Pinoy Data Privacy

Pinoy Data Privacy

Share

Pinoy Data Privacy stands as an advocacy of culture of data privacy awareness in the Philippines.

"Pinoy Data Privacy" stands as a robust advocacy initiative dedicated to fostering a culture of heightened data privacy awareness across the Philippines. Spearheaded by passionate individuals committed to safeguarding personal and sensitive information, this movement strives to empower Filipinos with the knowledge and tools necessary to protect their digital identities and privacy rights in an increasingly interconnected world. Through educational campaigns, workshops, and outreach programs, Pinoy Data Privacy seeks to demystify the complexities of data privacy laws and regulations, making them accessible and understandable to all. By promoting best practices in handling, sharing, and securing data, the initiative endeavors to equip individuals, businesses, and organizations with the skills needed to navigate the digital landscape responsibly and ethically. Moreover, Pinoy Data Privacy serves as a vocal advocate for legislative reforms and policy enhancements aimed at strengthening data protection frameworks within the Philippines. By collaborating with government agencies, industry stakeholders, and civil society groups, the initiative strives to shape a regulatory environment that prioritizes the privacy rights of Filipino citizens while fostering innovation and economic growth. At its core, Pinoy Data Privacy embodies a collective commitment to upholding the fundamental right to privacy and ensuring that every Filipino can confidently navigate the digital realm with a sense of security, dignity, and respect for their personal information.

11/09/2026

NEWS | Several Philippine government websites, including BIR's, were hacked on Sept. 8, 2026. Homepages were defaced, but the agencies and DICT restored them within hours. Taxpayer records and core systems reportedly weren't touched, though checks continue.

DICT's cybersecurity team, the Cybercrime Investigation and Coordinating Center, and the PNP Anti-Cybercrime Group are working to trace the breach and prevent repeats.

This isn't the first time gov't sites have been hacked, and "your data is safe" isn't the full picture. What's needed: regular security checkups, faster fixes, and clear public updates. Not a one-time patch.

Any cybersecurity experts here? What are your thoughts on how this could've been prevented? If you've got ideas or projects in this space, let's connect. Drop a comment or message us.

07/08/2026

๐ŸŒ HTTP vs. HTTPS vs. VPN โ€“ What's the Difference? ๐Ÿ”’

Understanding these technologies is essential for protecting your privacy online. HTTP sends data without encryption, HTTPS encrypts your connection to websites, and a VPN creates a secure encrypted tunnel that helps protect your internet activity from your ISP and other third parties. Knowing when to use each option can significantly improve your online security and privacy.

๐Ÿ’ฌ Which do you rely on the most for secure browsingโ€”HTTPS alone or HTTPS with a VPN? Share your thoughts in the comments!

07/08/2026

Nmap is a network scanning tool used by system administrators, IT professionals, and students for security auditing, troubleshooting, and learning.

Common Scans

nmap -sP โ†’ Ping Scan: Checks which devices are active on a network.

nmap -sS โ†’ TCP SYN Scan: Helps discover open services.

nmap -sU โ†’ UDP Scan: Finds active UDP services.

nmap -sV โ†’ Version Detection: Identifies service versions for maintenance.

nmap -O โ†’ OS Detection: Detects operating system type (for compatibility testing).

nmap -A โ†’ Aggressive Scan: Runs multiple checks for detailed results.

Timing & Input

nmap -T4 โ†’ Timing Template: Controls scan speed.

nmap -iL โ†’ Input from List: Reads targets from a file (useful for admins).

nmap -sn โ†’ Host Discovery: Finds devices without scanning ports.

Advanced TCP Techniques

nmap -sX โ†’ XMAS Scan: Uses a special test packet to check responses.

nmap -sF โ†’ FIN Scan: Uses a different method for host analysis.

nmap -sT โ†’ TCP Connect Scan: Connects directly to services.

nmap -sN โ†’ Null Scan: Uses empty packets to analyze responses.

nmap -sA โ†’ ACK Scan: Helps detect firewall filtering.

Scripting & Port Options

nmap -sC โ†’ Default Script Scan: Runs safe built-in scripts.

nmap --script โ†’ Run Specific Script: For detailed service checks.

nmap --top-ports โ†’ Top Ports Scan: Scans the most used ports.

