Fun story - About 10 years ago I was reversing a “new” malware that was monitoring all keystrokes on users computer but didn’t find it doing anything malicious. Turns out it was a keylogger installed by the banks that was required for customers to login to the bank account and for long time SK banks would only work on IE6
I've been trying to get in touch with South Korea's government IT. Have got really severe vulnerabilities that could literally compromise national security. No response so far but maybe been emailing the wrong places. If anyone could point me a direction, please shoot me an email.
afaik up to 2020, IE and ActiveX was required for online banking. Past that I heard you had to install a local webserver that the browser could communicate with. I'm not sure if any security issues are mandated by law, but it does sound like a minefield.
There's still a whole business sector selling snake oil "anti screenshot" software and such to banks and government agencies and such (complete with vulnerable kernel drivers of course). They learned nothing from the ActiveX days.
SK is such a crazy arc. Somewhat recently got over famine and authoritarianism, then five families took over the whole country, while growing the economy to crazy levels per capita, in the fastest time ever.
They took over global pop music, while also entering demographic collapse faster than anyone.
In 2024 they had their own Jan 6th type event, but democracy appears to have won? Yet last month, they sent 30% of Russia's diesel imports via their ports, while very loudly complaining about the public announcement of two captured NK soldiers in Ukraine.
I am very ignorant, and I genuinely have no idea what is happening in SK. But last month, they were helping fund the NK + Russian war machine? What a trip.
I recently read reports about Korean banks that were not affected by the latest hacking incident.. They restrict work access to designated tablets only, and they don’t give loan recruiters access to the internal network or even a separate work system. When a recruiter hands a case over to a branch, the rest of the process is handled internally.
Looking at this, it seems that rather than making things easier because of AI, it actually requires more bureaucratic handling. The surface that made people comfortable is, paradoxically, becoming AI’s attack surface.
I’m waiting for a hospital to get hacked by A.I. and some poor folks to lose their lives or otherwise get severely injured as a result. It seems no one is meaningfully pulling the handbrake on these shenanigans so why wouldn’t it end up there?
You don't need to wait for AI for that, when you have Russian state-authorized ransomware gangs already doing exactly that for many years. They have a SaaS model, affiliates, and everything.
OpenAI and Anthropic can slow their frontier work if they want to. They claim their frontier models are being distilled and jailbroken, so their own work is contributing to adversaries.
I found this relevant in yesterday’s ML4 announcement:
> This is particularly important in cybersecurity, where provider-level refusals can block legitimate vulnerability research and incident response, and where losing access to a capability mid-incident can itself become a critical security risk. ML4 pairs top-tier cyber performance with open weights and self-deployment, giving organizations both the capability and the autonomy to run advanced security work under their own policies.
Fun story - About 10 years ago I was reversing a “new” malware that was monitoring all keystrokes on users computer but didn’t find it doing anything malicious. Turns out it was a keylogger installed by the banks that was required for customers to login to the bank account and for long time SK banks would only work on IE6
I've been trying to get in touch with South Korea's government IT. Have got really severe vulnerabilities that could literally compromise national security. No response so far but maybe been emailing the wrong places. If anyone could point me a direction, please shoot me an email.
If you exploit the vulnerability and compromise national security, they'll notice
[dead]
They didn't have this problem when they forced everyone to use Internet Explorer + ActiveX...
According to https://news.ycombinator.com/threads?id=CyberMacGyver it installed a keylogger in a comment currently above
Doesn't SK have famously, laughably terrible internet security by law?
afaik up to 2020, IE and ActiveX was required for online banking. Past that I heard you had to install a local webserver that the browser could communicate with. I'm not sure if any security issues are mandated by law, but it does sound like a minefield.
There's still a whole business sector selling snake oil "anti screenshot" software and such to banks and government agencies and such (complete with vulnerable kernel drivers of course). They learned nothing from the ActiveX days.
In your opinion, what should they have learned?
That requiring users to install software that makes their devices vulnerable is not a viable security model.
What do you mean by not viable?
I’m curious to see their evidence on how they knew it was AI agents and which agents were used.
OpenAI user agent may be lol
Ah, yes, the famously secure Korean Banking system. Lol.
SK is such a crazy arc. Somewhat recently got over famine and authoritarianism, then five families took over the whole country, while growing the economy to crazy levels per capita, in the fastest time ever.
They took over global pop music, while also entering demographic collapse faster than anyone.
In 2024 they had their own Jan 6th type event, but democracy appears to have won? Yet last month, they sent 30% of Russia's diesel imports via their ports, while very loudly complaining about the public announcement of two captured NK soldiers in Ukraine.
I am very ignorant, and I genuinely have no idea what is happening in SK. But last month, they were helping fund the NK + Russian war machine? What a trip.
Trying to align them to either "side" is likely a mistake. They are their own separate entity.
Certainly. I just didn't think that they would be basically funding NK combat training.
That's one way to drag a country bent on staying in the past kicking and screaming into the future.
I recently read reports about Korean banks that were not affected by the latest hacking incident.. They restrict work access to designated tablets only, and they don’t give loan recruiters access to the internal network or even a separate work system. When a recruiter hands a case over to a branch, the rest of the process is handled internally.
Looking at this, it seems that rather than making things easier because of AI, it actually requires more bureaucratic handling. The surface that made people comfortable is, paradoxically, becoming AI’s attack surface.
I’m waiting for a hospital to get hacked by A.I. and some poor folks to lose their lives or otherwise get severely injured as a result. It seems no one is meaningfully pulling the handbrake on these shenanigans so why wouldn’t it end up there?
You don't need to wait for AI for that, when you have Russian state-authorized ransomware gangs already doing exactly that for many years. They have a SaaS model, affiliates, and everything.
Here’s my bet: open weights AI will become powerful enough that it will be used by adversaries to create havoc.
This is the main risk that the labs OpenAI and Anthropic have called out for and asked for slowing the frontier.
Almost all people thought that this was fear mongering, hype marketing and regulation capture.
The same people will blame OpenAI and Anthropic for creating this.
OpenAI and Anthropic are not profitable corporations and they would save a fortune in research and development expenses by "slowing the frontier".
OpenAI and Anthropic can slow their frontier work if they want to. They claim their frontier models are being distilled and jailbroken, so their own work is contributing to adversaries.
I found this relevant in yesterday’s ML4 announcement:
> This is particularly important in cybersecurity, where provider-level refusals can block legitimate vulnerability research and incident response, and where losing access to a capability mid-incident can itself become a critical security risk. ML4 pairs top-tier cyber performance with open weights and self-deployment, giving organizations both the capability and the autonomy to run advanced security work under their own policies.
I remember way back when OpenAI was "hacking" Huggingface and only the open weight models would help, those labs models refused.
I prefer not to have oligarchs and governments deciding what prompts are allowed and which need to be modified before I get to see it.
[dead]
[flagged]
[flagged]
Waiting for the day AI agents break into Nasdaq to achieve a goal.
Why are you waiting for this?
You're right! There's no time like the present!
Why not?
We dont need banks. Interest bearing CBDC wallets is all most people need. Richie rich already hire people to keep tabs on their assets.