ADVERTISEMENT

DICT: Hackers got into the 'test site', not the website itself

Published Oct 25, 2023 11:23 am

The Department of Information and Communications Technology (DICT) on Wednesday, October 25 claimed that hackers were able to infiltrate the “test site” and not the website of the agency itself.

DICT Undersecretary Jeffrey Ian Dy disclosed this during the Senate Committee on Science and Technology hearing on the various resolutions seeking an investigation into the country’s cybersecurity measures.

Dy explained to the committee that the agency utilizes a “test site” to check the stability of their website against cyber attacks since they have their own vulnerability assessment and penetration testing.

“That particular device or that particular ‘website’ was actually designed to be attacked, that’s what I only would like to point out, sir without going for the technicals of it,” Dy told the Senate panel.

Dy said hackers were able to penetrate this particular site because they left it open by mistake, but the public has nothing to worry since this test site is empty.

“For the record…that website contains nothing it was a test site that we used for checking vulnerabilities because we also have our own vulnerability assessment and penetration testing,” the official said.

“So the only unfortunate thing that happened is that after the testing, it was left open. But we assure the public there’s really nothing there,” Dy added.

But when Sen. Alan Peter Cayetano, chairman of the Senate science panel inquired if it is necessary for Congress to give the DICT confidential funds to put a stop to the online hacking activities in the Philippines, Dy replied in the affirmative.

Dy told the panel the DICT is short on funds to strengthen its own cybersecurity measures.

Cayetano agreed and said the agency deserves such funding so that the DICT can provide sufficient reward for those who can provide information on these hackers.

The DICT, however, said that all their funds for cybersecurity do not need to be confidential funds, but they would leave it to Congress to decide whether or not to grant them such funds.

For his part, Cayetano urged the DICT to hire more cybersecurity experts amid the growing threat of hacking and data breaches in the Philippines.

Aside from the DICT, the websites of the Philippine Health Insurance Corp. (PhilHealth), the House of Representatives, and the Philippine Statistics Authority (PSA) were also defaced over the past few weeks.

“Are there enough cyber security experts in the DICT and in government? Baka kasi may fund na ibinibigay for (because there could have been funds available for) counter attacks, but there are not enough experts in government,” Cayetano lamented.

Mary Rose Magsaysay, Cybercrime Investigation and Coordinating Center Deputy Executive Director, told Cayetano that they currently have 55 experts among their personnel.

Magsaysay said most of them are cyber technologists and the “best of the best people” they know, and admitted that the 55 experts are not enough manpower.

Cayetano agreed and noted that another issue is getting IT experts into government as most of them would rather work abroad or at the private sector.

“We can’t blame them for wanting to provide for their family. It's not for everyone, but there are really hot career choices na kung hindi tayo makipag agawan sa gobyerno ay mapupunta sila sa private sector o abroad (that if the government cannot offer better pay, they will go to the private sector or abroad),” the senator noted.

Cayetano also pointed out that the budget of the Philippine National Police’s (PNP) cybersecurity personnel, is far from ideal since their 2024 budget for the Information System Strategic Plan (ISSP) for 2023 to 2025 is at least P100,000 per region only.

“It’s a good start… pero mas kumplikado rin pala (ang hiring) sa PNP. Ang sweldo kasi nila ay parallel to the rank. Kung may cyber expert sila pero major, hindi naman pwedeng mas mataas ang sweldo niya sa general (but the hiring process in the PNP is complicated. Their salary is parallel to the rank. If they have a cyber expert but is a major in rank, it’s inappropriate for him to have a pay that’s higher than the general),” the lawmaker acceded.

“That would be a complication for both. So let’s have a separate discussion on this,” Cayetano said.

Nevertheless, the senator urged the government to immediately look into this investment for the PNP and the military since “future wars will be fought in cyberspace.”

Related Tags

Department of Information and Communications Technology Senate of the Philippines Alan Peter Cayetano
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.