Close
 


Philhealth HACKED! Paano na personal data natin?
Hide Subtitles
Click any subtitle word to view Tagalog.com dictionary results.
Computer Shortcuts: Left / Right arrows to jump 2 seconds back or forward. +Enter or Space to toggle Play/Pause button. Full Screen Mode
Gaano ka-grabe yung pagkaka-hack sa Philhealth? Watch our episode with data scientist and cyber security expert Dominic Ligot
Christian Esguerra
  Mute  
Run time: 45:04
Has AI Subtitles



Video Transcript / Subtitles:( AI generated. About AI subtitles » )
00:00.0
🎧 Intro Music 🎧
00:27.0
Good evening guys! Welcome to tonight's episode ng ating Facts First Podcast. Ako po si Christian Esguerra. Maraming maraming salamat po sa patuloy ninyo pong pagsuporta dito po sa ating programa.
00:38.0
So today is October 5 para mahina yata internet ko. Ayoko na idiretso rito sa naka wifi ako. Ayoko na ikonect directly rin sa LAN dahil baka mawala yung camera ko. Magka problema na naman.
00:54.0
Anyway, iraos natin ito. Pag-uusapan po natin may kaugnayan sa cyber security. So I suppose nabaritaan nyo po yung nangyari sa Philippine Health Insurance Corporation o PhilHealth.
01:25.0
So di ba sinabi ko nabiktima sila sa PhilHealth? Actually tayo yun. Kasama tayo dun. So tayo po basically nabiktima nitong hacking incident, yung tinatawag na ransomware attack.
01:37.0
Ang salary ng mga hackers ang pangalan Medusa. So papa-explain po natin sa ating ekspertong guest ngayong gabi kung gano bakat hindi itong efekto nitong nangyaring ransomware attack dito po sa PhilHealth.
01:49.0
And of course, ang latest po ay naglabas na po ng ilang mga data yung mga hackers dito po sa tinatawag na dark web. Basically na-expose na po yung ating data dyan po sa dark web. So ano po implications nya? Napakaseryoso po itong usapan natin ito.
02:19.0
So kayo mga troll, quiet muna kayo. Hindi naman political ang pag-uusapan natin. Pag-uusapan natin dito, apektado lahat. So kayo mga troll dyan, I suppose cover din kayo ng PhilHealth. Yung mga bulag na loyalista, so habok pa rin kayo ng PhilHealth or nasa PhilHealth kayo. So makinig lang kayo, pag-aralan natin itong issue.
02:49.0
So, sa program again, si Mr. Dominic Ligot siya po yung founder ng Data Ethics PH. Isa po siyang data scientist at the same time cyber security expert. Magandang gabi Doc, docon nickname niya. Maraming salamat for joining us.
03:19.0
Ano ba yung nangyari? Mukhang ransomware tayo. Actually pwede ko i-connect. Actually pwede ako mag-reconnect kagamit dito yung LAN cable para malinaw ako. Pero lalabas ako dito sa studio. Pero magsarita ka lang. Okay lang ba yan?
03:34.0
Yeah sure, no problem. Hanggang hindi ako bumabalik. Mabilisan ito. Siguro mga 3 oras lang. Siguro mga 15 seconds. Okay. Papa-explain ko lang muna sa iyo Doc. So basically ano ba yung nangyari? Ano ba yung nangyari dito sa PhilHealth? Yung tinatawag na ransomware attack? Go.
04:04.0
So basically it's a cybercrime group. Marami na silang victim na mga companies at global sila. Hindi lang sila focus dito sa Philippines. PhilHealth obviously yung pinaka-recent victim nila. Pero parang gawain talaga nila, mag-hack talaga ng mga companies na actually kung base sa mga pagsusuri namin, yung mga companies na victim nila before.
04:34.0
So alam mo itong mga hackers na ito kung titignan mo yung mga galawa nila, on the one hand talagang they're really in it for the money. Talagang nag-ransomware sila para kumita. But on the other hand, and again I'm not approving their work by any means.
05:04.0
So maraming mga conditions that could have led dito sa PhilHealth hack na ito. In my opinion, sana na-avoid natin kung sana proper precautions were made.
06:04.0
I don't know whether they should click the link or not. Actually you should not click the link. Can I be very clear? Kasi ano yan, product yan of a cyberattack and kung mahuhuli ang kahit sinuman na may possession ng data na yan, that can constitute a cybercrime.
06:25.0
It's a crime. Okay. Sige. Exfiltrated data yan. Di mo dapat ginagalaw yan.
06:55.0
So maraming silang natira. And these are companies all over the world. So mukhang global group. Di lang sila base sa Pilipinas. And maraming mga grupong ganyan actually. Mga naghahanap ng mga mabibiktima. And baka later pag-usapan natin ano ba yung mga possible scenarios kung paano nila nahanap itong PhilHealth.
07:23.0
Medyo excited ako dyan. Pero ilatag lang muna natin kung gano'ng kavicious itong grupo na ito. As far as yun o gano'ng katagal na ba sila nag-cooperate?
07:54.0
Yung mga nagbayad, most likely may mga syempre hindi namin sinuri lahat. You can always interview yung mga kaso na yung naka-exposed lang doon yung mga apparently hindi nagbayad. Tapos nakalabas yung data nila.
08:10.0
Ang point ko naman dito, kung magbayad man ng company. Kunwari lang PhilHealth, although hindi nagbayad ng PhilHealth. Ano naman assurance nung hinack na company?
08:19.0
Wala kang assurance. Pwede nga labas pa rin nila. And I think that's also part of pag-usapan din natin yung mga naging reaction din ng PhilHealth leading to the disclosure.
08:30.0
It's possible na nagbobluff yung hacker. Call yun ng company whether you entertain these hackers or not. Tsaka in a way, sa prinsipyo lang, kung ina-honor mo yung ransom, in a way, ina-encourage mo rin yung activity na yan kasi pinagkakita ka kayo.