07/08/2026

๐Ÿ“ฑ A Few Minutes Updating Your Device Can Save Hours Of Frustration Later ๐Ÿš€

07/08/2026

โšก๐—ก๐—ฒ๐˜„๐—น๐˜† ๐—ฎ๐—ฝ๐—ฝ๐—ผ๐—ถ๐—ป๐˜๐—ฒ๐—ฑ ๐—ฎ๐˜€ ๐—ฎ ๐——๐—ฎ๐˜๐—ฎ ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ข๐—ณ๐—ณ๐—ถ๐—ฐ๐—ฒ๐—ฟ? ๐—ฆ๐˜๐—ฎ๐—ฟ๐˜ ๐˜€๐˜๐—ฟ๐—ผ๐—ป๐—ด.

Equip yourself with the practical knowledge and skills to lead your organization's data privacy compliance. Join the ๐——๐—ฃ๐—ข ๐—™๐—”๐—ฆ๐—ง-๐—ง๐—ฅ๐—”๐—–๐—ž ๐—Ÿ๐—ฒ๐—ฎ๐—ฟ๐—ป๐—ถ๐—ป๐—ด ๐—ฆ๐—ฒ๐˜€๐˜€๐—ถ๐—ผ๐—ป and learn how to implement the ๐——๐—ฎ๐˜๐—ฎ ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ฎ๐—ฐ๐˜† ๐—”๐—ฐ๐˜ ๐—ผ๐—ณ 2012 (๐—ฅ๐—” 10173) with confidence and clarity.

Led by ๐—”๐˜๐˜๐˜†. ๐—ฅ๐—ฎ๐—ป๐—ฑ๐—ผ๐—น๐—ณ๐—ผ ๐—–. ๐—ฌ๐—ฎ๐—ป๐˜‡๐—ฎ, this intensive webinar focuses on real-world compliance, practical applications, and the essential responsibilities of every DPO.

๐Ÿ“… August 22, 2026 (Saturday)
๐Ÿ•˜ 9:00 AM โ€“ 4:30 PM
๐Ÿ’ป Zoom Webinar
๐Ÿ’ฐ Learning Investment: โ‚ฑ3,500

๐ŸŽฏ ๐™๐™š๐™œ๐™ž๐™จ๐™ฉ๐™š๐™ง ๐™ฃ๐™ค๐™ฌ ๐™–๐™ฃ๐™™ ๐™›๐™–๐™จ๐™ฉ-๐™ฉ๐™ง๐™–๐™˜๐™  ๐™ฎ๐™ค๐™ช๐™ง ๐˜ฟ๐™‹๐™Š ๐™Ÿ๐™ค๐™ช๐™ง๐™ฃ๐™š๐™ฎ.
๐Ÿ”— https://forms.gle/19YZB38mdPzBBgFf8

18/07/2026

๐Ÿšจ Email Change Takeover Bug: When Changing Email Becomes Account Takeover
Email address is one of the most important parts of any online account.
It is used for login, password reset, security alerts, OTPs, invoices, notifications, and account recovery.
But if the email change process is weak, attackers may abuse it to take over user accounts.
This is called Email Change Takeover Bug.
๐Ÿ” What Is Email Change Takeover?
Email change takeover happens when an attacker can change the email address linked to an account without strong verification.
If the system does not properly verify the old email, new email, password, session, or MFA, the attacker may replace the victimโ€™s email with their own.
After that, they can reset the password, receive security alerts, and control the account.
โš ๏ธ Common Email Change Bugs:
๐Ÿ”น Email changed without password confirmation
๐Ÿ”น Email changed without verifying old email
๐Ÿ”น Email changed without verifying new email
๐Ÿ”น Verification link works multiple times
๐Ÿ”น Old session remains active after email change
๐Ÿ”น Password reset goes to attackerโ€™s new email
๐Ÿ”น MFA not required for email change
๐Ÿ”น Email change allowed from hijacked session
๐Ÿ”น Weak CSRF protection on email update
๐Ÿ”น API accepts modified user ID or email field
๐Ÿ”น Email change token does not expire
๐Ÿ”น User not alerted after email update
๐ŸŽฏ Why This Is Dangerous:
๐Ÿ”น Full account takeover can happen
๐Ÿ”น Password reset can be redirected
๐Ÿ”น Security alerts go to attacker
๐Ÿ”น Victim may lose recovery access
๐Ÿ”น Business accounts can be compromised
๐Ÿ”น Sensitive data can be exposed
๐Ÿ”น Attacker can lock out the real user
๐Ÿ”น Trust and platform security can be damaged
๐Ÿง  Example Scenario:
An attacker gains access to a victimโ€™s logged-in session.
They go to account settings and change the email address.
The platform only asks for the new email and does not require password, MFA, or old email confirmation.
Now the attacker controls the recovery email.
They can request a password reset and take full control of the account.
This is how weak email change logic can become account takeover.
๐Ÿ›ก๏ธ How Companies Can Stay Safe:
โœ… Require password confirmation before email change
โœ… Require MFA for sensitive account changes
โœ… Verify the new email before activating it
โœ… Send security alert to the old email
โœ… Delay sensitive changes for high-risk accounts
โœ… Invalidate old sessions after email change
โœ… Prevent email change from suspicious sessions
โœ… Use short-lived verification tokens
โœ… Make verification tokens single-use
โœ… Log every email change event
โœ… Alert users about email update attempts
โœ… Rate limit email change requests
โœ… Validate ownership on backend APIs
โœ… Test email change flow during security reviews
๐Ÿ”ฅ Why Ethical Hackers Should Care:
Email change takeover is a serious authentication and account security vulnerability.
It may look like a simple profile update feature, but the impact can be critical.
Modern ethical hacking should test email update flow, old email verification, new email verification, password confirmation, MFA enforcement, token expiry, session handling, and password reset behavior.
An email address is not just contact information.
It is the recovery key to the account. ๐Ÿ“งโš ๏ธ
If email change is weak, account takeover becomes easy.

