Japan's government has ordered local tech giants LINE and NAVER to disentangle their tech stacks, after a data breach saw over 510,000 users' data exposed. LINE is a messaging app created by an offshoot of South Korea's NAVER – a Google-like web giant. The LINE app is very widely used across Asia – in Japan and Thailand it is used by the majority of the population and enjoys the kind of ubiquity WhatsApp boasts in other nations. In 2021, LINE merged with Yahoo! Japan, which is owned by SoftBank. NAVER and SoftBank emerged as half owners of an entity that operates LINE. In 2023, however, LINE leaked. And on Tuesday, Japan's Ministry of Internal Affairs and Communications issued administrative guidance on how to avoid a similar snafu in future. The Ministry's guidance outlines deep entanglements between LINE and NAVER tech. NAVER's cloud has "extensive access" to LINE's environment, making it easy to access data stored in the messaging app's legacy systems using NAVER's network. The guidance also reveals how authentication services were shared – a decision that became problematic as details of former LINE staff were stored in a shared Active Directory. Some of those former staff later contracted to LINE, and it was unauthorized access to those credentials – via NAVER Cloud – that led to the data breach. NAVER didn't spot the intrusion, so LINE wasn't aware it was at risk. The document includes extensive criticism of infosec practices and governance at both LINE and NAVER, and c...
Japan orders local giants LINE and NAVER to disentangle their tech stacks
The Register
·Simon Sharwood
·Published Mar 6, 2024
·Updated
Affected Software
2 affected components
LINE LINE app
NAVER NAVER Cloud
Frequently Asked Questions
1
What event triggered the Japanese government's order to LINE and NAVER?
A data breach that exposed the personal data of over 510,000 users prompted the Japanese government to intervene.
2
What specific action has the Japanese government mandated regarding LINE and NAVER?
The Japanese government has ordered both companies to disentangle their tech stacks to enhance data security.
3
Which software applications are primarily affected by this security issue?
The LINE app and NAVER Cloud are the main software affected by the data breach.
4
What kind of data was compromised in the breach involving LINE?
The breach led to the exposure of personal data belonging to over 510,000 users.
5
How significant is the LINE app in terms of its user base in Asia?
The LINE app is widely used across Asia, making it a major communication platform.