08:47.0
Pero yung tradeoff yan, paano kung totoo? Kasi minsan threat lang yan. You might actually even receive mga spam emails, ako nakakatanggap din ako noon, na may mag-threaten sayo, nakita ko yung mga videos mo, mga photos mo, nagbabakasakali lang, padalan mo ako ng X number of dollars on whatever bitcoin to this address, kundi ilalabas ko lahat ng mga photos mo. Marami rin naloloko sa ganyan kahit hindi totoo.
09:17.0
Q1. Ano naman yung tinatawag na dark web? Kasi diba they started publishing data hacked from PhilHealth dito sa tinatawag na dark web. Ano naman to?
09:47.0
I remember reading, that's only maybe 10% at most or 20% ng totoong internet. The rest of the internet, malalim yung dark web. Yung dark web, internet din siya pero yung mga URL niya hindi mo ma-access normally. You need a special browser, kunyari may tinatawag silang Tor na browser na na-access niya yung mga special URLs.
10:17.0
Yung website lang din siya, hindi lang siya accessible via the normal means. Tapos kaya siya tinatawag na dark, bukod sa hindi mo siya makikita normally, marami rin mga karumal-dumal na nangyayari dyan. May mga nagbibenta ng drugs for example or may mga websites where mga hitmen. I don't want to excite people too much kasi you should not really be on the dark web to be honest.
10:48.0
Pinupost nila yung mga, I guess yung mga bounty nila. Oto, merong listahan. Actually, nakailang Philippine datasets na rin na-post dyan eh. If I'm not mistaken, meron pa ng NBI dataset, the AFP dataset, the Comeleek dataset. Pinupost dyan ng mga hackers for the highest bidder.
11:10.0
Ang common na natatransact dyan, usually anything related to finance. Mga credit card numbers, maguro na-download nila somewhere, bibenta nila. Mga $1 per credit card. Kasi hundreds of thousands, sometimes even millions of credit card numbers. Malamang karamihan, hindi gagana. Pero kung niyari, maka-bing with ka kahit isa o dalawang credit card, bawi man yung cost ng buong dataset na binili mo.
11:36.0
So yan, ganyan ang galawan sa dark web. It's not a place for anyone to go, pero it exists.
11:42.0
Maraming kademonyohan pala nangyari dyan sa dark web. Eto, puntahan natin, PhilHealth, gobyerno, papano man mahahack? Papano nahack as far as you know itong PhilHealth?
11:52.0
Okay, syempre may official investigation dapat mangyari dyan. But just to give you some scenarios, again, I'm not saying this is exactly how it happened. Number one, yung encryption ng mga websites ng government. Mahina ang government in general dyan.
12:11.0
Second, yung tinatawag nating mga passwords ng mga tao. Very common pa rin tayong, I mean in our case, may mga nakikita pa rin kami mga cases where yung username admin, yung password admin123. I mean, di ba? Kung ganyan ang password mo, paano magulat kung tatamaan ka?
12:31.0
Something a bit more complex. And ito, this is a common vector. Noong pandemic kasi, syempre hindi ka makapunta sa office. Maraming mga companies, yung ginawa nilang setup ng IT nila is you can access your office PC remotely.
12:50.0
Kunyari sa Windows may tinatawag na remote access. Actually, it's not very safe to do that kasi parang in-expose mo na yung, parang binuksan mo yung gate ng bahay mo, welcome, I'm open. Maraming mga companies yung gumawa na. I'm not saying PhilHealth did that pero that's a potential vulnerability na pwede makita lalo na kung Windows yung computer mo, nakabukas yung tinatawag nilang RDP port.
13:14.0
Makikita ka agad ng hacker yan. Huwag niyong gagawin yan kasi there are more, I guess, secure ways of doing that. Kunyari mga VPN where pwede ka mag-login sa network ng IT ninyo sa office remotely. Secure yun, encrypted yun. Pero yung bubuksan mo lang yung RDP port, kitang kita agad yan, and pasok na yan.
13:36.0
So i-combine mo. Nakabukas yung RDP port mo tapos yung password mo admin123. Again, I'm not saying that's what happened but that would be one of the first things I would look. And then another thing din yung...
13:48.0
Wait TukTuk before you proceed mo. Yung RDP port in layman's term, ano yan?
13:53.0
Okay, so merong function kasi sa Windows. Ano to feature, hindi to bug, yung tinatawag nilang remote desktop protocol na RDP where literally you can access another computer with a computer parang using yung port na yan. Parang ka nag-login sa second laptop mo using your one laptop.
14:12.0
Normally, the safer way to use that is within a network. Ninyari, sa bahay mo, meron kang computer sa ibang floor, accessing mo sa baba. For some reason, you wanna do that. Or usually, it's in the context of transferring files.
14:27.0
Para mabilis.
14:29.0
Mabilis ng network. Pero pwede mo rin gawin yan in the internet. Ninyari, nasa bahay yung computer mo, tapos nasa wherever, sa ibang lugar ka. Or baliktad, nasa office yung computer mo, sa bahay ka, nakabukas yung port na yan, maka-login ka.
14:43.0
Pinag-usapan din natin ito in another context, yung IP address. Pag alam mo yung IP address ng bahay mo or ng office mo, you can log in, haharapin mo nalang yung computer IP and then you can log in.
14:55.0
As I said, that's dangerous kasi anything na kahit hindi mo sinabi yung IP address mo, meron ginagawa yung mga hacker na common method where you can scan mga ports. Tawag nila port scanning.
15:10.0
And random lang yan. Magrarun lang sila ng program. Maghahanap lang yan ng mga random IP. Tapos pag may nakita sa lang, ops, merong bukas na port, yari ka. Kasi that means it's an attack waiting to happen.
15:24.0
It's a common practice na nakabukas yung database sa internet. For, I don't know, automation purposes, kunyari gusto mong i-access sya remotely or maybe may dalawang, what you call this, may dalawang systems na gusto mag-usap and they're located in different locations.
15:49.0
The challenge lang talaga dyan is kung may combination ka of nakabukas yung port tapos pangit yung password mo, super daling hulaan, you're really asking for trouble. That's another thing.
