Archive for the 'open web' Category

quick update on Korea

Tuesday, May 25th, 2010

Kim Tong-hyung, staff reporter for the Korea Times, is the only reporter providing English-language coverage of the news on the Microsoft monopoly in S. Korea.

I wanted to share two recent articles from Kim Tong-hyung, one covering the event that Mozilla’s Lucas Adamski attended at the end of April and another covering the “anti-virus” industry in Korea, which is one of the incumbent industries that would be significantly negatively affected if the Korean government moved away from the current PKI-based encryption architecture.

Experts Say Specific Tech Mandates Make [Korean] Internet Banking Vulnerable

“There is danger in relying on technology too much, and specific technology in that,” Schneier said, stressing that the government should be commanding “results,” rather than technologies, from banks and credit-card companies in their efforts to provide better user protection.

“Once a law mandates specific technologies such as protocol, applications or software, innovation stops. Companies know they will be okay as long as they do everything that the law says, and they will not figure out ways to make things more secure.

and

Lucas Adamski, who heads the software security team at Mozilla, which backs the Firefox Web browser, said online banking and e-commerce providers should consider redesigning their Web pages to support HTTPS, or HTTP Secure.

“Supporting HTTPS comes with many benefits. The server is authenticated to ensure the user is talking to the server they think are talking to, before any content is sent or received,” Adamski said.

“The browser will not normally send or receive any content from a Web site with an invalid or expired certificate or if the certificate does not match the server name. This means that there is no opportunity for a man-in-the-middle (MITM) injection attack to happen in the first place.”

Is AhnLab to blame for online banking mess?

Kim Kee-chang, a Korea University law professor who had led a series of unsuccessful lawsuits against the government over the overwhelming Active-X use, is absolutely merciless when describing the role of AhnLab and other anti-virus firms in the whole mess.

“Anti-virus firms are the only ones who are benefiting from the current Internet banking structure, which itself happens to be the biggest fraud of all. This system is all about creating an illusion of security that essentially does nothing other than allowing these software makers to make easy money off aging technology,” Kim said in a recent interview with The Korea Times.

“It’s depressing to see these so-called Internet technology experts sinking so low, sacrificing their morality to the last ounce in pursuit of profit. They have government officials in their pockets, as nobody ever accuses bureaucrats of having a bright understanding of technology,” he said, emphasizing that it was the anti-virus firms that chose plug-ins as the method to provide the required security programs to banks and computer users.

the Security of Internet Banking in South Korea in 2010

Wednesday, April 28th, 2010

For those of you who have followed my blog, you know that it has been 3 years since I first reported on the fact that Korea does not use SSL for secure transactions over the Interent but instead a PKI mechanism that limits users to the Windows OS and Internet Explorer as a browser. Nothing fundamentally has changed but there are new pressures on the status quo that may break open South Korean for competition in the browser market in the future.

In fact, one of the new pressures on the status quo has been the popularity of the iPhone in South Korea, which wasn’t available officially until late 2009 due to a different Korean software middle-ware requirement, WIPI, which has since been deprecated. With WIPI dead and buried, Apple released the iPhone to great fanfare in the Korean market and Blackberry has also launched in the Korean market.

Another pressure on the status quo was a recent report out from 3 researchers (Hyoungshick Kim, Jun Ho Huh and Ross Anderson) from the University of Oxford’s Computing Laboratory, “On the Security of Internet Banking in South Korea.

South Korean Internet banking systems have a unique way of enforcing security controls. Users are obliged to install proprietary security software – typically an ActiveX plugin that implements a bundle of protection mechanisms in the user’s browser. The banks and their software suppliers claim that this provides trustworthy user platforms. One side-effect is that almost everyone in Korea uses IE rather than other browsers.

We conducted a survey of bank customers who use both Korean and other banking services, and found that the Korean banks’ proprietary mechanisms impose significant usability penalties. Usability here is strongly correlated with compatability: Korean users have become stuck in an isolated backwater, and have not benefited from all the advances in mainstream browser and security technology. The proprietary mechanisms fail to provide a trustworthy platform; what’s more, alternative strategies based on trustworthy computing techniques are quite likely to suffer from the same usability problems. We conclude that transaction authentication may be the least bad of the available options.

The popularity of the iPhone (the press claims 500,000 units sold in the few months since it was released) resurfaced the issue that only Windows and IE can be used to make secure transactions with Korean Internet services. iPhone/Blackberry/Android users in Korea (not to mention Firefox/Opera/Safari/Chrome users) cannot bank online or purchase items online or do any secure transaction with the smartphone browser because Korean services only support the PKI mechanism that only works with Active-X in IE and Windows.

Dr. Keechang Kim of Korea University has been working tirelessly for many years to try to change the status quo in Korea around browsers and the reliance on a PKI mechanism that is tied to one platform. With concern being raised by different parts of the Korean government, including the Korean Communications Commission as well as the Office of the President of Korea, Keechang has gathered a very interesting panel of presentations for April 29th in Seoul.  The panelists will be addressing the (Korean) Financial Supervisory Service (FSS) which is the regulatory body in Korea that is currently mandating the PKI mechanism that is in place today (which requires Active-X, etc.)  Unless the FSS relaxes or changes their regulations, Korean banks cannot offer other mechanisms for Korean users to bank online, etc.  In short, unless the FSS changes their stance, nothing will change in Korea.

Security Issues of Online Banking & Payment in Korea” is an open public meeting (registration recommended) starting at 10 AM on April 29th at COEX Conference Hall E1 and will feature:

  • Bruce Schneier (Chief Security Technology Officer, BT) on “Security: What Works, What Doesn’t, and Why”
  • Hyoungshick Kim, Jun Ho Huh (Univ. of Oxford) “What’s the danger of mandating proprietary security solutions?”
  • Lucas Adamski (Dir. Security Engineering, Mozilla) on “Securing Browser Interactions”

Again this meeting is open to the public. Anyone is welcome to attend.

While I have no illusions that one meeting will get the key Korean government entities to do a 180 from their current stance, I do think this will be an important opportunity to bring external, Korean and non-Korean security expertise to Korea to discuss the current state of affairs and show that a PKI-based security architecture is only as secure as the computers that those certificates are used on.  If the computers are compromised, and at least one security services provider, Network Box, claims that S. Korea is the largest source for malware in the world, (Korea reigns as king of malware threats) then there is no way to be sure that the person in control of those personal certificates is the legitimate owner.

The deletion of the requirement for WIPI in Korean mobile phones opened the Korean market to the iPhone and the Blackberry and Android phones from outside of Korea.  Korean users of these new smartphones realized that they could not bank online, buy online, etc. and are now pressuring the Korean government to change the current laws which mandate a PKI-based mechanism that has been implemented with Active-X.  As the popularity of smartphones that cannot make use of the current PKI-based architecture for encryption/authentication grows in Korea, the pressure for the government to change their regulations will only mount.  The key question for Mozilla is whether the Korean government will open up to a point where Firefox and Fennec can be used in the future for secure transactions in Korea.

Thank you to Keechang and everyone in the OpenWeb.or.kr community for your tireless efforts to try to break open the Korean market. Thank you also to Channy Yun who has put aside his own schedule in order to participate and guide Lucas in Seoul.  There is still a long road to walk to an open, competitive market in S. Korea for browsers, but I am starting to see the light at the end of the tunnel.

US ISP redirects DNS in Firefox toolbar

Tuesday, April 6th, 2010

Disturbing news from the US.

Windstream Communications, a large ISP based on the East Coast of the US, has been caught using DNS redirection of the search results from the Google Toolbar in Firefox. Users using the Google Toolbar in Firefox were served a Windstream search results page, not a Google search results page. I’m not clear how this could even be done but this should never ever happen.

Windstream Hijacking Firefox Google Toolbar Results – Users kick back, Windstream promises correction tonight

Once their customers started complaining, Windstream representatives posted at dslreports.com that

“I won’t go into the technical details, but this was not a desired result to modify the Firefox search field regardless of which search provider is used in the browser.”

Somehow I can’t give this company the benefit of the doubt.

Edit:

Firefox redirects to windstream communications search results when I do a Google search in the search bar. (Mozilla Firefox support forums)

and

How do I remove a web search redirect? (Google Web Search Help Forum)

most powerful voice in open source – Channy Yun

Tuesday, March 23rd, 2010

Channy Yun, Mozilla’s community leader in Korea and the Korean Firefox localization leader has been selected as a Mindtouch “Most Powerful Voice” in open source.  Congrats to Channy for his tireless efforts to push web standards, the open web, and promote open source in both Korea and the world.

No choice of browser in South Korea

Wednesday, February 24th, 2010

UPDATE: Marcis has kindly provided a Belorussian translation of this post – НЯМА магчымасці выбіраць браўзар У ПАЎНОЧНАЙ КАРЭІ

As has been in the news this week and mentioned on many Mozilla blogs, the European Commission is working with Microsoft and other browser manufacturers, including Mozilla of course, to launch the web browser ballot in the EC.