18/07/2026

๐‘๐„๐€๐ƒ: Real reforms begin with institutions willing to lead. We are grateful to the ๐ƒ๐ž๐ฉ๐š๐ซ๐ญ๐ฆ๐ž๐ง๐ญ ๐จ๐Ÿ ๐๐ฎ๐๐ ๐ž๐ญ ๐š๐ง๐ ๐Œ๐š๐ง๐š๐ ๐ž๐ฆ๐ž๐ง๐ญ (๐ƒ๐๐Œ) and our government partners for demonstrating that leadership through their constructive engagement with ODPP, bringing the institutionalization of the Data Protection Officer profession closer to reality.

United by a common purpose, we will continue advancing the institutionalization of the ๐ƒ๐š๐ญ๐š ๐๐ซ๐จ๐ญ๐ž๐œ๐ญ๐ข๐จ๐ง ๐Ž๐Ÿ๐Ÿ๐ข๐œ๐ž๐ซ (๐ƒ๐๐Ž) ๐š๐ฌ ๐š ๐ซ๐ž๐œ๐จ๐ ๐ง๐ข๐ณ๐ž๐ ๐ฉ๐ซ๐จ๐Ÿ๐ž๐ฌ๐ฌ๐ข๐จ๐ง to help build a more secure, privacy-respecting, and future-ready Philippines.

---
๐—ง๐—ผ ๐—ฟ๐—ฒ๐—ฎ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ณ๐˜‚๐—น๐—น ๐—ฝ๐—ผ๐˜€๐—ถ๐˜๐—ถ๐—ผ๐—ป ๐—น๐—ฒ๐˜๐˜๐—ฒ๐—ฟ, ๐—ฐ๐—น๐—ถ๐—ฐ๐—ธ ๐—ต๐—ฒ๐—ฟ๐—ฒ: https://www.facebook.com/odppi/posts/pfbid02vY5UZS3wJMxB1kUvwLFEwhe5ZTcJyNPsaaVNo4nQM6fNDqzUYuMtPAtkZnMCr5RMl

18/07/2026

๐—–๐—ข๐—ก๐—š๐—ฅ๐—”๐—ง๐—จ๐—Ÿ๐—”๐—ง๐—œ๐—ข๐—ก๐—ฆ to all our participants who successfully completed the seminar on ๐——๐—ฎ๐˜๐—ฎ ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ฎ๐—ฐ๐˜† ๐—Ÿ๐—ฎ๐˜„: ๐——๐—ฃ๐—ข ๐—™๐—”๐—ฆ๐—ง-๐—ง๐—ฅ๐—”๐—–๐—ž ๐—˜๐—ฎ๐˜€๐˜†-๐—Ÿ๐—ฒ๐—ฎ๐—ฟ๐—ป๐—ถ๐—ป๐—ด ๐—ฆ๐—ฒ๐˜€๐˜€๐—ถ๐—ผ๐—ป.

We look forward to welcoming the next batch of participants in August!

Want your practice to be the top-listed Law Practice in Manila?
Click here to claim your Sponsored Listing.

Category

Website

Address


Manila