Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a serious problem for us in my business as our business banking software we are forced to use by our bank in mainland China still only works with IE. I spent an hour last night ultimately inputting shady commands into my registry, to try to force IE to open instead of being hijacked by edge. When an entire industry in a country refuses to upgrade what the hell? Of course I’m pissed the bank hadn’t upgraded but it’s infuriating that Microsoft breaks my processes without my permission.


Korea went deeply down the "custom security" rabbithole too, and many banks there still rely on activeX controls and custom encryption algorithms and other insane bullshit that actively impairs security. It seems to be a regional thing (or at least a developing-country thing).

https://palant.info/2023/01/02/south-koreas-online-security-... HN discussion: https://news.ycombinator.com/item?id=34231364

https://www.forbes.com/sites/elaineramirez/2016/11/30/south-...

This is not unheard-of in the enterprise world in the US either. To name-and-shame, Allscripts Enterprise EHR system still uses active-x controls and is still actively deployed in hospital systems.

The typical deployment will be a sandboxed VDI installation that isn't allowed to directly talk to anything except its EHR server and has to be connected via citrix or similar. It is still insane, of course, but the medical world is another one that moves slow. Probably some stuff in the financial sector too, they like that shit too.


I spent two years modernizing one of these IE only apps (moved to chrome/firefox). Sometimes the offending activex control is simply a xml component (literally parsing, xsl, xpath, etc stuff) of a newer version than what was built in at one time. Firefox and Chrome don't handle xml nearly as seamlessly as old IE did. But other times these apps require IE11, but it's actually executing the page in IE6 or 7 compatibility mode. That was the case with mine, Microsoft DHTML Behaviors, the horror, the horror....


South Korea is very much not a developing country and hasn't been one in about 3 decades :-)


I know it's just... weird. SK embarked on a path of rapid industrialization by handing a massive amount of power to corporate conglomerates (chaebols). They're like a developing nation in that respect... they just happen to be a developing nation that is on the forefront of certain high-tech industries. Samsung, LG, Hyundai, and the other chaebols utterly run the political sphere in a sense that is obscene even by western standards.

The president being jailed a couple years ago for being a chaebol pawn is kind of indicative of the whole thing, and nothing has really changed.

On the other hand maybe that's the shadowrun future in store for us all. ;)


I'm at a US government agency and the system that processes our time and attendance still does not work with Chrome or Firefox - I think it's some kind of security certificate issue? So they tell us to use Edge to fill our our time and attendance. I click some link from our internal home page and it loads up the page in "Internet Explorer Mode," complete with the blue "e" in the address bar.


It's bullshit "security" for banking, it could be that it depends on something that isn't emulated by Edge, like toolbars or some other form of deep browser extensions, not "just" ActiveX.

For all it's worth it could be something as insane as a kernel driver that assumes a certain IE build and hooks into it for "security". Never heard of such things in areas outside of gaming, but won't be remotely surprised. Banking industry is way more backwards than gaming, after all.


I sympathise with your frustration, but the blame is absolutely with your bank. I mean, finances are like THE thing to be security minded about - the fact they're still using IE is just unacceptable from any lens.


Sometimes the blame is regulations: too many hoops for banks to update their software easily and without adding stupid regulatory liabilities. Regulations added to protect the user, but perversely hinder the user.


Wait, what?

No, regulations do not incentivise bad security practices at all. In fact, they are one of the only tools to enforce good security practices.


Sorry, I was unclear.

I am all for good regulations - they are vital for a well functioning society.

However, there are plenty of bad regulations that have perverse outcomes. There are also plenty of regulations due to regulatory capture where the regulations help an incumbent and hinder new entrants. Watch Intuit protect their income at the expense of tax payers. In New Zealand, there are plenty of horrifically inefficient health & safety regulations, because who can argue against saving a life at any cost?

I am against bad regulations that cost society too much without giving enough benefit.


That's really on your bank for insisting on using technology which has been sunset for many many years though.

I would contact them and tell them you're considering switching. If they're anything like the banks in North America they'll be freaking out trying to give you deals to stay. They did this for me when I told them that I would switch over trying to force SMS-based 2fa on me.

I'm really not sure about the economic situation in China right now but since they hiked the interest rates banks have been extremely competitive in terms of signup offers here in the past few months. Might be worth considering!


Yeah, MS have a 10 year window to migrate. If you found yourself at the end of 10 years still not migrated, then you’ll only do it when it breaks.


This change has been announced long ago. IT should have identified this issue and taken the steps to enable IE mode on Edge for this specific site a year ago.


MS announced you shouldn’t be using IE several years ago.


> When an entire industry in a country refuses to upgrade what the hell?

Well, I don’t think they can refuse to upgrade any longer if it doesn’t work, right?


We went through this 20 years ago when it was IE6.


shudder

Brings me back to the days of having to support IE6 for a client website when everyone has moved on from IE6. That shit was a dog to support


Perhaps a virtual machine running windows with the compatible version of IE just for this purpose would be a good option. Take snapshots after it's setup correctly so any sneaky update shenanigans MS pulls can be reverted.


Block Microsoft, and use a virtual machine that you copy before every session.


On VirtualBox it's easy to set the disks as immutable. The machine will come up, write to the disk and, when you reboot, it'll be back into the original state.

More than once I updated the VM only to realize I forgot to make the disk mutable.


And now they'll finally fix it, as they have no other choice. You can thank MS for that.


Microsoft retains the right to break your process without your permission.


The warnings started how long ago? The compatability mode is available and works.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: