Tving CEO Choi Ju-hee (최주희) (left), Democratic Party lawmaker Lee Hoon-ki (이훈기). [Photo captured from the National Assembly Broadcasting YouTube channel]

Tving, which suffered a large-scale personal data leak, faced criticism in the National Assembly that it had weak basic security management, including storing developer access keys in plain text in source code. Lawmakers also raised concerns that fundamental improvements were not made despite hardcoding vulnerabilities being flagged in a past penetration test.

Tving CEO Choi Ju-hee (최주희) attended the Ministry of Science and ICT audit by the National Assembly's Science, ICT, Broadcasting and Communications Committee as a witness on Monday. "As the person responsible, I am sorry to the public, and I have clearly felt that we have been negligent on security," she said.

Democratic Party lawmaker Lee Jeong-heon (이정헌) said 39.54 million account records and 361 source-code items were leaked from Tving. "How can you put a developer access key in source code in plain text?" he said.

He also said Tving failed to detect signs of abnormal activity while an attacker used a virtual server to take out about 24 GB of data, and that reporting of the breach was delayed.

Choi said the company had been negligent on security. She explained that it provided affected users with anti-phishing insurance and points and coupons. "I will make sure we are reborn with a global-level security system so this never happens again," she said.

Lawmakers also said previously identified security vulnerabilities were not properly addressed.

Democratic Party lawmaker Lee Hoon-ki (이훈기) said a hardcoding vulnerability was found during an earlier penetration test and Tving was asked to make broad improvements. He said Tving only fixed the specific projects flagged and failed to remove the underlying risk.

Choi responded in the sense that while the company improved the projects flagged at the time, it did not extend to more fundamental process or system improvements.

Lee also pointed to Tving having only 4 dedicated information security staff despite rapid growth. Choi said it was true the amount invested in information security had increased, but she had not checked whether it was sufficient. She said it would increase staffing and investment to raise security to a global level based on zero trust.

The process of submitting 자료 to the National Assembly after the incident also came under scrutiny.

Democratic Party lawmaker Hwang Jeong-a (황정아) said Tving was refusing to submit 자료 on the grounds that it was under investigation. She said it was the biggest theft incident ever and that its response was worse than that of small and medium-sized companies.

Choi said she understood Tving could not provide figures that were not final because an investigation by the Personal Information Protection Commission was under way. She said she would personally look after the work and separately report the necessary 자료.

Hwang urged Deputy Prime Minister Bae Kyung-hoon (배경훈), who is also science minister, to impose stronger penalties on companies that conceal incidents or do not cooperate with document submissions, while providing security consulting and AI support to companies that actively cooperate with investigations.

Bae said it was necessary to respond strictly to companies seeking to conceal breaches, including by submitting 자료 insincerely, failing to respond to breaches, or refusing to submit 자료.

Keyword

#Tving #National Assembly #Democratic Party #Ministry of Science and ICT #Personal Information Protection Commission
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.