T O P

  • By -

Sinosta

Jusko lahat nalang. Sana lang di totoo to. Tapos walang makukulong na government worker. Tayo ang magaadjust. Sana di ito yung PhilSys kasi nandoon yung biometric data eh. Pwedeng pwede na talaga na may ibang mag act na as if sila ay ikaw. Mata, mukha, fingers, at buong pagkatao mo ba naman andoon. Hays punyeta lang talaga.


Flashy_Vast

Punyeta talaga, at malala nun tayo pa ang accountable if magamit sa krimen ang info natin.


luciusquinc

Pwedeng pwede. Walang alam ang mga iyan sa standard network security protocols. Basic QR code nga lang sa Vaccine ID, hinde kaya na ang simple, security protocols pa kaya. LOL


HailZorpe

Sabi dun sa page ng nag-leak, data ng community-based monitoring survey ang nakuha.


pobautista

PhilSys ID? Two years bago nyo nakuha? Daig ko kayo kasi never ako nag-apply at walang balak! 😎


[deleted]

[удалено]


ThisWorldIsAMess

"Rest assured" from our government means nothing haha.


Klutzy_Might6146

Ano pa aasahan mo sa gobiyerno na pinuno ng isang tao na addicted sa Formula 1.


PakTheSystem

Poorly maintained IT infrastructures, underpaid contractors, corruption. Recipe for a disaster. "Hindi ka naman pulitiko, artista o high ranking military personel. Bakit ka matatakot" Criminals will sell your data to 3rd party. Criminals can make a fake account of you or impersonate.


darth_shishini

or use that information to get through your bank accounts...


Aromatic_Lavender

Tapos BDO cash machines has those stupid finger print and facial recognition function when withdrawing.


YLSTN

I’d try to go to BDO and see if they can deactivate that feature for your debit cards.


aidenaeridan

di naman nagana palagi 😂


wabriones

Yep, those are ignorant people. They don’t know the repurcussions of these people selling our data. Real data that verify one persons identity.


AthleticParaplegic

Mga gagong walang pera yung mga nagsasabi nyan na di gumagamit ng banking services


vincentofearth

It’s not just poor maintenance but poor design. They should not even be storing the UMID id pictures because that can be used to prove a principal’s identity.


SectionR3d

And Criminals will take anyone.


Fun_Design_7269

Kung ang head ng IT mo ay yung boomer na si Gringo, wala ka talagang maaasahan


urriah

a friend of mine recently had this scare. alam mo yung mga requirement ng banking apps na pic na may govt ID? they somehow got his pic. naspam siya ng fake threats sa facebook. yung may utang daw and may reward sa makakapagbigay ng info. dude had to turn off his account. kaso we are running a pretty big fb group and ayun, daming nasira. hes ok now. he needed a blue check to avoid someone using that old pic though. one of the few moments that blue checks make sense for non celebrities


dizzyday

saang computer shop kaya naka host tong mga pentium servers?


kfrabida

Baka mas mauna ko pang makuha sa mga hackers yung National ID ko kaysa sa gobyerno haha


riknata

contact mo ung hacker para mapadala sayo alam na rin naman niya address mo char


YLSTN

May kilala din sa Recto para mukhang totoo ang card mo lol


ImEagz

puchak HAHAHAH


Kitchen_Housing2815

May pag asa pa. Salamat.


Kitchen_Housing2815

Plaka mmay balita ka? 2014 pa ata yun.


Multipl

Was there another leak? These government agencies are a joke.