To those critics of the browser ballot who would rather the free market be left completely to Adam Smith’s invisible hand, I would present to you the example of South Korea. In short, South Korea is a sad example of a Microsoft monoculture where the course of history and the lack of anti-monopoly oversight have created a nation where every computer user is a Windows user and banking or ecommerce or any secure transaction on the Internet with South Korean entities must be done with Internet Explorer on a Windows OS.

The situation in South Korea has gotten markedly worse since the government, bowing to pressure from the citizens who wanted to use the smart phones that were sold elsewhere in the world, relaxed a rule that previously required a Korea-specific middleware called WIPI, that was never going to be implemented by smart phone makers outside of Korea. Now that the WIPI requirement was gone, manufacturers like RIM and Apple can now sell Blackberries in Korea and iPhones in Korea.

But as I suspected last fall when the iPhone’s official sales in Korea was announced, the browsers in these new smart phones (be it the browser in the iPhone, the Blackberry, or the Android devices that are on sale in Korea) can’t interoperate with the Active-X based security requirements that Korean banks and ecommerce stores require. So it’s not surprising to me at all that the news from Korea since the launch of these smart phones has been universally negative regarding the requirement to use Active-X for secure web transactions in Korea.

Here’s a selection of quotes from 3 recent articles in the Korea Times:

Korea Paying Price for Microsoft Monoculture (09-23-2009)

But the land of ubiquitous broadband, feature-happy “smart” phones and ultra-cool computing devices doubles as a crusty regime where Linux, Firefox, Chrome and Opera users can’t bank or purchase products online, and where Mac users buy Windows CDs to prevent their devices being reduced to fashion items.The bizarre coexistence of advanced hardware and an outdated user environment is a result of the country’s overreliance on the technology of Microsoft, the U.S. software giant that owns the Korean computing experience like a fat kid does a cookie jar.

It is estimated that around 99 percent of Korean computers run on Microsoft’s Windows operating system, and a similar rate of Internet users rely on the company’s Internet Explorer (IE) Web browser to connect to cyberspace.

Mobile Banking Monoculture? 01-10-2010

At the center of the controversy is the [Korean] Financial Supervisory Service’s (FSS) guidelines on the safety of financial services provided on smartphones, which were finalized and announced last week.The new rules can be summarized simply ― all financial transactions on these advanced handsets will be subject to the same security requirements that control online transactions on personal computers.

The problem with this, according to critics, is that the existing legal framework was precisely what allowed Microsoft to establish a virtual monopoly in computer operating systems and Web browsers here, which is now blamed for having computer users stuck with outdated technologies and exposed to larger security risks.

Rigid Regulations Retard Mobile Wallet Era 02-10-2010

In essence, the current law states that all encrypted online communications on computers require the use of electronic signatures based on public-key certificates. And since the fall of Netscape in the early 2000s, Microsoft’s Active-X controls on its Internet Explorer (IE) Web browsers remain as the only plug-in tool to download public-key certificates to computers.

So we can see in Korea today that the lack of choice of web browser (not to mention the lack of choice of computer operating system), indeed the lack of interoperability of Korea’s secure transaction protocol on the web, means that the smart phones of today, that don’t support ActiveX, are useless in Korea for secure transactions. That means if you are an iPhone/Blackberry/Android user in Korea, you cannot bank online with a Korean bank, you cannot trade stocks on the Korean markets, you cannot shop online with a Korean Internet site. You can’t do many of the key things that these smart phones were designed to do.

So when people ask you, “why is the choice of a web browser important?” tell them that in South Korea, people don’t get a choice of what operating system to use or what web browser to use.  After you explain to them that a place without choice is South Korea, ask them again if they’d like to not have a choice and why the choice of a web browser is important.

I hope to have better news from South Korea soon.  Please watch my blog for updates on this issue and other issues facing Mozilla and the open web in Asia.

