Five years after Korea abolished its mandatory certificate, logging in still means choosing a company
Removing the accredited certificate's legal monopoly in December 2020 ended two decades of plugin misery and replaced a state-mandated bottleneck with a handful of private identity gatekeepers.

For roughly twenty years, doing anything consequential online in Korea required a specific piece of software. The accredited certificate, established under the Digital Signature Act of 1999, was a public-key credential issued by designated authorities and granted a presumption of legal validity that competing methods did not receive. In practice that presumption made it compulsory: banks, brokerages, the tax service and government portals all required it, because using anything else exposed them to evidentiary risk. The certificate itself was a reasonable piece of cryptography. Everything built around it was not.
Because the certificate had to run inside the browser, Korean financial sites delivered it through ActiveX controls, which existed only in Internet Explorer. Around that dependency accumulated a second layer: keyboard encryption modules, anti-keylogger agents, personal firewalls, each installed separately per institution, each a background process, none removable. Users stored certificates on USB sticks and renewed them annually. Passwords had to mix character classes and were re-entered constantly. Macintosh and Linux users, and anyone abroad on a foreign-issued phone, were substantially locked out of Korean banking. Because the mechanism was mandated, none of this had to improve, and for a decade and a half it did not.
The amended Digital Signature Act took effect on 10 December 2020 and removed the accredited certificate’s privileged legal status. The change is often described as abolition, which slightly overstates it: the same credential continued to exist, renamed the joint certificate, and remains in use. What ended was its monopoly. Electronic signatures of other kinds became legally equivalent, and institutions became free to accept whatever they could defend as reliable.
Competition arrived quickly and the improvements were immediate and visible. The banking sector’s clearing institute issued a financial certificate stored in the cloud rather than on a USB stick, with a multi-year validity and a simple PIN. The three mobile carriers jointly operated a certificate delivered through a phone application. The dominant messaging platform, the leading search portal and several fintech applications each issued their own credentials, unlocked by biometrics or a six-digit code, with issuance counts running into the tens of millions within a few years. Government services followed, accepting private certificates for year-end tax settlement and portal logins from 2021. The plugin stack largely disappeared. Browser choice returned.
The structure that replaced the monopoly, however, is not neutral. Acceptance is fragmented: a given bank, insurer or public service supports some certificates and not others, so most people hold three or four and discover which one is required at the moment they need it. More significantly, the identity layer underneath all of them did not change. Verifying that a new user is who they claim to be still typically routes through mobile carrier authentication tied to a resident registration number, which means a very small number of private companies sit at the entry point of nearly every Korean online service. The state did not so much dismantle a chokepoint as decline to run one, and the position was occupied by firms whose incentives are commercial and whose accountability is contractual.
The government has been building a public alternative in parallel — a mobile driver’s licence from 2022 and a broader programme of digital identity documents — which is the right instinct, though public options in identity tend to compete poorly against credentials already installed on the phone for other reasons.
The transferable lesson is narrower than “deregulation worked”. Korea’s mistake was never requiring strong authentication for banking; it was mandating a particular mechanism and then granting it legal privilege, which converted an engineering choice into a permanent one and removed the pressure that would have modernised it. Requiring an outcome — that a signature be reliably attributable — leaves room for the method to improve. Requiring a method freezes the year it was written in, and Korea spent two decades in 1999 finding that out.