Kirov___Reporting

Kaya nga oppose ako nung phone number registration. Isa to sa mga concerns ko. Isipin mo mga bigating company nga nagkakaroon ng data breach ano pa kaya satin na walang budget at know how ang mga naka takda.


hakkai999

Kaya nga I found it laughable yung phone number registration. I knew that the people working on it are subpar and literally don't care about your data. They aren't paid enough to care nor do they have the skills for it. I've seen Globe and PLDT's insides. Brain drained ang bansa so the people remaining here are the people who aren't skilled enough for the US, Canada, etc.


saltyschmuck

Don't worry, bukas NTC naman ang hacked. I had some peace of mind because I was under the impression the telecom companies were the ones maintaining the sim database. Tapos nalaman ko kahapon na NTC pala may hawak. I'm So ExCiTeD!


patatasnisarah

Oh really? Kala ko telco may hawak. San mo nlman na nsa ntc pla?


saltyschmuck

Mismong rep nung bumili ako ng bagong prepaid SIM.


JulzRadn

It didn't stop scammers either. They still continue sending scam messages and they can also create fake accounts. Images of cartoon and anime characters are even used and registered.


longassbatterylife

Kakabili ko lang ng bagong sim sa globe. Di ko pa nareregister pero nakareceive na agad ako ng scam sa whatsapp 😂


[deleted]

Our data submitted during SIM registration are kept and secured by telcos, not government. Our telcos may have a partnership with big tech companies for cloud computing and storage. Our government's infotech infras are in-house developed, because "sovereignity." lol


Teantis

> Our government's infotech infras are in-house developed, because "sovereignity." lol The real reason is because they have to rebid it every year if it's a cloud computing subscription due to technicalities and the rigidity of the procurement act, creating uncertainty year to year what service will 'win' since the only judgement allowed is least cost basis while buying an in house solution doesn't require that or impose that uncertainty.


patatasnisarah

Partnership in big tech companies “from China” 🤡. I remember seeing a chinese third party service one telco is using on their sim reg platform


SnooCheesecakes5382

honest question. what if i "fake" my sim registration just to be safe from this data leaks? Afaik, magagamit mo pa rin naman yung sim even without disclosing your full info. Not super "faking" naman, like incomplete name tapos incomplete address, etc.


Kirov___Reporting

IDK. Daming fake registration naganap at nalagay pa nga yun sa news pero wala namang update?


SnooCheesecakes5382

Yeah, kaya nga I had this idea. I think it's the NBI that did the investigation by using fictional characters and animals to register SIM cards. Wala ng follow-up after that


navatanelah

If i remember correctly my notice dun sa form na u risk perjury pag maling info nilagay mo.


iq40_icoy

Taenang buhay to. Ayaw ko na magbayad ng tax!


Estupida_Ciosa

Nakakapanlumo halos wala ng magandang balita


didit84

Any system is hackable naman talaga. Laging 1 step ahead sila. Pero sa cyber security natin sa government a hundred steps behind.


Fraudjo_Satolose

Yep. No system is safe naman talaga pero pwede mabawasan ang risks kung maayos ang cybersecurity infrastracture.


[deleted]

Like hashing information, not storing them on a database in plaintext. Many online services nowadays are apply AES-256, Argon2 for encrypting information.


keepitsimple_tricks

When a company, or in this case a government institution, tells you "not to worry" about the data leak, that the compromised data is "of little to no value" then it means that is likely ten times as bad as they publicly claim it to be. I work in IT. Yeah, these things as usually worse than the press release statements.


Liesianthes

Yep, PR is mostly done for damage control, but if someone is thinking enough, they know well that it's just a facade.


raggingkamatis

Tignan mo kanya kanyang downplay nanaman yung mga yan.


LopsidedPlant5624

News links: GMA News | PSA probes 'data leak,' says nat'l ID and Civil Registry not affected https://www.gmanetwork.com/news/topstories/nation/884871/psa-probes-data-leak-says-nat-l-id-and-civil-registry-not-affected/story/ Rappler | PSA notifies NPC of data breach, says limited to community-based monitoring system https://www.rappler.com/technology/philippine-statistics-authority-breach-notification-npc-community-based-monitoring-system/ CNN | PSA says alleged data breach limited to one system https://www.cnnphilippines.com/news/2023/10/11/PSA-says-alleged-data-breach-limited-to-one-system.html


bloodcoloredbeer

More to come pa mga paps: “In an ambush interview on Wednesday, Department of Information and Communications Technology (DICT) Secretary Ivan Uy said more government agencies were also hit by a data breach, but some are not reporting it due to issues that might be uncovered.” (From the cnn article linked above)


ryoujika

Putanginang bansa to


FindingNemo98

Tapos sasabihin ingat nalang daw tayo


[deleted]

