Why Are HowBridge's DNS and Web Hosting on Chunghwa Telecom in Taiwan? Does Your Personal Data Pass Through China?
Quick answer: Where are HowBridge's DNS and hosting? Does personal data go to China?
HowBridge 0523.tw's registrar is Chunghwa Telecom HiNet (per TWNIC whois records), its authoritative DNS name servers are admns1.hinet.net and admns2.hinet.net (HiNet DNS hosting), and the web hosting's IPv4 114.32.86.150 and its IPv6 address both belong to Chunghwa Telecom HiNet (APNIC whois: Data Communication Business Group, Chunghwa Telecom), physically located in Taoyuan; member accounts, recipient details, consolidation orders and billing data are stored in the database on this Taiwan-based server, and backups are also kept within Taiwan. We do not use any DNS hosting, CDN, cloud hosting or database service based in China — the A record points directly to the Taiwan server, with no third-party CDN proxy in between. Consolidation itself requires the Shenzhen warehouse to label and ship your package, and that step's minimum-necessary data processing is handled under the "Cross-Border Data Transfer" section of our Privacy Policy — this page is about the domain, hosting and data storage, and it does not make an "absolute" guarantee for the entire operational process.
HowBridge has only a Shenzhen consolidation warehouse and a Taoyuan operations warehouse, and only offers China → Taiwan consolidation service; we have no warehouses in any other country, and we do not offer purchasing-agent (daigou) service. This page is about the domain, DNS, hosting and data storage location of the 0523.tw website itself; for data handling in warehouse operations and logistics, our Privacy Policy governs.
Who Hosts HowBridge's Domain DNS? Where Is the Web Server?
Where a website "lives" has three layers: which provider the domain is registered with, who manages the DNS name servers, and which network operator the hosting IP address belongs to, and which country it's in. All three layers have public records, and for HowBridge the answer is Chunghwa Telecom HiNet across the board — all in Taiwan. The table below shows the verification results and lookup methods as of September 22, 2026:
| Item | Verification Result | How to Check (anyone can do this) |
|---|---|---|
| Domain Registry (.tw) | Taiwan Network Information Center (TWNIC) — a foundation based in Taipei | whois 0523.tw; or use TWNIC's web lookup at whois.twnic.tw and enter the domain |
| Registrar | Chunghwa Telecom HiNet (Registration Service Provider: HINET; service URL domain.hinet.net) | The "Registration Service Provider" field in the whois result |
| Authoritative DNS Name Servers | admns1.hinet.net, admns2.hinet.net (HiNet DNS hosting; both servers sit within HiNet's Taiwan network ranges) | dig NS 0523.tw; the "Domain servers in listed order" field in whois |
| Web Hosting IPv4 | 114.32.86.150, registered in APNIC with netname HINET-NET, description Data Communication Business Group, Chunghwa Telecom Co., Ltd., country TW | dig A 0523.tw → whois 114.32.86.150 |
| Web Hosting IPv6 | Within 2001:b011:5c0c:d168::/64 (part of HiNet's 2001:b011::/32 allocation block) | dig AAAA 0523.tw |
| Physical Server Location | Taoyuan City (HowBridge's Taoyuan operations site, on a Chunghwa Telecom Hinet Fiber static-IP line) | IP ownership only shows Chunghwa Telecom and Taiwan; the city-level detail is self-disclosed by HowBridge |
| Whether It Goes Through a CDN or Proxy | No: the A/AAAA records point directly to the server; there is no third-party reverse proxy between the browser and the server | The IP returned by dig is the server's own IP, not a CDN provider's IP range |
| TLS Certificate | Issued by Let’s Encrypt, covering 0523.tw and www.0523.tw, with the default 90-day validity period and automatic renewal before expiry | The padlock icon in the browser address bar › Certificate information |
It's the authoritative DNS layer — anywhere in the world, when something needs the IP for 0523.tw, the query ultimately goes to HiNet's admns1/admns2.hinet.net. Which recursive resolver your own computer or phone uses (for example, your carrier, your router, or a custom public DNS you've set) is a setting on your end — HowBridge has no control over it and can't see it; but no matter which resolver you use, it still has to get the answer from HiNet's authoritative servers in the end.
When You Open 0523.tw, Which Nodes Do the DNS Lookup and Connection Pass Through?
