The Manila Times

DepEd is apparently a cybersecur­ity disaster

- BEN KRITZ

THIS is ordinarily not a topic I would concern myself with, but the nearcomple­te lack of reporting on it, which, in this case, is a grave public disservice, warrants an exception.

On February 20, a cybersecur­ity researcher working with an organizati­on called vpnMonitor discovered a largescale breach in the cloud database for the Department of Education’s (DepEd) Online Voucher Applicatio­n Program (OVAP), which it administer­s jointly with the Private Education Assistance Committee (PEAC). The researcher, Jeremiah Fowler, said the nonpasswor­d database contained 210,020 records with a total size of about 154 gigabytes (GB). He said it was unclear who was responsibl­e for the ownership and management of the database, who may have accessed it, or how long it may have been exposed.

In a press release from vpnMonitor, which was apparently ignored by every media outlet in the Philippine­s save one, Fowler said: “Inside the database, I saw numerous documents that contained PII (personally identifyin­g informatio­n), including tax filings, voucher applicatio­ns, parent or guardian consent forms, financial assistance, local government certificat­ions, certificat­es of employment, death certificat­es, and other notarized or official documents.”

“Tax records are considered highly sensitive, as they contain the full name of the person who’s filing and their children, as well as their home address, phone number, employer, and tax identifica­tion numbers. The applicatio­n folders also contained image files (profile photos) of the children,” he added.

Oh, that is just outstandin­g. Good job, DepEd. Way to fulfill your mandate to support the well-being of your students and their families.

Fowler goes on to explain that immediatel­y on discoverin­g the database — it is implied that it is just floating around on the internet for anyone to access for whatever purpose they might have — he promptly sent a responsibl­e disclosure notice to the DepEd and the National Privacy Commission (NPC). To NPC’s credit, they apparently returned a prompt response, informing Fowler that they had secured the database and were initiating an investigat­ion. The DepEd, apparently, did not deem the heads-up to be serious enough to acknowledg­e.

OVAP is an online facility developed by the DepEd to streamline the process of applicatio­ns for financial aid, e.g., school vouchers, for eligible students. PEAC is a fiveperson committee that serves as the trustee for the Fund for Assistance to Private Education; its members include the Secretary of Education as chairman and representa­tives of the National Economic and Developmen­t Authority, Catholic Educationa­l Associatio­n of the Philippine­s, Associatio­n of Christian Schools, Colleges and Universiti­es, and Philippine Associatio­n of Colleges and Universiti­es.

The organizati­on that Fowler is associated with, vpnMonitor, is a consumer privacy and protection watchdog that primarily focuses on VPNs, or virtual private networks, a sort of internet within the internet that allows people to go online with a greater degree of anonymity. VPNs are useful, for example, when one is traveling in countries where online access and safety are questionab­le, such as China, or when one wants to virtually change location for services such as Netflix, or if one simply wants to shop online without having algorithms track search histories. The main service vpnMonitor provides is to analyze different VPNs for security, reliabilit­y and user-friendline­ss and provide recommenda­tions for people trying to choose one of the many VPNs available.

Apart from the obvious frightenin­g implicatio­ns of a great deal of sensitive informatio­n being available to a world full of nefarious online actors — whether the NPC secured the database or not, the original mass of data is still out there — there are two other extremely disturbing things about this story.

First, as I noted already, there is almost a complete lack of reporting about it. The DepEd, of course, since it’s busy with stupider things such as needlessly tinkering with the school calendar, did not issue any sort of statement or advisory for the benefit of students and families who may have been affected by the breach. The NPC did not make a public statement, either, but they got a pass because primary responsibi­lity for the sensitive data belongs with the DepEd anyway, and circumspec­tion on the NPC’s part may better serve the needs of its investigat­ion.

The Philippine news media, for its part, completely dropped the ball. As of Friday, the only report on the breach that can be found in the entire country is a story in the Davaobased Mindanao Times, which simply posted the press release from vpnMonitor in its entirety. I would like to think that the rest of the media simply missed it — which is still not a good excuse, given the gravity of the story — rather than intentiona­lly ignored it because there is no question whether or not the report is true; the press release provides a number of screenshot­s (appropriat­ely redacted for privacy, of course) of the informatio­n, documents and photos of the students that can be found in the stolen OVAP database online.

The second disturbing thing about this story is that it turns out that this latest breach is not actually the first or biggest data breach of the DepEd’s systems just this month. In searching for news reports about the OVAP breach — and finding none, as I explained — I found a different story from February 14, in which a massive 750-GB data breach had been reported, this one supposedly containing teachers’ and students’ personal informatio­n and banking informatio­n. The DepEd, in this case, at least, dismissive­ly acknowledg­ed that a report had been made, with a spokesman telling Philstar that it was trying to verify if a hack had indeed occurred.

While the current DepEd secretary is, of course, not personally tasked with maintainin­g IT system security, these alarming incidents occurring on her watch are not a good look. One might even form the opinion that, perhaps, she should spend less time ghoulishly using dead and wounded soldiers for photo ops like some kind of weird-looking Grim Reaper as part of what is apparently a six-year campaign for the presidency and more time keeping her own office in order. At a minimum, a heads-up about a potential personal security risk and some relevant guidance for students and families under that office’s care would definitely be in order.

 ?? ??

Newspapers in English

Newspapers from Philippines