- 27/06/2024
- Category: Commentaries
Author: Ayom Mratita Purbandani
Editor: M Perdana Karim
As the Ministry of Communication and Informatics (Kominfo) threatens to block the app X (formerly Twitter) in response to its new policy of allowing sexual content to circulate as a form of “legitimate artistic expression”, a website named ElaElo has emerged, regarded as an alternative to X. There is a suspicion that this site is a government-sponsored initiative, which calls itself a “local social media replacement for X.”1 According to ElaElo’s homepage, which features the Garuda emblem and claims to be made by Kominfo, the statement ‘Under Kominfo’s Supervision’ reinforces this suspicion. In response, Kominfo’s official website refuted this claim, stating that it has not developed ElaElo.2
The ElaElo project has been controversial from the start. The public has been adversely affected by the portrayal of the site as a government project and an alternative to blocking X. A blockage of X by the government is seen as a government attempt to suppress freedom of expression.3 With Kominfo’s denial of being the developer of ElaElo, the public’s skepticism about the legitimacy of ElaElo has intensified. Concerns range from the unclear authority of the developer to extremely low security levels.
Who is the developer?
Having Kominfo deny ElaElo’s unilateral claim regarding its development raises questions about who is actually responsible for its development. The WHOIS data indicates that ElaElo is owned by PT Aksara Data Digital, with the domain www.aksaradata.id, located at Cyber Building 1, 3rd Floor, South Jakarta.4 Aksara Data Digital, however, denies developing ElaElo, stating that they are only the registrar and not the owner of the domain. ElaElo’s creator, using the alias ‘Iron Dome #Hmei’, serves as an administrator on the website. This administrator altered a headline within ElaElo from “Indonesians Urged to Change Social Media, Kominfo to Block X” to “Indonesians Urged to Change Social Media to Elaelo.id, Kominfo to Block X.” The original developer of ElaElo remains a mystery, as the data of the domain tenant is unknown.
A possible breach of personal data
ElaElo’s data security has been questioned by several netizens who have accessed the service. A user named Om Jayy (@Omjayyyyyyyy) on X tweeted that ElaElo forces visitors to accept all cookies when they first access the site. Taking all cookies without informing users is a dangerous practice, as it allows excessive and nontransparent data collection.5
Source: @Omjayyyyyyy on X
ElaElo’s About Us, Privacy Policy, Terms of Use, and FAQ sections contain no detailed information about the site. Therefore, there is no legal assurance that the data won’t be misused or sold. In accordance with UU No. 27 of 2022 on Personal Data Protection, such information is mandatory for a site. SAFEnet’s Head of the Digital Security Division, Daeng Ipul, warns that the ElaElo site is very unsafe and insecure.6 Among other things, ElaElo’s lack of essential information raises doubts regarding the developers’ motives and credibility. Moreover, the ElaElo user interface closely mimics that of X, making the site appear unoriginal. According to the narrative, ElaElo is intended to replace X locally. However, the developers shouldn’t duplicate it completely.
Initially, the site featured a Guy Fawkes mask informing visitors of maintenance with a black background, displaying the Garuda logo, and stating “Under Construction by Kominfo.” However, after Kominfo’s denial, it was changed to “Under Construction by Democracy Fighter.”
Sumber: elaelo.id
There are some who believe that ElaElo was created as a satirical response to the blocking of X. Most X users, however, are hesitant to switch to ElaElo because of its unclear developers, privacy concerns, and complete similarities to X. As netizens shared their extensive information and experiences about ElaElo’s lack of transparency, they indicate that the public is increasingly concerned about protecting personal information.
Sumber: @zassfarsabilah, @szxcdav, and @abdlrzzq di X
Since Kominfo’s official denial, ElaElo’s one-sided information has become clearer; however, Kominfo should take firm action against ElaElo considering the use of the Garuda logo and the national anthem displayed on ElaElo’s website. On June 20, 2024, ElaElo became inaccessible, but it is unknown how many users registered and shared their personal data with it. Websites that collect personal data from users need to be held accountable for that data.
- Ramdhan, F. Tirto.id. “Apa Itu ElaElo yang Katanya Medsos Lokal Pengganti X?” Accessed June 23, 2024. https://tirto.id/apa-itu-elaelo-yang-katanya-medsos-lokal-pengganti-x-gZKx. ↩︎
- Hoaks Situs ElaElo Buatan Kementerian Kominfo,” Kementerian Komunikasi dan Informatika, accessed June 23, 2024, https://www.kominfo.go.id/content/detail/57226/hoaks-situs-elaelo-buatan-kementerian-kominfo/0/laporan_isu_hoaks. ↩︎
- Kilat.com, ‘Medsos Tanah Air ElaElo Tuai Kritik, Ditakuti Jadi Aplikasi Lakukan Phising Rakyat,’ accessed June 23, 2024, https://www.kilat.com/nasional/84412927858/medsos-tanah-air-elaelo-tuai-kritik-ditakuti-jadi-aplikasi-lakukan-phising-rakyat. ↩︎
- WHOIS Lookup for elaelo.id,” GoDaddy, accessed June 23, 2024, https://sg.godaddy.com/whois/results.aspx?itc=dlp_domain_whois&domain=elaelo.id. ↩︎
- Xu, Z., Yu, W., Almohri, H. M., & Xu, W. “Accept All Exploits: Exploring the Security Impact of Cookie Banners,” Proceedings of the 38th Annual Computer Security Applications Conference (2022): 68-80. https://doi.org/10.1145/3564625.3564647. ↩︎
- Situs ElaElo Dianggap Tidak Aman, SAFEnet Peringatkan Soal Keamanan Data,” Tempo, accessed June 23, 2024, https://tekno.tempo.co/read/1881792/situs-elaelo-dianggap-tidak-aman-safenet-peringatkan-soal-keamanan-data. ↩︎