In the meantime, please be sure to visit Open To Choice.org where Mozilla’s Chair, Mitchell Baker and Mozilla’s CEO, John Lilly, explain why we at Mozilla believe that the choice of browser is a critical right for all Internet users worldwide.

opentochoice.org

Here’s a list of things that the Mozilla community is doing and which we encourage everybody to do:

• Comment on the open letter at opentochoice.org;
• Follow @opentochoice on Twitter;
• Write a post on your blog;
• Use your favorite social network to spread the word;
• Write to bloggers that you know, to local media
• Start a thread in technology and OSS related forums and mailing lists about the browser choice screen;
• Offer to localize the open letter (send an email to contact -at- opentochoice.org)
• Are you participating in local events where you can talk about choice? Do a talk, organize a booth, distribute flyers in the welcome pack, put a banner on the event page;
• Become a browser choice screen watcher: did you see the browser choice screen pop-up on your screen? send us an email, post it on your blog, Tweet about it. Give details (country, time of day, choice of browser).

Mozilla Philippines community rocks!

Friday, February 19th, 2010

In the span of a few months, the brand new Mozilla community in the Philippines is active and ambitious.  A new Mozilla Philippines Community website, Five Years of Firefox in Manila, and check out the 2010 plans they have for promoting Firefox and Mozilla in the Philippines here: Mozilla Philippines Community 2010 Kick-Off.

And for photos from the 2010 kick-off meeting, be sure to visit Pics from the Mozilla Philippines 2010 Kick-Off Meeting.

Mozilla Philippines community 2010 Kick-off meeting

Will China’s Great Firewall Hold?

Thursday, January 21st, 2010

One day before US Secretary of State, Hillary Clinton’s speech on Internet freedom, the New America Foundation has hosted a panel discussion on Chinese censorship of the Internet with Alex Ross of the State Department, Rebecca MacKinnon of the Open Society Institute, Tim Wu of Columbia University, and Evgeny Morozov of Georgetown University. The discussion was moderated by James Fallows of The Atlantic Monthly.


Authority, Meet Technology: Will China’s Great Firewall Hold?

For those who prefer the audio, you can download the MP3 Recording of This Event.

Mozilla at Linux.conf.au in Wellington with Code Rush

Monday, January 18th, 2010

Robert O’Callahan mentioned it on his blog but if you attend Linux.conf.au this week, you get to see not only ROC in action speaking on the importance of open video on the Web,  but also Chris Double on implementing HTML5 video in Firefox and Taras Gleck on The Hydras too.

Not only that, they’re screening Code Rush on Wednesday evening, so you get to see Stuart Parmenter too!

TEDx Seoul – Korea Internet Galapagos

Thursday, January 7th, 2010

Changwon Kim, a friend of mine and a talented Internet entrepreneur who sold his blog service startup to Google in 2008 (and currently works at Google Korea), recently did a great presentation on the Korean Internet at TEDx Seoul. Changwon covers the fact that due to early broadband infrastructure and the geography of Korea, Korean companies were leading in innovations around virtual worlds, mobile Internet and social networks way before the global Internet brands that are world-wide today.  However, recently there has been less Korean innovation which has been concerning to technologists and entrepreneurs.

The video from his presentation is now online (in Windows Media) and covers some of the challenges facing the Korean Internet, including two mentions of the Microsoft browser monopoly in Korea.

TEDxSeoul Talks – [Changwon Kim] Korea Internet Galapagos

Filipinos Fête Five Years of Firefox

Wednesday, December 2nd, 2009

On November 26th, the newest Mozilla community, Mozilla Philippines, which started only a few weeks earlier in the Philippines, celebrated the Five Years of Firefox at the Asian Institute of Management in Manila.

Five Years of Firefox in Manila

Five Years of Firefox in Manila backdrop

Everything came together very quickly with organization driven by Regnard Raquedan, our new community leader, as well as the Filipino Campus Reps, (Ren-Ren Gabas, Allan Caeg, and Joell Lapitan among many others) who have been very active.  Sherwin Sowy of Globe Labs (a division of Globe Telecom) was kind enough to help with sponsorship and showed off a Firefox Addon that university students had recently developed which enabled the sending of web content (text or images) via SMS/MMS.

If you would like to join the new community that is growing in the Philippines to support Mozilla and Firefox, please join the Philippine Mozilla community list.

Five Years of Firefox in Manila Done!

Other blog posts on the event can be found here:

Five Years of Firefox in Manila Done! – Mozilla Philippines

Five Years of Firefox in Manila Done!

Five Years of Firefox in Manila! – a set on Flickr (Photos courtesy of Aja Lapus & Joell Lapitan)

Mozilla Firefox Turns Five

5 Years of Firefox in Manila, a Report

Happy 5th Birthday Mozilla Firefox!

2009-11-21 Five Years of Firefox in Manila – a set on Flickr: