ADVERTISEMENT
970x220

Critical vulnerability in PH National ID System fixed

Published Apr 29, 2021 07:57 am  |  Updated Apr 29, 2021 07:57 am

A data privacy leak of massive proportion that could potentially put to shame the COMELeak, LTO, AFP, and all other local breaches put together was waiting to happen as PhilSys was about to put online the registration for the country's National ID System.

This week, the Philippine Statistics Authority, the agency responsible for the Philippine Identification System or PhilSys, announced the online registration for the National ID System. Philsys aims to establish a single national identification system for all citizens and resident foreigners of the country.

The Philippine Identification System or PhilSys is the government’s central identification platform for all Filipino citizens and resident aliens of the Philippines. (Photo from https://atom.hackstreetboys.ph/)

To ensure the system's smooth operation, PhilSys put up a User Acceptance Testing environment or UAT. It is a production-like setup, a final step before making the system available to the public.

When Secuna co-founder AJ Dumanhug noticed the PSA announcement, he immediately checked the PhilSys subdomains for possible security problems that could arise when the system is up for public use.

"As a security researcher and concerned data subject, I quickly checked the available subdomains of philsys.gov.ph using an online website and discovered the subdomain named register.philsys.gov.ph," Dumanhug said in his post.

Using the information from previous vulnerabilities he reported and promptly fixed by PhilSys, he found out that there is a new critical vulnerability in the final phase of the testing environment of the National ID System. By merely checking passively, he found out sensitive information that could be exposed if not fixed immediately.

The PhilID is a valid proof of identity that can be used to transact with the government and private sector. It is a non-transferable card issued upon successful registration to the PhilSys.

"I discovered some domains, IP addresses, Database IP, ports used, GitHub repository link, and other information. I also found sensitive information such as secret keys and passwords. The worst is that I found critical information that malicious individuals could exploit, such as authorization token of users who registered for PhilSys, their IP address, the system's IP address, cookies, and user's PhilSys registration ID." AJ Dumanhug said in an interview with MB Technews.

"The latest vulnerability could allow malicious users to access sensitive system information and retriever personally identifiable information of PhilSys users," he added. Since PhilSys aims to give all citizens and resident aliens a national ID, the potential of the data breach victims, if not fixed, could be millions.

AJ Dumanhug then informed PhilSys about his findings, and PhilSys immediately fixed the vulnerability. We could now expect a more secure PhilSys system once people start to register online.

AJ Dumanhug, Secuna co-founder and one of the country's top cybersecurity practitioners, once again proves that private companies and government agencies would benefit more if they would have responsible disclosure programs. It is a process that allows security researchers to report to the company or agency found vulnerabilities in their systems, networks, or services.

Here are some of his recommendation to PhilSys:

1) Change the secret keys and password 2) Check for sensitive folders and files or open services and remove or close them before deploying online.

AJ Dumanhug was also responsible for exposing unauthorized access of malicious users to the LTO's database. While LTO denied a breach and that the data are unnecessary, the National Privacy Commission investigated the agency for the leak and ordered the internet service providers to take down the website that collects information from the LTO database.

ADVERTISEMENT
300x250
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0 72px 0 12px; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // The two offset values // changed to 10 from 1 , 2 const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } function isNearBottom() { return window.innerHeight + window.scrollY >= document.documentElement.scrollHeight - 100; } function onScroll() { if (isLoading) return; // Skip if already loading if (isNearBottom()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; // Set flag to prevent multiple calls const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { loadCount++; // Increment only after successful execution }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; // Reset flag after execution }); } } window.addEventListener("scroll", onScroll); }); // Mutation Observer for Newly Loaded Articles const observer = new MutationObserver(() => { const articles = document.querySelectorAll(".articles-observe"); if (articles.length > 0) { observeArticles(articles); } }); observer.observe(document.body, { childList: true, subtree: true }); // Intersection Observer for Updating URL function observeArticles(articles) { const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); } } }); }, { threshold: 0.1 } ); articles.forEach(article => intersectionObserver.observe(article)); }
.col-md-12.noPadding.col-xs-12:has(.mb-header-bottom) {padding: 0;} .bottom-footer {color: #fff;background-color: #2E3192;padding: 8px 0;} .bottom-footer .bottom-footer-menu {font-family: Inter;font-weight: 400;font-size: 12px;line-height: 16px;padding: 0px 10px !important;color: #fff !important;text-decoration: none; } .bottom-footer .container {display: flex;justify-content: space-between;align-items: center; } .bottom-footer p{font-family: "Inter";font-weight: 400;font-size: 12px;line-height: 16px;margin-bottom: 0;} .subscribe-button{position: absolute;bottom: 15%;right: 11%;} .subscribe-container {position: fixed;display: flex;align-items: center;background-color: white;height: 50px;border-radius: 50px;box-shadow: 1px 3px 8px 3px rgba(0, 0, 0, 0.2);width: 50px;overflow: hidden;transition: width 0.3s ease-in-out;text-decoration: none;white-space: nowrap; } .subscribe-icon {background-color: #2E3192;color: white;border-radius: 50%;width: 50px;height: 50px;display: flex;align-items: center;justify-content: center;font-size: 18px;flex-shrink: 0;transition: border-radius 0.3s ease-in-out; } .subscribe-text {font-size: 18px;font-weight: bold;color: black;margin-left: 0;margin-right: 0;width: 0;visibility: hidden;opacity: 0;transition: opacity 0.3s ease, width 0.3s ease;} .subscribe-container:hover {cursor: pointer;width: 170px;} .subscribe-container:hover .subscribe-icon {border-bottom-right-radius: 0;border-top-right-radius: 0;} .subscribe-container:hover .subscribe-text {visibility: visible;opacity: 1;margin-left: 10px;margin-right: 10px;width: auto;} h6.footer-heading{ font-weight: 700; } #bottom-footer ul li { display: flex; align-items: center; } @media screen and (min-width: 767px) and (max-width: 991px) { .bottom-footer p, .bottom-footer .bottom-footer-menu{ font-size: 9px; } } @media(max-width: 767px) { .bottom-footer .container {display: block;} .bottom-footer .container .justify-content-center{margin-top: 20px !important;} .bottom-footer .container .justify-content-center .list-group{ width: 100%; display: grid; row-gap: 10px; grid-template-columns: 1fr 1fr 1fr; justify-content: unset; } .bottom-footer p{font-size: 10px;} .subscribe-container { width: 50px !important; overflow: hidden;} .subscribe-container:hover { width: 50px !important;} .subscribe-container .subscribe-text {display: none !important;} .subscribe-button{right: 15%;bottom:7%;} } .mb-header-bottom .header-menu:hover { color: #2E3192 !important; } @media(max-width: 400px) { .bottom-footer .container .justify-content-center .list-group{ grid-template-columns: 1fr 1fr; } }

Sign up by email to receive news.