16:01.0
And then I was about to get to this. This is a more common problem. Yung mga unsecure emails. For example, may spam ka na receive, mga phishing, tawag dyan phishing. Yung mga simple na phishing attack, literally tatanungin ko lang.
16:19.0
Kaya makatanggap ka ng email, kunyari sakin, from Doc Ligot, Christian Esguerra, oh hey Christian, padala mo naman sa akin yung password at username ko kasi nakalimutan ko. Actually, it didn't come from me. Pwede mo kasing ispoof yung mga email na yan. Nakala mo galing sakin, but actually iba yung email address. That's the simple version.
16:40.0
This is a more complicated version. Again, this is another thing I would immediately check. Baka may attachment, kunyari PDF file, whatever, pero hindi talaga siya PDF file. Kunyari lang, pag clinic mo siya, actually it's a program and that creates a vulnerability na sa network mo. Can be many things. Pwedeng huguti niya lahat ng credentials ng computer mo, papadala niya sa hacker kung nakaconnect yung computer mo sa internet.
17:06.0
Probably, this is probably connected. It can open yung port na yan. So baka originally wala pala siya, nakasara pala siya, pero may clinic kang attachment, literally bubuksan niya yan at malalaman na agad ng hacker, oh may nakabukas ng ating booby trap, puntahan natin ito. Very common, very common attack, lalo na kung kunyari, it happens in the normal course of doing business.
17:33.0
So if there's a person na nakakatanggap ng email sa taong to, and then suddenly may lumusot na email na kunyari galing sa taong na yan, you would not think twice pagbukas ng attachment, parang walang nangyari, pero yun pala na buksan niya.
18:17.0
Usually, naboblock yun ang antivirus kasi the programs are trained to spot yung mga ganyan. Pero if it's an expired antivirus, it's possible na may makakalusot yan kasi ang antivirus kasi ano ba talaga yung nag-expire dyan?
18:32.0
May mag-expire dyan yung listahan of known malware and viruses. Kung hindi updated yun, may bagong version na lumusot, that's where it could have started.
19:03.0
And again, hindi pa fully known kung at least in my end, I haven't seen the actual data file kasi alaki eh. I think at least 800GB ata.
19:12.0
Nag-invictima ng red tape yung ano.
19:18.0
Sorry I'm a bit angry about this kasi data natin yan. Lahat tayo mandatory contribution sa PhilHealth and you trust na we can get more into the details later. Yung number mo nandoon, email mo nandoon. Tapos makakompromise yun.
19:37.0
So as far as ano, ano ba yung mga na-compromise sa data natin?
19:40.0
Okay may conflicting reports. Gumitin muna natin yung third party reports kasi yung unang turing, wala. Kasi may common phrase na ginagamit si PhilHealth, just paraphrasing their statement.
19:56.0
The member database is intact or was not infected. And then towards the later part, lalo na nung lumabas na yung link, may mga kasi based on what I'm reading, the ICT is investigating it already.
20:11.0
Meron ng lumabas ng employee data. And then later on, the most recent news, some member data and employee data. So palaki ng palaki. So di ba natin alam fully baka by the time matapos yung investigation, baka there's more to it than that.
20:33.0
Sorry Dokka. Ang dating sa akin yan, kung nagbabago yung lumalabas na information from PhilHealth, they don't know.
20:41.0
Or nag-evolve pa. I mean let's be fair. Kasi to be honest, di naman madaling i-handle yung data na ganyang kalaki.
20:49.0
Hindi nga. Pero kung sasabihin mo originally na wala naman na-expose na member database, nagsalita ka na tapos. Apparently, paano meron pala.
21:01.0
I'm going to go on the record here. Kasi there was a press conference recently, right before the deadline.
21:09.0
And I don't know bakit ganito yung patakbo. Basically, yung presidente ng PhilHealth mismo.
21:16.0
Tila bang hinamon pa yung mga hacker? Kasi tinanong sila, di ba kinababahala, ganyan. Sabi na, tingnan na lang natin. Malamang nagbabluff lang yan.
21:26.0
And ang sabi pa ng spokesperson or the president, kung merong lalabas dyan, fabricated yung data na yan. Di ba may mga ganong assumption.
21:35.0
So for me, maybe it's for PR or whatever, pero huwag ka muna magsalita until you see it. In the first place, meron ng clear and present risk.
21:46.0
You have to assume the worst case scenario palagi.
21:48.0
And for you, at saka yung mga hacker, hindi mo hinahamon yung mga ganyan tao. In the first place, nagawa na nga nilang mapasok yung system mo.
21:56.0
And now evidently, true pala siya. Then i-assume mo na bluff. Unless alam mo talaga na hindi.
22:00.0
Would've been better to say, actually, nacheck na namin. Di naman totoo. Pero it seemed very speculative at that time.
22:07.0
I think that was around 1 o'clock, right before. Kasi 3.20 lumabas yung airbox. 1 o'clock PM.
22:14.0
And then 3 o'clock lumabas. Ngayon, unti-unti na nag-trickle out yung mga reports.
22:20.0
And then, I've also been in touch with, may mga cyber investigators na rin tumingin.
22:25.0
Siyempre, mga people who would not be named. Kasi they're doing it out of para sa bayan.
22:32.0
Yung patikim, nagbigay ng patikim yung mga hackers before the deadline.
22:39.0
And it's just a list of files. The list was so big. Almost 50 or 60 MB. Yung listahan pa lang na yun.
22:47.0
Hindi pa yung actual files. And may mga mukhang sensitive talaga na data na nandun, according to that list.
22:53.0
Like what?
22:55.0
Mayroong list of senior citizens. May ganoon. May lumabas na ganoon.
22:59.0
Mayroong list of... Well, of course, may employee list.
23:05.0
Kaya hanapin mo lang yung mga keywords. Siyempre, until you see the actual file, you don't know what's there.
23:09.0
Pero if you take that list at face value, there might have been at least a few member data that could have been leaked.
23:16.0
Kaya, I mean, I'm assuming lang na the ICT and related parties using that information is going through the data.
