<?xml version="1.0" encoding="utf-8" standalone="yes"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-ph"><title>techmagus</title><link rel="self" type="application/atom+xml" hreflang="en-ph" href="https://im.youronly.one/techmagus/tag/privacy/feed.xml"/><link rel="alternate" type="application/atom+xml" hreflang="ja" href="https://im.youronly.one/techmagus/ja/tag/%E3%83%97%E3%83%A9%E3%82%A4%E3%83%90%E3%82%B7%E3%83%BC/feed.xml"/><link rel="alternate" type="application/atom+xml" hreflang="ko" href="https://im.youronly.one/techmagus/ko/tag/%EC%9D%80%EB%91%94/feed.xml"/><link rel="alternate" type="application/atom+xml" hreflang="x-default" href="https://im.youronly.one/techmagus/tag/privacy/feed.xml"/><link rel="alternate" type="text/html" hreflang="en-ph" href="https://im.youronly.one/techmagus/tag/privacy/"/><link rel="alternate" type="application/rss+xml" hreflang="en-ph" href="https://im.youronly.one/techmagus/tag/privacy/index.xml"/><id>/techmagus</id><updated>2025-04-02T22:30:08Z</updated><generator>Hugo 0.135.0</generator><entry><title>Philippine ISPs caught hijacking connections</title><link rel="alternate" type="text/html" hreflang="en-ph" href="https://im.youronly.one/techmagus/philippines-isp-hijack-connection-2021206/"/><id>https://im.youronly.one/techmagus/philippines-isp-hijack-connection-2021206/</id><updated>2021-07-25T03:37:38Z</updated><summary type="html">&lt;p>A friend of mine noticed that Philippine ISPs started to hijack connections to certain websites and they are also using a fake SSL certificate. If a user choose the option to continue despite the warning about an invalid SSL certificate, they will see a Philippine government warning and the related Republic Act explaining why they–our ISPs–are hijacking our connection.&lt;/p>
&lt;p>Let’s take a look at an example.&lt;/p></summary><content type="html"><![CDATA[<img src="https://im.youronly.one/techmagus/images/m/mediafire-no-vpn-ph-gov-isp-ssl-hijack-03.png" /><p>A friend of mine noticed that Philippine ISPs started to hijack connections to certain websites and they are also using a fake SSL certificate. If a user choose the option to continue despite the warning about an invalid SSL certificate, they will see a Philippine government warning and the related Republic Act explaining why they–our ISPs–are hijacking our connection.</p>
<p>Let’s take a look at an example.</p>
<p><strong>MediaFire</strong> is a popular file sharing and cloud storage. A file sharing and/or cloud storage service by itself is not “evil” as most governments, politicians, and the corporate world is painting it to be. Unfortunately, as with all services and technologies, there are people who use it for “evil purposes”. This was the basis for the Philippine government [supposedly] ordering Philippine ISPs to hijack the connection to <strong>MediaFire</strong>, as shown in the screenshot below.</p>
<div class="obj_center"><figure class="figure_box txt_center">
      <div>
          <picture><source srcset="https://im.youronly.one/techmagus/images/m/mediafire-no-vpn-ph-gov-isp-ssl-hijack-01_hu13124372845659683206.webp" type="image/webp" /><img src="https://im.youronly.one/techmagus/images/m/mediafire-no-vpn-ph-gov-isp-ssl-hijack-01.png" alt="Hijacked connection" type="image/png" style="max-width: 100%;" loading="lazy" decoding="async" />
          </picture>
          </div>
      <figcaption class="attribution_caption txt_center">
        
        <p><i>Hijacked connection</i></p><p xmlns:dct="http://purl.org/dc/terms/" xmlns:vcard="http://www.w3.org/2001/vcard-rdf/3.0#"><small>
              <cite>Hijacked connection</cite> by <a href="https://im.youronly.one/" rel="dct:creator noopener">I’M YourOnly.One</a> is
                  licensed under <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="license noopener external">CC BY-SA 4.0 International</a>.</small></p></figcaption>
    </figure></div>

