32 comments

  • CyberMacGyver 2 days ago ago

    Fun story - About 10 years ago I was reversing a “new” malware that was monitoring all keystrokes on users computer but didn’t find it doing anything malicious. Turns out it was a keylogger installed by the banks that was required for customers to login to the bank account and for long time SK banks would only work on IE6

  • penskymaterial 2 days ago ago

    They didn't have this problem when they forced everyone to use Internet Explorer + ActiveX...

  • acheong08 2 days ago ago

    I've been trying to get in touch with South Korea's government IT. Have got really severe vulnerabilities that could literally compromise national security. No response so far but maybe been emailing the wrong places. If anyone could point me a direction, please shoot me an email.

    • cowlevel 2 days ago ago

      If you exploit the vulnerability and compromise national security, they'll notice

  • WheatMillington 2 days ago ago

    Doesn't SK have famously, laughably terrible internet security by law?

    • turpentine 2 days ago ago

      afaik up to 2020, IE and ActiveX was required for online banking. Past that I heard you had to install a local webserver that the browser could communicate with. I'm not sure if any security issues are mandated by law, but it does sound like a minefield.

      • r1ch 2 days ago ago

        There's still a whole business sector selling snake oil "anti screenshot" software and such to banks and government agencies and such (complete with vulnerable kernel drivers of course). They learned nothing from the ActiveX days.

        • cowlevel 2 days ago ago

          In your opinion, what should they have learned?

          • r1ch a day ago ago

            That requiring users to install software that makes their devices vulnerable is not a viable security model.

            • cowlevel a day ago ago

              What do you mean by not viable?

  • tangotaylor 2 days ago ago

    I’m curious to see their evidence on how they knew it was AI agents and which agents were used.

    • v3ss0n 2 days ago ago

      OpenAI user agent may be lol

  • humanlity 6 hours ago ago

    As far as I know, it seems a Chinese student using an open-source project with AI did this, so funny

  • consumer451 2 days ago ago

    SK is such a crazy arc. Somewhat recently got over famine and authoritarianism, then five families took over the whole country, while growing the economy to crazy levels per capita, in the fastest time ever.

    They took over global pop music, while also entering demographic collapse faster than anyone.

    In 2024 they had their own Jan 6th type event, but democracy appears to have won? Yet last month, they sent 30% of Russia's diesel imports via their ports, while very loudly complaining about the public announcement of two captured NK soldiers in Ukraine.

    I am very ignorant, and I genuinely have no idea what is happening in SK. But last month, they were helping fund the NK + Russian war machine? What a trip.

    • apefulsin a day ago ago

      Trying to align them to either "side" is likely a mistake. They are their own separate entity.

      • consumer451 a day ago ago

        Certainly. I just didn't think that they would be basically funding NK combat training.

  • skeledrew a day ago ago

    That's one way to drag a country bent on staying in the past kicking and screaming into the future.

  • jdw64 2 days ago ago

    I recently read reports about Korean banks that were not affected by the latest hacking incident.. They restrict work access to designated tablets only, and they don’t give loan recruiters access to the internal network or even a separate work system. When a recruiter hands a case over to a branch, the rest of the process is handled internally.

    Looking at this, it seems that rather than making things easier because of AI, it actually requires more bureaucratic handling. The surface that made people comfortable is, paradoxically, becoming AI’s attack surface.

  • phs318u 2 days ago ago

    I’m waiting for a hospital to get hacked by A.I. and some poor folks to lose their lives or otherwise get severely injured as a result. It seems no one is meaningfully pulling the handbrake on these shenanigans so why wouldn’t it end up there?

    • consumer451 a day ago ago

      You don't need to wait for AI for that, when you have Russian state-authorized ransomware gangs already doing exactly that for many years. They have a SaaS model, affiliates, and everything.

  • bradgranath a day ago ago

    Ah, yes, the famously secure Korean Banking system. Lol.

  • simianwords 2 days ago ago

    Here’s my bet: open weights AI will become powerful enough that it will be used by adversaries to create havoc.

    This is the main risk that the labs OpenAI and Anthropic have called out for and asked for slowing the frontier.

    Almost all people thought that this was fear mongering, hype marketing and regulation capture.

    The same people will blame OpenAI and Anthropic for creating this.

    • staticman2 a day ago ago

      OpenAI and Anthropic are not profitable corporations and they would save a fortune in research and development expenses by "slowing the frontier".

    • iAMkenough a day ago ago

      OpenAI and Anthropic can slow their frontier work if they want to. They claim their frontier models are being distilled and jailbroken, so their own work is contributing to adversaries.

      I found this relevant in yesterday’s ML4 announcement:

      > This is particularly important in cybersecurity, where provider-level refusals can block legitimate vulnerability research and incident response, and where losing access to a capability mid-incident can itself become a critical security risk. ML4 pairs top-tier cyber performance with open weights and self-deployment, giving organizations both the capability and the autonomy to run advanced security work under their own policies.

    • verdverm a day ago ago

      I remember way back when OpenAI was "hacking" Huggingface and only the open weight models would help, those labs models refused.

      I prefer not to have oligarchs and governments deciding what prompts are allowed and which need to be modified before I get to see it.

  • iAMkenough 2 days ago ago

    Waiting for the day AI agents break into Nasdaq to achieve a goal.

    • ronnier 2 days ago ago

      Why are you waiting for this?

      • esseph 2 days ago ago

        You're right! There's no time like the present!

      • iAMkenough a day ago ago

        Why not?

      • eluru a day ago ago

        it funny :3

  • hc49 2 days ago ago

    We dont need banks. Interest bearing CBDC wallets is all most people need. Richie rich already hire people to keep tabs on their assets.