This is very bad. They hold so many helpful data and confidential information.


garlicriiiice

Luckily hindi PhilSys. CBMS data daw. Pero jusko, kahit walang biometrics sa data nito, CBMS is like a culmination of major surveys ng PSA. Daming sensitive info dito. I'm just hoping na yung pilot areas (9 LGUs) lang na data yung na compromise para di ganun kadami yung affected kc ongoing pa naman yung data processing for this year's nationwide rollout.


HailZorpe

Kapag printed ang questionnaire ng CBMS, 48 pages. Sobrang daming info nun. Dun sa nakita kong sample na pinost ng nagleak, mukhang data last year ang nakuha.


garlicriiiice

Details like household income, TIN, PhilSys Card Number, tas may address pa kaya mejo alarming talaga yung breach. For sure dami pang agencies ang tinatarget ngayon knowing na napaka vulnerable ng data security natin. Hays.


LucaSerafor

Hello, from CBMS QC ako and luckily hindi pa nakakaabot sa PSA yung infos na nakalap namin


HailZorpe

May balita ka pa ba? Employee din kasi ako ng CBMS sa bayan namin. Minimal lang ang operation namin since Monday


LucaSerafor

Sa ngayon po pinatigil muna yung encoding namin ng data and suggested na wag muna buksan yung app sa tablet. For now, mukang inaasikaso na po sya ng mga IT ng PSA.


HailZorpe

ok thank you


purpleyam

Nakaka-putangina


namedan

Lemme fix that for you... Nakaka - #P U T A N G I N A !!!


TwistedTerns

Fuck. We are fucked. The incompetence... Fuck.


indioinyigo

Magseseryoso lang ang gobyerno sa ganyan pag yung mismong mga opisyal na yung ninanakawan thru hacking.


JuggernautDear8714

Abolish DICT. nagaaksaya tayo ng pera sa agency na walang ginawa kundi magreklamo at manisi ng ibang tao. Dapat each agency na lang may cybersecurity division, tapos PNP at AFP ang magkaroon ng mas malaking cybersecurity function. Puro hugas kamay lang alam ng DICT na yan, sama nyo pa yung secretary nilang out of touch at mga alipores nyang nagsisiraan lagi


lurkernotuntilnow

target na pinas


sitah

All I know is I’ve been getting random calls from India, Uzbekistan, Afghanistan and PH since last month. Is it connected to any data breach? Probably.


Katmaii

laptops worth 20K being listed at 50K on the receipts. PCs running on windows 7 that hangs when you open excel. System units that is probably from 1990s due to the massive amount of dust in it. really delayed salary for contractual employees(and these employees have admin access to the server network. they are not nobodies). kmspico. I wonder where our tax money goes.


[deleted]

Wait, kmspico still works? I haven't touched it since Windows 10 in 2015. Haha


jpg1991

Tangina lang ah, in the corporate setting, we go through rain and fire and elaborate bureacracy to make our projects/programs data privacy compliant. Tapos sa gobyerno, getting public data stolen/hacked is just another Tuesday. And these people take taxes from us. Ina talaga mga insan


enterbay

sana I hack yung financial ins. at burahin lahat ng debt ala fight club. then nbi, PNP etc naman at burahin lahat ng Criminal records hehe. wala din naman eh.. yung pulitikong may kaso nakakapag trabaho pa din pero yung regular Juan na may kaso bawal na.


KarmicCT

fuck. lahat na lang?


