Tving Data Breach Fallout Raises Questions About Easy Login and OTT Bundled Plans
IT DAILY ·
✦ AI Summary
The government investigation team and related companies said the Tving breach had nothing to do with SNS easy login or telecom carrier-OTT access-right linkage. The team said the number of leaked accounts came to 39.54 million, and leaked user information from SNS easy sign-up accounts totaled 22,471,922. The team pointed to poor management of Tving's authentication keys and DB as the cause, and the government moved up the implementation date for separate management and storage of resident registration numbers and linking information to January 1 next year.
As the fallout from Tving's personal data breach continues, attention is turning to the security of easy login and OTT bundled products. The accounts hit by the Tving intrusion included SNS easy sign-up accounts, raising concerns that easy login may have been the cause of the data leak. With telecom companies rolling out plan and subscription products that include OTT access rights one after another, interest is also growing in the security of the personal data linkage process between carriers and OTT services.
However, the government investigation team and related companies said the intrusion was unrelated to SNS easy login. They also said the incident had nothing to do with the way telecom carriers link OTT access rights. That was stated in the joint announcement made on the 3rd by the Ministry of Science and ICT's public-private joint investigation team.
The investigation team disclosed the results of its analysis of Tving DB and related logs. The number of leaked accounts was tallied at 39.54 million, of which 22.06 million active accounts were in a state where login was possible and 17.37 million inactive accounts included withdrawals and dormant accounts. 110,000 test accounts were included, and the tally of leaked accounts also included duplicate accounts belonging to the same person.
Based on the classification criteria by sign-up method, leaked user information from SNS easy sign-up accounts was tallied at 22,471,922. Based on the results of this investigation, the scale of the leak from SNS easy sign-up accounts turned out to be significant, raising the possibility that anxiety over SNS easy sign-up itself could spread.
The investigation team identified 20 items and 70 types of information leaked in the intrusion. The leaked items included ID, password (one-way encrypted), CJ ONE integrated ID, name, mobile phone number, email address, date of birth, and CI (Connecting Information).
As such, the investigation found that the amount of user information leaked from SNS easy sign-up accounts was substantial. Accordingly, the situation created room for concerns about easy login.
However, in the end, the government says SNS easy sign-up itself was not the cause of the data leak. The line of analysis is that this leak cannot be linked to a problem with the SNS easy sign-up method itself.
The Ministry of Science and ICT explained that the information transmitted from SNS to Tving is limited to a name and email address. The government pointed out that the scope of information passed by external platforms through SNS easy sign-up is limited.
Specifically, the information transmitted from Naver consists of four items: year of birth, gender, name, and email. Based on the scope of this transmitted information, the government said anxiety over SNS easy sign-up itself could grow, but the SNS easy sign-up method itself cannot be seen as the cause of the data leak.
Typically, the information transmitted is a name and email. However, Tving's structure secures additional information collected after identity verification, including a mobile phone number, CI, duplicate sign-up verification information (DI), date of birth, and gender.
A Ministry of Science and ICT official said the Tving data leak does not mean SNS information is automatically leaked.
The investigation team pointed to poor management of Tving's authentication keys and DB as the main cause of the incident. The reason for that approach was development convenience.
The storage method for operating-environment access keys had no separate storage space, and the keys were used in a hard-coded state inside source code. In addition, the configuration values for running development-environment programs were left in plain text without separate encryption, and the DB access credentials for storing user information (ID, PW) were also confirmed to have been saved in plain text without encryption.
As telecom carriers recently continue rolling out plan and subscription products that include OTT access rights, user attention is focusing on the way personal data is shared and linked.
In connection with this, in the Tving breach, the number of leaked cases among KT Tving compensation coupon recipients was found to be 527,000.
KT said it operates a system that provides access-rights coupons without separate account linking.
Customers go through the process of using access-rights coupons by signing up directly with Tving or through an existing Tving account, and a KT official said KT's role is to provide subscription coupons.
The KT official then explained that the structure requires customers to sign up with and log in to Tving directly, and said there was no sharing of customer information with Tving related to the customer response program.
SK Telecom offers the subscription platform 'Woori Pass,' KT offers the OTT bundled rate plan 'Choice Plan,' and LG Uplus offers the subscription service 'U+ Idol.' According to reporting on the three major mobile carriers, the usual method for these bundled products is understood to be a structure in which existing OTT accounts are linked to telecom carrier products and then access rights are applied for use.
Where separate sign-up is required, the customer signs up directly with the OTT service and then, through steps such as phone-number verification within the platform, the access right is applied. The scope of use for linkage information between the telecom carrier and the OTT service is described as being limited to the minimum information needed to confirm access-right provision and connect the account, namely a phone number.
In this structure, it is emphasized that the information exchanged between the telecom carrier and the OTT service is limited. However, if a security management flaw occurs within the OTT platform itself, user information could be exposed regardless of the linkage structure.
This breach is expected to highlight the data management responsibilities of platform operators. There is growing possibility that discussions will expand around the OTT platform's own security management level and the scope of its responsibility rather than the linkage method itself.
In this incident, the inclusion of CI in the leaked personal data items emerged as a problem. CI is a unique identifier generated by encrypting a resident registration number during mobile phone identity verification and i-PIN authentication processes.
CI is used as electronic information to identify a specific individual online. It is also used during login to determine whether the account holder and the person attempting to log in are the same person.
However, CI alone does not allow account takeover or financial transactions. Even so, it is pointed out as a risk because it can identify the same user across multiple services.
In particular, if CI is combined with other personal information, additional damage is possible. The fact that CI was included in this incident is being taken as something that heightened these concerns.
In response, the government has moved to improve the system by separately managing resident registration numbers and CI. The goal is to preemptively respond to the risk of additional damage following recent incidents in which resident registration numbers and linking information were leaked at the same time.
The Broadcasting and Media Communications Commission (BMC Commission) held the '17th plenary meeting of 2026' and decided to change the implementation date for the separation and storage of resident registration numbers and linking information. The implementation date, originally scheduled for May 1 next year, has been moved up to January 1 next year, bringing it forward by 4 months.
A BMC Commission official said the revision to the 'standards on the generation and processing of linking information' is in its final stage, including provisions on the separate management and storage of resident registration numbers and linking information, and said the plan is to solicit opinions through an administrative notice, consult with relevant ministries, undergo a regulatory review, and then implement it on January 1 next year.
Source: IT DAILY · Seong Won-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=241410
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.