23:24.0
And for me, ang immediate protocol dapat dyan, if it were me lang, kontakin nyo na agad kung sino man yung nandun.
23:32.0
Hindi mo na-compromise yung information mo and take the following precautions.
23:36.0
Actually, kahit ako, not even knowing what's in the database, nag-post na ako.
23:42.0
Guys, kung yung number mo in PhilHealth, ginagamit nyo for any other thing, palitan nyo na agad.
23:49.0
Just don't even entertain the possibility na ma-compromise yung identity mo.
23:54.0
Kasi nowadays, without us asking for it, naging personal identifier na natin yung cellphone natin.
24:02.0
Karamihan naman ng tao, isa lang naman yung phone na gamitin.
24:04.0
Ako, F3. Kasi talagang praning ako.
24:07.0
Pero yung iba, isa yung phone mo, yun din yung ginagamit mo sa Facebook, yun yung ginagamit mo sa whatever, Lazada, Angkas, probably, or online banking.
24:15.0
The moment malaman nyan ng isang hacker, mayroong tinatawag na attack na SIM swap.
24:22.0
Kunyari ikaw, nalaman ko yung number mo, Christian Esguerra.
24:25.0
Tapos meron akong copy ng mga ID mo which allegedly the Medusa people have based on that dataset.
24:32.0
Naglabas din kasi sila ng video.
24:34.0
Literal passport photos nandun.
24:36.0
So I have your ID, Christian. I have your number. Punta ako sa telco.
24:40.0
Hi, this is Christian Esguerra. I lost my SIM. Can I request for a replacement?
24:45.0
And again, maybe the pressure is now on the telcos.
24:48.0
How are they verifying the identity?
24:50.0
Usually, titignan lang nila, please provide an ID.
24:53.0
If you're not the person, authorization letter.
24:56.0
And then within 24 hours, you have your SIM.
24:58.0
Pag nakuha ko yung SIM mo, next step, email mo na.
25:02.0
Iri-reset ko na yung Gmail mo or whatever email you have.
25:05.0
Dali na mahuga, ahulaan yung email mo.
25:08.0
Christian.esguerra or whatever.
25:10.0
Various combinations. May mga normal combo na yan.
25:14.0
The moment may ma-reset akong email mo, wala na. That's it.
25:18.0
Probably, it's the same email you use for Facebook.
25:20.0
It's the same email you use for Lazada and everything else.
25:24.0
Wala na. Kuha ko na yung identity mo.
25:26.0
Kaya for me, yun yung immediate chain reaction.
25:29.0
Oh my gosh. Sabi ko, nandun yung mga cellphone numbers.
25:32.0
We have to tell people.
25:34.0
Hassle siya. Palitan yun na agad.
25:36.0
Pinakahassle yun yung bangko.
25:38.0
If your banks are like my banks, you have to go in person
25:42.0
to change them sa branch of account.
25:46.0
Hirap nun. Napakahassle.
25:48.0
Ano ba yun sa'yo?
25:50.0
Karamihan are the local banks.
25:52.0
UPI, BDO, Metrobank.
25:54.0
Yan ang normal protocol.
25:55.0
Basically, dun sa branch.
25:57.0
Eh kung napalitan na yung SIM card mo without your knowledge,
26:02.0
yung OTP mo pupunta na dun sa hacker.
26:05.0
I mean, think about it.
26:06.0
Kasi yun yung way mo of protecting your identity.
26:10.0
Yung multi-factor or two-factor authentication.
26:14.0
OTP, PIN.
26:15.0
Pupunta yan dapat sa phone mo.
26:17.0
Eh kung hindi mo na-control yung SIM mo kasi napalitan na siya.
26:21.0
Imagine mo, three steps yan.
26:23.0
You have to go to the telco and tell them,
26:25.0
Boy, yung nagpapalit ng SIM, hindi ako yun.
26:27.0
Oh, please provide verification. Ganyan, ganyan.
26:30.0
Tagal. May affidavit of loss pa yang nalalaman and all that.
26:33.0
You're really wide open if you entertain the possibility.
26:37.0
So ang dapat gawin,
26:38.0
Andami kasi member ng PhilHealth, diba?
26:41.0
So hindi ko nakakamali, more than 90% ng coverage yan, diba?
26:44.0
Yung pinagmamalaki yan.
26:45.0
So ang advice mo, just to be cautious.
26:50.0
On the safe side.
26:51.0
Huwag pa rin ng number.
26:53.0
If you think, oh nga, if you think yung number mo sa PhilHealth,
26:57.0
kasi may application form ng PhilHealth, katapat-katapat na data yan.
27:01.0
You fill that up, diba?
27:02.0
Baka nga hindi nyo naaalala kung ano yung pinilapan ninyo
27:05.0
kasi probably you applied for it when you started working, diba?
27:09.0
If it's the same number you're using for any other identity,
27:13.0
don't even think twice.
27:15.0
I-detach mo na.
27:16.0
At the very least, detach your number from your emails.
27:19.0
There was a big hack years ago.
27:22.0
Yung Yahoo hack.
27:25.0
Nangyari ito sa Facebook.
27:27.0
Parang nakakompromise yung database ng Yahoo.
27:30.0
And ang ginawa ng Yahoo, to be safe,
27:33.0
dinelete niya lahat ng compromised emails.
27:36.0
Nakakanala ko yan.
27:37.0
Dinelete nila, to be safe.
27:39.0
However, hindi naman na-delete sa Facebook yung mga email na yun.
27:44.0
Kanyari, ChristianEsguerraAtYahoo.com,
27:46.0
dinelete ni Yahoo yung email mo.
27:48.0
So your email does not exist.
27:50.0
Pero nakakalimutan ng mga tao na,
27:52.0
hey, yun yung email na ginamit ko pang bukas ng Facebook.
27:55.0
So that doesn't stop me, for example,
27:58.0
from creating a brand new ChristianEsguerraAtYahoo.com,
28:02.0
exactly the same email you had.
28:04.0
Since wala na siya sa system ng Yahoo,
28:06.0
gawa na akong bago.
