Dumaguete Info Search


Massive ph data breach (COMLEC website)

Discussion in 'News and Weather' started by DavyL200, Apr 8, 2016.

  1. DaveD

    DaveD DI Senior Member Showcase Reviewer Veteran Navy

    Messages:
    859
    Trophy Points:
    196
    Location:
    Dumaguete
    Ratings:
    +1,041 / 129
    Blood Type:
    A+
    The registered voters of the PI on Comelec website that got hacked by Anonymous Philippines. It's all over the internet.
     
    • Like Like x 2
  2. TheDude

    TheDude DI Forum Patron Highly Rated Poster

    Messages:
    1,907
    Trophy Points:
    351
    Ratings:
    +1,465 / 822
    Are you bagging on Filipino's? :wink: Someone with a brain and an internet connection could download the data and answer this question directly. And you would probably get more accomplished that way.

    No ****. It's a database. The point of a database is that you are able to query it. If all the fields werre encrypted, then you couldn't query it. It would no longer be a database.

    No it's not. The passwords are encrypted, but you can't read passwords anyways. It's a one-way encryption process and generally worthless as data. As long as the data can be displayed, it's not ecrypted. The hackers likely got this information by accessing the database as opposed to downloading a bunch of files from the server.

    You could do key encryption so that certain items can be decrypted when it needs to be (information which doesn't need to be used as a possible query field) but as long as you have the keys to the server, then you probably have the means to display the info.

    That there is actually encrypted info in this data means they probably just did a general dump. Spitting out all the data is a relatively cheap operation as that's what database software is designed for. Having the system decrypt data for this many records would be a much bigger job as you would probably need the content management system software to do the decryption.

    So, yeah, identity fraud. In the U.S. that generally means credit cards. Good luck opening credit card accounts for Filipino's. :wink:

    Phishing scams? You would have to friend them on Facebook first.

    Generally not the most high value data.

    Maybe I could use it to score some chick's phone numbers.
     
    • Informative Informative x 1
  3. Rye83

    Rye83 with pastrami Admin Secured Account Highly Rated Poster SC Connoisseur Veteran Army

    Messages:
    13,106
    Trophy Points:
    451
    Occupation:
    FIRE
    Location:
    Valencia
    Ratings:
    +16,069 / 3,796
    Blood Type:
    O+
    :hmmm: I don't think so.

    TDE. But if the data is presented to the public, as 99 percent of forum user data is, there is no need to encrypt it.
     
    • Agree Agree x 1
    • Informative Informative x 1
  4. OP
    OP
    DavyL200

    DavyL200 DI Forum Luminary ★ Global Mod ★ ★ Moderator ★ Highly Rated Poster Showcase Reviewer

    Messages:
    3,968
    Trophy Points:
    401
    Location:
    On an island
    Ratings:
    +5,126 / 466
    Remember when OPM got breached last year? There was a lot of excitement in various parts of the world (namely the US) because here we had a government department (Office of Personnel Management), and they’d just lost 21.5 million records! These records included such sensitive data as names, dates of birth and addresses and by any reasonable measure, it was serious – that’s almost 7% of the country’s population!

    Yet somehow, last week’s news that 55 million Filipino voters’ data was now out in the wild went largely unnoticed. Let’s put it down to a very western-centric tech media but move past that and look at this incident for what it is – a ginormous data breach with extremely sensitive information and at 55M individuals, that’s also more than half the country’s population.

    Whilst there’s been limited press coverage on the issue, a public statement from the Filipino government has suggested that nothing sensitive was disclosed. As I discovered when I reached out to some of the people involved, this is blatantly wrong. Here’s how it all unfolded. When a nation is hacked: Understanding the ginormous Philippines data breach
     
    • Informative Informative x 2
Loading...