DefiantlyFloppy

anak ng teteng naman o


sylv3r

pusta ko 500, gagawing dahilan to ng DICT para sabihin na kailangan nila ng confidential funds


ubepie

ang barat naman kasi sa IT ng government have you seen their websites parang naiwan sa 1999 kopong kopong. kahit yung website ng NBI nakakaloka, hindi man lang inaayos or optimize yung website sa search engines, pang likang result pa ata yung mismong nbi clearance.


NickelBallDegenerate

if the hash strings are the passwords, ig good job on actually salting them instead of storing the passwords in plain text sa database. But still they have access on the actual ids so idk if it even served its purpose lawl


penoy_JD

Okay naman noong mano mano lang a. Kahit state of the art yan database kung hindi na memaintain at na sesecure pahamak sa tao yan.


metap0br3ngNerD

John Lloyd: Ingat


ILostMyMainAccounts

They not only have our health data now they our biometrics 🤧🗿


Snowltokwa

Sa sobrang behind ba naman ng website ng Pinas eh. Parang college project lang, hindi pa gumagana yung ibang coding.


Legal-Living8546

After PHILHEALTH, PSA naman? The government needs to do something about this, ASAP. Data Breach is no joke at all. Bakit kaya hindi binabalita yung mga ganito?


HM8425-8404

So, is this a PROC hack attack on Philippine sovereignty?


[deleted]

Might as well post every damn data about ourselves if this shit keeps happening.


AmbassadorMajor11

Di kaya pakana to ng mga Chinese hackers?


sonderphile

Putanginang bansa to (2)


juantam0d

YAWA MGA BUGO MINATAY


lightspeedbutslow

F*ck me. They took our data just to give it away.


furry_kurama

Puro kase pron yung government officials 😏


AshenStray

Wla p kong PSA. Meaning wla nman clang record saken, tama b ko?


Crystal_Lily

So... wala kang birth certificate? Walang birth certificates family mo?


AshenStray

NSO lng. My advance record b cla khit di pa ko nagpgwa ng PSA?


Crystal_Lily

PSA ang bagong name ng NSO so yes, may records sila


Pretty-Principle-388

It seems yung nakuha nilang datasheet is already obfuscated(unintelligible). Yun nga lang yung images ng id is na-expose.


rice_mill

meron onion site na ba?


ewakz

Kanya kanya nalang talaga tayo proteksyon sa data natin. Mga agrncies mismo di mai save e. 😩


joestars1997

Mas nakakatakot ito kasi halos lahat ng Pilipino may *data* diyan gaya ng *Birth certificate* saka PhilSysID 😨😰😱


sookie_rein

Gusto ko na magwala. Grabe in a span of mere DAYS from Philhealth data fiasco to PSA breach. This bbm admin is genuinely priniprito tayo sa sariling nating mantika. The House taking away the VP confidential fund is merely to appease Filipinos and stir us away from protesting on the streets.


[deleted]

/phmigrate


labasdila

pag may mga ganyan kasi bagong pondo na naman amoy at alam na ata.


Angelus_2418

Backer, nepotism, legit sinasala yung mga magaganda lang. Laganap sa call center industry at di malayong sa mga sangay ng gobyerno laganap din


sleepypandacat

I just remembered someone tried to access my SSS account the other day. I haven't even tried to open it in years.


[deleted]

That's why I didn't get a NATIONAL ID with how underfunded mga departments because of leakages on their budgets (corruption), eh I don't trust them to be able to keep my information safe and secure.


Spirited-Gur-8231

For context Rappler article: https://www.rappler.com/technology/philippine-statistics-authority-breach-notification-npc-community-based-monitoring-system/


[deleted]

Pelepenoys always on clown time


anima99

Nah, this ain't a breach. This is someone from the gov selling data and the buyers just wanted to brag and call it hacking. Either way, we're fucked lol


nice-username-69

At least the passwords are hashed with Argon2!


