to use Windows. For instance, Uwayapply, a college admission application service, doesn't support macOS.

Or: they provide .pkg file to install similar program.

Most of them want sudo. They use root permission for various purpose, but the most impressive one for me was registering their CA certificate on Firefox root store, to support WebSocket over TLS to localhost on Firefox.

Nice! That way you can extract the private key and cert from the app and spoof the local server! I bet that cert is valid for *. and the same on every machine as well?

That situation was pretty normal if you used Macs back in the day, for many workflows. Virtual PC on PPC Macs were a godsend in many situations in the late 1990s.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.