28:07.0
And yun punta ako sa Facebook,
28:08.0
re-reset ko na yung password ko,
28:10.0
pupunta na siya dun sa Yahoo na yun.
28:11.0
And then that's it, I can take over.
28:12.0
Ang dami mga taong nabiktima dyan.
28:14.0
Identity theft, no?
28:16.0
That's just with the email.
28:17.0
Ngayon, nauso na yun two-factor or multi-factor authentication.
28:21.0
Di lang email, kailangan may telpon number.
28:23.0
It makes everyone a little safer.
28:26.0
Pero paano kung nakompromise yung number mo?
28:29.0
Ah, yun, hassle yun.
28:30.0
Pagpalitan mo ngayon lahat ng...
28:33.0
Nakakahilo eh, kaya ang dami nag-galit.
28:35.0
It's not political, it's just incompetence.
28:39.0
Kasi lahat tayo tinamaan.
28:41.0
Doesn't matter kung BBS ka, or BBM ka,
28:43.0
or kakamping ka, lahat tayo tinamaan.
28:46.0
So I feel na hindi dapat natin politika tong issue na to.
28:50.0
Talagang we have to hold people to account.
28:53.0
And protect ourselves, yung bottom line.
28:55.0
Defense muna tayo, defense.
28:57.0
Speaking of accountability eh,
28:58.0
nang gusto kong puntahan.
28:59.0
Hindi naman pwedeng ganon-ganon lang yan.
29:01.0
So ang criminal gagawa ng criminal.
29:03.0
Yan ang trabaho nila eh.
29:04.0
Pero yung PhilHealth bilang gobyerno,
29:07.0
dahil kinuha nila yung data natin, private information,
29:10.0
dapat protectahan nila.
29:12.0
So ano yung mga dapat gawin dito?
29:14.0
Dapat may managot, di ba?
29:32.0
So if your data was compromised...
29:35.0
Actually, ito yung magandang tanong eh.
29:37.0
Ano bang kaso yung ipa-file mo to begin with?
29:40.0
Kasi may criminal case, may civil case.
29:44.0
Number one, you have to prove na may breach.
29:46.0
Somehow, malalaman mo mo lang naman yun.
29:49.0
Pag biglang meron ang kumukontak sa'yo,
29:50.0
or somebody made an attempt.
29:52.0
So that's a breach.
29:53.0
Until then, or na-verify mo na nandun ka sa dataset.
29:57.0
Kaya nga, segue lang tayo saglit.
29:59.0
I feel that another thing that needs to happen
30:02.0
is kung sino man yung nag-i-investigate ang data na yan,
30:04.0
kailangan meron tayong facility to validate
30:07.0
if your name is on that list.
30:09.0
Merong website na haveibeenpwned.com
30:13.0
It's maintained by a private individual.
30:15.0
Ginagawa lang niyang public service
30:17.0
na ina-upload niya dun yung mga passwords
30:21.0
tsa mga names.
30:22.0
Naka-encrypt yun.
30:23.0
So you won't be able to get it.
30:25.0
Pero you can check,
30:26.0
is my name Dominic Ligot in that list?
30:28.0
Or is my password, yung mismo password mo,
30:31.0
mavalidate mo kung na-breach siya somewhere.
30:33.0
So that should certainly happen for this.
30:36.0
Kailangan may way tayo validating.
30:38.0
Di ba dapat gobyerno gumawa nun?
30:40.0
Correct.
30:41.0
They're the most equipped.
30:43.0
And they're the ones who can do it legally.
30:46.0
Remember, a private citizen should not have access to that data
30:49.0
kahit na naka-open siya.
30:51.0
Nothing's stopping anyone.
30:53.0
So, dapat may helpline na paano kung na-compromise ako.
30:57.0
Anong mangyayari?
30:58.0
So if, let's say, proven na may breach or worse,
31:01.0
hopefully hindi nangyari,
31:03.0
meron nang nangyaring financial loss,
31:05.0
may gumamit ng credit card mo or whatever,
31:08.0
according to the NPC, you can sue.
31:10.0
Kasi under the data privacy app,
31:13.0
yung data controller, whoever has possession of your data,
31:17.0
is liable for breaches.
31:19.0
Who's the data controller here?
31:20.0
Field Health is the data controller.
31:22.0
Yun lang. I mean, just keep it simple.
31:25.0
Pero sobrang hassle na yan. Sobrang hassle yan.
31:28.0
Tsaka mag-astos. Mag-ahir ka ng lawyer.
31:30.0
Parang paramihan sa atin, public attorney ang habol mo.
31:34.0
Haba ng pila doon.
31:35.0
So, nakapanghina kasi you feel so helpless.
31:40.0
Ito may tanong sa'yo, Dok.
31:43.0
Basically, nasagot mo na ito.
31:45.0
How do you know if your account is compromised?
31:47.0
So, dapat may maglabas.
31:49.0
Basically, dapat gobyerno.
31:52.0
Yung inquiry, whatever you call it,
31:56.0
validation portal, siguro.
31:59.0
Dapat labas agad yun.
32:00.0
Para macheck mo agad.
32:01.0
Kasi malay mo, wala ka pala doon.
32:03.0
At least, you can feel a little safe.
32:05.0
Pero, yun na nga.
32:07.0
If you don't want to take second chances,
32:09.0
palitan mo na agad.
32:11.0
And then, secondly, if you're there,
32:13.0
what do you do?
32:14.0
Kailangan naka-outline na yung steps.
32:16.0
This is how you protect yourself.
32:17.0
Parang right na. Wala kang mahanap na gano'n.
32:20.0
May nagpasalamat nga sa akin the other day,
32:22.0
na, muna na lang, Dok,
32:24.0
nag-post ka dito sa social media.
32:25.0
Otherwise, di ko alam yung gagawin ko.
32:27.0
I mean, to be honest, most of us don't really...
32:29.0
Yung nga, eh.
32:30.0
Actually, nalama ko extent ito
32:32.0
because of your posts sa Twitter.
32:34.0
Ayokong gamitin yung ex.
32:35.0
Hindi ako makarelate doon sa
32:36.0
ex social media platform.
32:38.0
Ibang episode yun,
32:40.0
pag-usapan natin yung Twitter ngayon.
32:42.0
Kung hindi ka nag-post niya,
32:43.0
hindi ko malaintindihan yung extent
32:45.0
nitong hacking sa PhilHealth.
32:47.0
And you were actually doing
32:48.0
a lot of public service with that.
32:50.0
E, sa gobyerno wala pang gano'n
32:51.0
initiative for us to know
32:53.0
yung mga PhilHealth members
32:55.0
kung talaga na-expose ba yung data natin?
32:57.0
I feel yung reaction time lang.
32:59.0
I think eventually,
33:01.0
malamang lalabas din.
33:02.0
Pero, ah, tumakdunin ka ba yun?
33:04.0
Diyan na yung...
33:05.0
I mean, in the first place,
33:07.0
again, I'm just talking out of my, ano,
33:09.0
parang ano, my own sentiment.
33:11.0
Bakit umabot doon?
33:13.0
At bakit parang hindi seneryoso?
33:16.0
Lumabas pa to,
33:17.0
Second wind.
33:18.0
Si...
33:19.0
Si...
33:20.0
Sino ba yung taga Manila Bulitin?
33:22.0
Si...
33:23.0
Si Art Samaniego posted it
33:25.0
4 days before the deadline.
33:26.0
Ito na. May countdown pa nga siyang pinakita.
33:29.0
The website has a countdown.
33:31.0
Parang way of raising the alarm bell.
33:34.0
Pero I feel na
33:35.0
either it was not taken seriously
33:37.0
or baka people thought
33:39.0
wala naman ng unyang laman.
33:40.0
Alala nga yan.
33:41.0
May tanong sa'yo sa Pinky.
33:43.0
Is it safe to do an online check
33:45.0
of one's PhilHealth account at this time?
33:47.0
Ah, yes.
33:48.0
Automatic dapat yan.
33:49.0
Unfortunately, again,
33:51.0
ba... bad day lang yun,
33:53.0
you might not even be able to access it right now.
33:55.0
Kasi ang ginawa ng PhilHealth,
33:56.0
hindi naman din nila yung system nila
33:58.0
in reaction to the...
34:00.0
to the hack.
34:01.0
Pipila kayo ngayon
34:03.0
sa PhilHealth office nearest you to check.
34:06.0
Or at the very least,
34:07.0
i-validate nyo ano ba yung data ninyo
34:09.0
na nasa PhilHealth.
34:10.0
That should be top of mind.
34:11.0
Actually, it applies to any government service.
34:14.0
Kasi nowadays,
34:15.0
sinihingi na yung ID,
34:17.0
telephone number, email,
34:18.0
in practically every application you make,
34:21.0
whether it's PhilHealth,
34:23.0
SSS, Pag-IB,
34:25.0
driver's license.
34:27.0
And then, di ba,
34:29.0
sa DICT, there's a move to put all of that
34:31.0
into one super app.
34:33.0
Again, I'm not politicizing it,
34:35.0
pero the moment everything is in one database
34:37.0
at na-compromise yung database na yan,
34:39.0
wala na. That's it.
34:41.0
And then,
34:42.0
kung mag-uusapan yung national ID,
34:43.0
that's another cat of worms, no?
34:45.0
Pero ganoon.
34:46.0
For convenience kasi yan,
34:48.0
you're putting everything in one place.
34:50.0
Pero ang trade-off mo sa convenience
34:52.0
is security.
34:54.0
Kasi na moment makompromise yung isa,
34:56.0
wala, tatamaan lahat.
34:57.0
Ayun nga eh.
34:58.0
Masagi, marami tayong pag-uusapan in the future, no?
35:00.0
Marami tayong dapat himayin.
35:02.0
Pero dito sa pagtatapos,
35:03.0
ano yung mga dapat gawin ng PhilHealth?
35:05.0
Or ibang mga government agencies,
35:08.0
mga kumpanya,
35:09.0
to be able to
35:10.0
be more resistant naman sa mga ganitong ransomware attacks
35:13.0
in the future?
35:14.0
Okay, sige.
35:15.0
Three points.
35:16.0
Number one,
35:18.0
defense.
35:19.0
Immediate...
35:21.0
Well, okay.
35:22.0
There was another article that came out,
35:24.0
yung nakasama rin natin sa show si Carlos Nazareno.
35:28.0
Ang riniklama naman niya is,
35:30.0
bakit Gmail yung ginagamit ng government?
35:34.0
Maramang kwento yan, no?
35:36.0
But ano ba yung problema kung Gmail?
35:39.0
Kasi kung Gmail naman ng legit PhilHealth person yun,
35:42.0
okay lang sana.
35:43.0
Ang problema, since it's not an official email,
35:45.0
ang daling gumawa ng fake na...
35:49.0
Kunyari, philhealth2023 at gmail.com.
35:52.0
Something like that.
35:53.0
Igawa kaya tayo ng philhealth2023-1 at gmail.com.
35:58.0
Ilabas mo yun.
35:59.0
Would a citizen be able to know the difference?
36:02.0
O di yun na, di ba?
36:03.0
So, there's a use for official emails.
36:06.0
That's number one.
36:07.0
Number two,
36:08.0
I just have to say it,
36:10.0
even up to now,
36:12.0
yung security ng mga government sites natin,
36:16.0
talagang...
36:17.0
I'm not just talking about PhilHealth.
36:20.0
Ang dami eh.
36:21.0
Local government, national government.
36:23.0
Number one, di nga nare-renew yung encryption yan from time to time.
36:26.0
Nage-expire yan.
36:27.0
Dapat automatic may hygiene yan.
36:29.0
And then, if yung news about that expired antivirus na report na,
36:34.0
I mean, that's basic.
36:36.0
Bakit dinadaan pa sa...
36:38.0
I mean, I don't know.