<p>Based on the message shown in the screengrab above, <strong>MediaFire</strong> <q>is a suspected child sexual abuse or exploitation material (CSAEM)</q>. They then explained that they will <q>initiate decryption of traffic for possible CSAEM content and block access as mandated by Republic Act No. 9775 or the Anti-Child Pornography Act of 2009.</q> In other words, they admit that your connection to <strong>MediaFire</strong> was hijacked and their all-seeing eye is watching you closely.</p>
<p>This is a very bad reality. There is now no doubt that all it takes for Philippine ISPs to intercept our Internet connection is an order from the Philippine government suspecting services and websites of CSAEM and/or whatever other laws they can use to justify breaking the privacy and security of the people.</p>
<p>Google Drive, OneDrive, and Dropbox, probably does not have “illegal content” because they can police their users. But you have to ask the question, how? Could it be they can read all the files uploaded to their storage? We will never know but at least one of those mentioned admitted that they do (it’s even in their Terms).</p>
<p><strong>It is understandable</strong> why they are doing this, no good person would tolerate child abuse and child pornography, that is a line no sane human being should ever cross. However, the way they are doing this policing is never acceptable, this is a clear violation of the user’s privacy and hijacking connections is a clear act of compromising the user’s security. No one can guarantee what these ISPs will do with the data they can see. They usually can not be held accountable if one of their “trusted” employee leaks confidential information he or she saw while searching for CSAEM materials. It is easy to say they will never do anything else other than to watch out for CSAEM but clearly, all it takes is a government order and we will never know what they are doing with all the other data.</p>
<p>We all know that we can never trust ISPs, government order or not, so let this be a lesson for everyone in the Philippines: encrypt your files before uploading; and use only services which offers end-to-end encryption; and always use <a href="https://www.torproject.org" title="Tor" class="icon_external" rel="noopener external">Tor</a> (The Onion Router) or better yet a highly reputable VPN. Our <strong>privacy</strong> <em>and</em> <strong>security</strong> matters.</p>
<div class="obj_center"><figure class="figure_box txt_center">
      <div>
          <picture><source srcset="https://im.youronly.one/techmagus/images/m/mediafire-ssl-cert-comparison-01_hu15046826826895372755.webp" type="image/webp" /><img src="https://im.youronly.one/techmagus/images/m/mediafire-ssl-cert-comparison-01.png" alt="Left: Hijacked connection SSL cert; Right: Encrypted connection and correct SSL certificate" type="image/png" style="max-width: 100%;" loading="lazy" decoding="async" />
          </picture>
          </div>
      <figcaption class="attribution_caption txt_center">
        
        <p><i>Left: Hijacked connection SSL cert; Right: Encrypted connection and correct SSL certificate</i></p><p xmlns:dct="http://purl.org/dc/terms/" xmlns:vcard="http://www.w3.org/2001/vcard-rdf/3.0#"><small>
              <cite>Left: Hijacked connection SSL cert; Right: Encrypted connection and correct SSL certificate</cite> by <a href="https://im.youronly.one/" rel="dct:creator noopener">I’M YourOnly.One</a> is
                  licensed under <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="license noopener external">CC BY-SA 4.0 International</a>.</small></p></figcaption>
    </figure></div>

<figure class="quote_box qbs_generic qbc_red">
<blockquote class="qbm_doublequotationmark" cite="https://github.com/DNSCrypt/dnscrypt-proxy/discussions/1790#discussioncomment-1052610">
<p>It looks like your ISP is using gear from Palo Alto networks to intercept your SSL traffic based on the common name in the SSL certificate.</p>
</blockquote><figcaption class="attribution_name txt_right">
<p><cite><a href="https://github.com/DNSCrypt/dnscrypt-proxy/discussions/1790#discussioncomment-1052610" rel="dct:title noopener external nofollow" referrerpolicy="strict-origin-when-cross-origin">Re: ISP can still hijack #1790</a>, </cite><a href="https://github.com/dapphp" rel="dct:creator noopener external nofollow" referrerpolicy="strict-origin-when-cross-origin">dapphp</a></p>
</figcaption></figure>
<p><strong>MediaFire</strong> was also informed and they are looking into addressing this.</p>
<hr>
<div role="cover-image-attributions">
    <div class="header_attribution">
      <footer class="attribution_caption"><p xmlns:dct="http://purl.org/dc/terms/" xmlns:vcard="http://www.w3.org/2001/vcard-rdf/3.0#"><small>
              ・ Cover image: <cite>Warning: Potential Security Risk Ahead</cite> by <a href="https://im.youronly.one/" rel="dct:creator noopener">I’M YourOnly.One</a> is
                  licensed under <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="license noopener external">CC BY-SA 4.0 International</a>.</small></p></footer>
    </div></div>]]></content><author><name>Yohan Yukiya Sese-Cuneta</name><uri>https://im.youronly.one/techmagus/</uri></author><category term="internet" label="Internet" scheme="https://im.youronly.one/techmagus/cat/internet/"/><category term="privacy" label="Privacy" scheme="https://im.youronly.one/techmagus/tag/privacy/"/><category term="security" label="Security" scheme="https://im.youronly.one/techmagus/tag/security/"/><published>2021-07-25T03:37:38Z</published></entry></feed>