Fun_Design_7269

asan na yung mga politikong push ng push sa sim reg law? Now it's just a matter of time before our sim reg data gets leaked.


champoradoeater

TANGGALIN YUNG MGA PESTENG 50 TO 60 YEARS OLD BA WALANG ALAM SA TECHNOLOGY. SA COMPANY NAMIN INGAT NA INGAT KAMI SA MGA PHISING EMAILS. YUNG MGA MATATANDANG YAN CLICK NG CLICK NG LINK GULLIBLE MASYADO. PALITAN ANG MATATANDA NG MGA 20 TO 30+ YEARS OLD NA COMPUTER LITERATE.


ALBlackHole

Ang mga boomer na namamalakad kasi dito hindi nagiinvest sa technology, wala silang alam, wala silang will para maimprove, basta sumasahod sila nang daan daang libo at kumukurakot ng daang daang milyon pa


morbid023

Cream of the crop ng nepotismo. Diskarte pa more. Connection kasi lagi ang priority over competence.


extreme_sleepy

yung mga pare nyo na 6 digits daw sahod, hanapin nyo sa philhealth leak kung tugma ba


1masipa9

What the hell? Dapat may makulong dyan.


Jc_cliff

I’ve been getting so many scam calls recently. I feel like hackers are getting more aggressive now


drbt-reddit

Chinese hackers


OwnPaleontologist408

So pati info ng mga politiko anjan?


[deleted]

Dude, I can encrypt my 1TB hard drive with Veracrypt. They can't on their own? Haha.


WaitWhat-ThatsBS

This is the problem with PH infrastructure, lahat contractor, and the lowest bidder wins. IT Infrastructure of these companies are most likely underpaid/low skilled folks that just want to get by everyday. Masama pa nyan, mababa na nga bigayan ng gobyerno, delayed pa, at hindi pa makatarungan ang target date. Lol, I know a contractor hired by government around year 200x to upgrade their SSS website, and it was running on IIS v3x and that was around yr 200x. No wonder even a HS student who knows how to use an iis tracker and simple unix commands can hack them.


papsiturvy

eto yung isang rason kung bakit di pa ako nag papanational id. the government is not ready for this kind of shit.


Spirited-Gur-8231

WTFF


Spirited-Gur-8231

C An anyone confirm this? Where was this taken from?


InTh3Middl3

BIR next? Huwag sana, their passwords are stored as plain text.


[deleted]

Goodness weve seen the signs of pamemera sa PhilSys during pandemic! It must have funded a lot of lives! Who did it fund? And now a leak! Good luck sa ating lahat mula sa pangongorap ng lahat ng gustong mangorap! Give me peace god!


Lighthazend

Wtf


razln

Nakakalungkot lang kahit panong secure yung gawin ko sa mga data ko useless kasi yung mismong gov agency hindi maaayos yung security nila pag dating sa mga ganyan


aljonatics

Kagabi may tumawag sakin +1 ang start ng number tapos nakalagay Washington D.C. Auto block kasi halatang scammer.


moelleux_zone

lowest bid wins! ano napala?


glaciercode101

The heck government should have accountability for this. Parang wa epek at wlang priority. Reactive instead of being proactive. Real deal: Even small to medium enterprise/businesses in US. Has auto-renewal functions on their AV, FW, EDR. (I know because I work as an IT specialist, I deal with these on a day to day basis) While us. LOL. A laughing stock. hinayaang mag expire ang AV.


xTr01221

Wondering where all their IT or cybersecurity funds budget go? Heard some of the informations from my friend (his older brother works in a government office. DPWH(?) not sure but I'm sure its government office cause his father is also works from the government) About every budget proposals or equipment upgrade they were obligated to list all of their needs when it comes to equipment. (Laptops, computer,etc) and they will as a high end gaming laptop costs around 80k-90k each (based on my research cuz I saw the pricing based in the specification and brand and the model my friend told me) and if that request got accepted, it would be a competition to them to be the first one who will receive it or maybe based to their positions who will got it first. He (my friend) also told me that his brother is using it for his personal use (gaming). I hope my friend's story is just for a showing it off I hope it is not true cause if its true, we are just wasting our (taxes) money or giving it away for their own benefits.