Skip to content

Technical Security ​

Nature: Detailed technical assessments, vulnerability analysis, and attack vector documentation. These documents provide the technical depth behind the core research findings.

Contents ​

  • Vulnerability Analysis — Critical analysis of SK ID Solutions' "Additional Security Measures" documentation, demonstrating how proposed mitigations fail against modern attack techniques.
  • QRLJacking Analysis — Detailed technical description of the QRLJacking vulnerability and Dynamic Browser-in-the-Browser (BITB) attack, including system architecture and proof-of-concept design.
  • Convenience vs Security — Multi-perspective analysis of the trade-off between user convenience and security in Smart-ID and Smart-ID+, covering push notification risks, QR code flows, and architectural limitations.

Research content licensed under CC-BY-4.0. Site code licensed under MIT.