36:39.0
Kung ano man yung reason, procurement or not,
36:41.0
kasama sa hygiene yan, dapat hindi yan nagla-lapse.
36:44.0
Dapat hindi yan nage-expire.
36:46.0
Alright? Sige.
36:48.0
Yung discipline ng mga tao sa loob,
36:50.0
again, I can't speak for anyone there,
36:53.0
pero there's a reason why nagkaroon ng vulnerability dyan.
36:56.0
Di ba?
36:57.0
That means mayroong nagkamali dyan.
36:58.0
Whether it was that potential yung port naka-open
37:01.0
or may nag-click ng attachment
37:03.0
tapos wala ka pang antivirus.
37:05.0
So that means...
37:06.0
Actually, I don't know if that's discipline
37:08.0
and education din.
37:10.0
Malamang education.
37:11.0
We need to do a media literacy,
37:14.0
cyber security literacy.
37:16.0
Si National Privacy Commission,
37:18.0
they do that eh, often eh.
37:19.0
The ICT also does that.
37:21.0
I guess kulang lang talaga
37:23.0
kasi kung alam sana ng mga tao yan.
37:26.0
I mean, little things like how do you know
37:28.0
kung mukhang pini-phish yung account mo?
37:30.0
Di ba? Mga ganyan.
37:31.0
Minsan hindi second nature.
37:34.0
Every time na lang may sumasabog
37:36.0
kung ano man leaks,
37:37.0
sakalang tayo nag-aalala
37:38.0
pero after that, wala.
37:39.0
It's gonna die down.
37:40.0
So yun yung top three.
37:41.0
And then, ah, maybe close fourth.
37:44.0
What do you do if something happens?
37:47.0
I don't see it posted anywhere
37:49.0
or kailangan ko pang hanapin.
37:51.0
Kailangan second nature.
37:52.0
Parang yung hotline ng bumbero,
37:54.0
di ba? Kung may maamoy kang sunog,
37:55.0
alam mo na agad,
37:56.0
fire station, call agad.
37:57.0
Dapat may ganyan din tayong attitude sa cyber.
38:00.0
You know who the people you can call,
38:02.0
na identity theft ka.
38:04.0
Kasi ngayon, I bet you,
38:05.0
talangin mo mga viewers natin,
38:07.0
anong gagawin mo kung na-compromise yung account mo?
38:09.0
Ayawin ko, NBI ba yan? PNP ba yan?
38:11.0
NPC ba yan?
38:12.0
And ngayon, lahat yung...
38:13.0
Ako, ako yung may message ko,
38:15.0
si Doc Rigot.
38:16.0
Oo, ipo-post ko na lang.
38:18.0
Pero I mean...
38:19.0
Seryoso?
38:20.0
I do my best.
38:21.0
Pero syempre,
38:22.0
dapat may official tayong...
38:23.0
And I know a number of people in government
38:25.0
that they're trying their best.
38:27.0
But I feel like we just need to do better.
38:29.0
Ah, kasi...
38:30.0
Eto, hindi naman akong nagsabi nito.
38:32.0
We're the number two.
38:33.0
Buti nga akong number two eh.
38:35.0
Target for cyber attacks.
38:38.0
According to a security firm.
38:40.0
Bakit tayo tina-target?
38:42.0
Kasi ang dali nating i-target, no?
38:45.0
Maraming vulnerability.
38:46.0
At saka hindi biro yung mga $300,000 na bounty na yan.
38:50.0
Hindi na maliit na pera yan.
38:51.0
So that means,
38:52.0
kung ikaw si Medusa,
38:54.0
alam mo na pwede mong makuha yung pera na yan.
38:57.0
Unfortunately, hindi kinol...
38:59.0
I think, hindi naman kinol yung kanilang ransom.
39:03.0
Pero as a result,
39:04.0
kumakalat na ngayon yung data na yan.
39:06.0
Mali ba natin kung sino yung na-download niya.
39:08.0
Yan. I mean, those are my sentiments.
39:11.0
Ay nako, grabe.
39:12.0
Nakakaanak.
39:13.0
Mabigat sa pakaramdam na itong interview natin, ah.
39:17.0
Nakakainis lang.
39:18.0
Kasi parang siyang...
39:20.0
Okay sana kung talagang may nanadja
39:23.0
and despite your best effort,
39:25.0
somehow, na-penetrate lahat ng defense.
39:28.0
Ito yung kaso na ito,
39:29.0
parang negligence ang dating eh.
39:32.0
It is negligence actually.
39:34.0
And ito pa yung malala.
39:37.0
If you can't trust the government,
39:39.0
who can you trust?
39:40.0
Yan yung problema diba?
39:41.0
Kaya ka nga,
39:42.0
willingly nagbibigyan ng data mo sa field health
39:45.0
and all these other entities.
39:46.0
Kasi alam mo,
39:47.0
sana na pinaprotectahan nila.
39:48.0
Kasi public service yan.
39:50.0
Paano na ngayon?
39:51.0
You know?
39:52.0
Nababasa ko sa comments nga eh.
39:53.0
Parang yung mga iba,
39:54.0
kayo na mag-contribute sa field health.
39:56.0
Eh, benefit mo yan eh.
39:57.0
Diba?
39:58.0
Sa employment mo,
39:59.0
kasama yan sa benefits mo eh.
40:00.0
Yung problema,
40:01.0
naging liability pa yung benefit mo.
40:03.0
Again, it's...
40:04.0
Yeah, I'm sorry to be so negative about it.
40:06.0
Kasi kahit ako,
40:07.0
nag-alala ako eh.
40:08.0
Tapos yung mga senior citizen,
40:09.0
assuming they were exposed,
40:12.0
hindi naman mga tech savvy yung mga yan.
40:14.0
Diba?
40:15.0
Maka iba pa,
40:16.0
hindi na makita-kita yung...
40:17.0
Hindi na naman mabasa yung apps nila.
40:19.0
Kawawa naman si lolot-lola.
40:21.0
Tatamaan sila nyo.
40:23.0
But maraming maraming salamat sa iyo Doc Ligot
40:25.0
for explaining all these things patiently sa atin.
