Iranian Foreign Ministry: "Continuing Message Exchanges with the U.S. and Activities of Mediating Countries"
Esmaeil Baghaei, Spokesperson for the Iranian Ministry of Foreign Affairs [Xinhua, Yonhap News file photo]Esmaeil Baghaei, spokesperson for the Iranian Ministry of Foreign Affairs, stated on the 26th
President Yoon: "Do You Think You Are Safe from the Special Counsel?"... Final Statement Video Released
President Yoon Suk Yeol rebuking the special prosecutor on the 24th. [Court video / @birds_justice X account subtitle GIF] A video of President Yoon Suk Yeol's closing statement at his trial rega
President Yoon, regarding the first-instance ruling on the Public Official Election Act: “An excessive political verdict that distorts the facts… We will appeal immediately.”
The first-instance sentencing hearing for President Yoon Suk Yeol regarding violations of the Public Official Election Act is being broadcast live at Seoul Station on the 27th. [Photo=Yonhap News]Pres
WSJ: "SK Hynix ADR Premium Is a Sign of AI Trading Overheat"
Advertisement for SK Hynix ADR listing in New York's Times Square [Reuters=Yonhap News file photo]The Wall Street Journal (WSJ) has pointed out that the price of SK Hynix’s American Depositary Recei
'Godfather of Japanese Mystery Novels' Keigo Higashino Passes Away After Battle with Cancer at 68
Famous Japanese mystery novelist Keigo Higashino [AFP=Yonhap News]It has been belatedly reported that Keigo Higashino, the "godfather of Japanese mystery novels" and author of bestsellers such as "The
[Park Pil-kyu Security Column] To the Ignorant Trying to Clothe a Beast in Sheep's Clothing
Rep. Kim Byung-joo of the Democratic Party of Korea [Photo=Yonhap News]“The Air Force Academy doesn't teach you how to fly a plane!” “The Army, Navy, and Air Force academies are exactly the
Risk originates from within, not from outside.
National Election Commission. Yonhap News
As of 2025, the core issue of the National Election Commission's (NEC) security is not "preventing external attacks."
If data structures, authorization structures, audit log structures, and code verification structures are absent, incidents occur not from external sources, but internally.
The personal information leak incident involving Coupang, affecting as many as 34 million individuals, serves as a case that re-establishes the fact that "security policies must extend beyond mere blocking to encompass verification."
In Korean society, personal information is no longer just data; it is a 'sovereign security asset' where national systems and individual safety intersect. The recent Coupang incident, originating from internal access rather than external intrusion, and revealing a lack of verification structures despite the presence of firewalls, carries significant implications.
At the same time, the National Election Commission, which holds information on all voters nationwide, repeatedly states that it is "safe because it is isolated from external networks." However, technically, isolation and safety are not synonymous. While isolation is akin to a firewall, safety is about structure, and this distinction highlights the fundamental difference between security awareness in the 1990s and security policies in 2025.
Examining the NEC through the lens of 2025 security policy reveals four problems.
Firstly, the fact that the NEC's systems are operated centrally rather than in a decentralized manner exacerbates structural risks.
Key systems such as the integrated voter registry, web servers, and integrated servers are concentrated in a central server. In information security, when data converges at a single point, authority also converges at that point, which is known as a 'Single Point of Failure.'
In other words, incidents do not necessarily originate externally; the stability of the entire system can be shaken by the intent of a single insider or a single mistake in authorization settings. This is not a conspiracy theory but a conceptual definition in information security.
The perception that 'blocking equals security,' centered around firewalls, is anachronistic.
Firewalls are merely devices to block external attacks and do not guarantee internal integrity. The Coupang incident clearly demonstrated this. Internal access, insider collusion, modifiable audit logs, and code changes without verification are all outside the protection of firewalls. The explanation that "it is safe because it is isolated from the outside" is merely political rhetoric lacking technical grounding.
The core of security lies in a structure that controls "who can do what."
Secondly, modern security operates under an RBAC (Role-Based Access Control) system. Authority is granted to roles, not individuals, and operational, verification, and auditing functions are separated. Systems lacking an RBAC structure allow a single administrator to perform all functions, including viewing, modifying, deleting, and accessing logs, leading to untraceability in the event of an incident.
RBAC is not an option but a minimum security requirement for 2025; however, there is no indication that the NEC operates this system.
Thirdly, the issue of audit logs is even more critical.
Audit logs must record 'who, when, and what' was changed, and properly designed logs must be immutable. They are only meaningful if administrators cannot modify or delete them. If there are no logs, tracing is impossible; if logs exist but can be deleted, they are as good as non-existent.
While the NEC emphasizes 'isolation from external networks,' there is no explanation regarding the operation of immutable audit logs.
Fourthly, code signing is also crucial for the security of election systems.
Systems operate based on code, not human commands, and modifications must undergo an approval process, signature verification, and be recorded in logs. Financial networks mandate this process, but the NEC does not disclose its code modification procedures.
This suggests not necessarily 'confidentiality' but rather a 'potential for an unpublishable structure,' as code can be directly linked to the processing of voting data.
The Coupang incident was a matter of "access," not "hacking," and system vulnerabilities stemmed from structural flaws, not technical loopholes.
Even if not currently under attack, security experts generally agree that the NEC is in a "structurally vulnerable state." The essence of the problem is that risks originate internally, not externally.
Hankyoreh, JoongAng Ilbo, and The Korea Herald pose three questions to the NEC:
First, does the NEC operate an RBAC (Role-Based Access Control) system? Is authority vested in individuals or in the structure?
Second, are audit logs designed in an immutable form? Can logs be deleted, or are they designed to be undeletable?
Third, do code changes undergo an approval process and signature verification? Are changes recorded, traceable, and designed for external verification?
Security is not about trust, but about verification. Verification is about responsibility, not attack, and that responsibility culminates in improving the verification structure of the electoral system.
Even those who dismiss suspicions of election fraud as conspiracy theories would likely agree with this point. Is there any reason why a single key employee of the NEC should have the ability to destabilize South Korea's elections? This is why the NEC's response is eagerly awaited.
Kim Young More by this author