40:28.0
Maraming maraming salamat sa iyo.
40:30.0
And thank you.
40:31.0
I think I speak on behalf of our viewers
40:33.0
in expressing our gratitude sa iyo.
40:37.0
Because of the help,
40:38.0
the assistance that you've been extending
40:40.0
to the public.
40:41.0
Di mo naman siya trabaho,
40:43.0
pero kinagawa mo.
40:44.0
Maraming maraming salamat sa iyo
40:45.0
for joining us tonight.
40:46.0
Thank you, thank you.
40:47.0
Yeah, last request lang.
40:48.0
Parang for now,
40:49.0
let's not politicize it.
40:51.0
Let's play good defense.
40:53.0
And then later sana may managot.
40:55.0
Yan lang yung hope ko.
40:57.0
Sana nga.
40:58.0
Okay, si Mr. Dominic Ligot.
41:00.0
Nakausap po natin,
41:01.0
cyber security expert.
41:02.0
Thank you.
41:03.0
Magandang gabi sa iyo Doc.
41:04.0
Good evening.
41:07.0
Ayan, si Doc Ligot.
41:10.0
Nakausap natin ngayong gabi.
41:12.0
Bigat.
41:14.0
Pinag-usapan natin.
41:15.0
Sana may managot.
41:17.0
Pero sana maayos na tong problema nito
41:19.0
kung maayos pa.
41:21.0
Okay.
41:22.0
Nga pala.
41:23.0
Pasensya na kayo dun sa...
41:26.0
Di ba nag-restock tayo ng merch natin?
41:28.0
Yung mga shirts and mugs?
41:29.0
Gulot ako ah.
41:30.0
Ito walang joke ah.
41:31.0
Di ba in-announce natin kailangan makahapon?
41:34.0
Pasensya na po.
41:35.0
Na sold out in 2 hours.
41:37.0
Pasensya na po.
41:39.0
Dun sa mga hindi nakahabol.
41:40.0
Pero sinisikap po natin
41:44.0
mag-restock uli.
41:45.0
Ma-replenish yung supplies.
41:47.0
Very very soon.
41:48.0
Maraming maraming salamat po sa inyo.
41:50.0
Pero yun po yung nangyari.
41:51.0
Ayan, dun po sa mga naka-access, naka-bili.
41:55.0
Well...
41:57.0
Kung magpo-post po kayo about it, just tag me.
42:00.0
Para ma-share din po natin sa ating mga social media accounts.
42:03.0
Isa po sa mga...
42:05.0
Umabot si...
42:07.0
Attorney Romulo Macalintal.
42:09.0
Yung sikat na election lawyer.
42:12.0
So...
42:14.0
Meron siyang shirts and mugs.
42:15.0
Maraming maraming salamat po.
42:17.0
Tsaka sa inyo po lahat.
42:19.0
Tapos shout out po.
42:20.0
Ito kasi may nag-message po sa akin.
42:21.0
Matagal lang po natin tong viewer.
42:23.0
Ayaw niyang basahin ko yung buong message niya.
42:25.0
Kasi...
42:27.0
Nakakahiya daw.
42:31.0
Pero natatempo akong basahin eh.
42:33.0
O sige, hindi ko babasahin ng buo.
42:35.0
Siya po si Angeles from San Jose, California.
42:41.0
Gusto ko tayo shout out eh.
42:43.0
Maraming salamat po for always watching.
42:45.0
For supporting our program.
42:47.0
Our advocacies.
42:48.0
So meron siyang pinapa-shout out, pinapabate.
42:51.0
Ang pangalan si Rico Sico.
42:53.0
Rico, maraming maraming salamat sa'yo.
42:55.0
Shout out.
42:56.0
Sabi ni Angeles...
43:00.0
Ayun.
43:02.0
Magkaibigan kayo.
43:03.0
At matagal lang gustong magpa-shout out.
43:05.0
Masugid mo rin siyang tagapakinig.
43:07.0
Kung hindi man siya nakakapanood ng live after work.
43:10.0
Hala, hindi pwedeng ma-miss ang program mo.
43:12.0
Wow, grabe.
43:13.0
Rico, maraming maraming salamat sa'yo.
43:15.0
At siya kay Angles.
43:17.0
Thank you, thank you very much po sa inyong lahat.
43:19.0
And then kay Miss Divine Villafuerte,
43:22.0
pa-shout out sa kaibigan ko na si Noni Llamido,
43:26.0
na nanonood ng Facts Verse.
43:28.0
Ayan.
43:30.0
Si Divine daw yung nag-introduce itong Facts Verse
43:33.0
kay Miss Noni.
43:35.0
So maraming maraming salamat sa inyo.
43:38.0
Ayun.
43:41.0
Sige, maraming salamat sa inyo.
43:43.0
Pagkita kita po tayo bukas.
43:45.0
So meron po tayo pag-uusapan na issue tomorrow.
43:48.0
Inga po, yung latest facts statics video na kung gusto mag-contribute.
43:52.0
Ano ba yung sa tingin nyo dapat gawin yan sa confidential funds na yan?
43:56.0
Dapat ba ilimit yung mga government agencies na dapat bibigyan yan?
44:02.0
Kung ano po yung sentimiento nyo.
44:04.0
Padala nyo po yung video nyo.
44:06.0
I-send nyo po sa aking Facebook account.
44:08.0
Up to 1 minute po yung video.
44:09.0
And then again, dapat meron tayong mga standards na sinusunod.
44:14.0
Bawal magmura, maging personal, walang character assassination.
44:18.0
Just stick to the issues. Okay?
44:20.0
So maraming maraming salamat po sa inyo lahat.
44:22.0
Ako po si Christian Esguerra.
44:24.0
And again, sa Team Replay, maraming salamat.
44:26.0
Alam ko pinapanood at pinapakinggan nyo itong ating programa on a delayed basis.
44:31.0
Maraming maraming salamat din po sa inyo.
44:33.0
Magandang gabi po.
44:39.0
Magandang gabi po.