Many people assume that "where a website is" only refers to its server. In reality, a chain of nodes sits between the moment you hit Enter and the moment the page appears; who operates each node, and in which country, determines who has a chance to see what. Below is the typical path a Taiwan-based user takes to open 0523.tw (using a Chunghwa Telecom subscriber as the example; for users of other carriers, the difference is in the resolver in Step 1 and the first half of the backbone in Step 4):
| Step | Node | Operator · Location | What It Handles |
|---|---|---|---|
| 1 | Your device and its recursive resolver (e.g., HiNet 168.95.1.1, or the DNS set by your router) | Your carrier or a service you've configured yourself · Taiwan (or wherever that provider is, if you use an overseas public DNS) | The question "what's the IP for 0523.tw"; does not include your account or page content |
| 2 | Root name servers and the .tw top-level domain servers | Root: 13 root-server letters coordinated by ICANN/IANA, 7 of which have sites in Taiwan (root-servers.org); .tw: TWNIC · Taiwan | Answers only "who manages .tw" and "who are 0523.tw's name servers"; usually already cached by the resolver, so it isn't queried every time |
| 3 | Authoritative name servers admns1/admns2.hinet.net | Chunghwa Telecom HiNet · Taiwan | Answers with 0523.tw's IPv4/IPv6 address |
| 4 | HTTPS connection (TLS 1.3 encryption, per the negotiated result measured 2026-09-22) | Your carrier's backbone → Chunghwa Telecom HiNet's backbone · Taiwan | The encrypted request and response; intermediate nodes can only see that you're connecting to port 443 on 114.32.86.150 and the site name (0523.tw) — they cannot see your account, password or page content |
| 5 | HowBridge's web server (nginx + Laravel) | HowBridge · Taoyuan (a Chunghwa Telecom static-IP line) | The decrypted request; logins, member data, consolidation orders and billing are all processed here |
| 6 | Database and cache | Same server · Taoyuan | Member and order data; not open to external connections |
| 7 | Backups | Local on the server + a separate independent storage device (a NAS within Taiwan; restic AES-256-encrypted snapshots) | The encrypted database and site files |
Steps 3, 5, 6 and 7 (authoritative DNS, hosting, database, backups) are all in Taiwan; in Step 4, the HowBridge side of the connection also terminates in Taiwan. Steps 1 and 2 are determined by your own network environment and internet infrastructure: when you're online in Taiwan, .tw and root-server queries are also mostly completed within Taiwan (both TWNIC and root-server mirrors are located here). If you're physically in mainland China or use an overseas DNS, the resolver in Step 1 will naturally be on the network you're connected to — that's your own environment, not HowBridge sending your data there.
The page loads fonts from Google Fonts and an icon font from cdnjs, and uses Microsoft Clarity to record anonymized interaction behavior; these services cannot obtain your login credentials or password. None of them is a service based in China.
Why Chunghwa Telecom HiNet? What's the Basis for the Stability and Speed Claims?
When choosing a registrar, DNS host and hosting line, we apply just three criteria: within Taiwan, on the same network as most Taiwan-based users, and backed by public records. Chunghwa Telecom describes itself as Taiwan's largest integrated telecom operator, and the NCC has also designated it as holding significant market power in the fixed-network broadband retail market (see the evidence below); when a HiNet subscriber looks up 0523.tw, both the authoritative DNS and the hosting sit within HiNet's own backbone, so there's no need to route out over an international line; users of other carriers only need to pass through a domestic Taiwan interconnection point. Here's the evidence we can point to:
Scale: Taiwan's Largest Fixed-Line and Broadband Operator
Chunghwa Telecom's own website describes it as "the largest integrated telecom operator in Taiwan," and its 2025 Form 20-F filed with the U.S. SEC likewise states it is Taiwan's largest telecommunications service provider (reorganized from the Directorate General of Telecommunications, Ministry of Transportation and Communications on July 1, 1996; stock code 2412). Per its 2025 annual report, HiNet's broadband ISP account market share was 52.2% (as of end of December 2025, calculated by the company itself); it had 4.47 million broadband subscribers overall and 3.82 million HiNet broadband subscribers as of end of June 2026 (press release dated 2026-08-05). On the regulator's side: the National Communications Commission (NCC) designated Chunghwa Telecom on June 5, 2023 as holding "significant market power in the fixed-network broadband retail service market" (Order No. Tongchuan-Pingtai-Zi 11241012010); the Executive Yuan's Taiwan at a Glance records 7.07 million fixed-line broadband subscriptions nationwide in 2024. The NCC has not published individual operators' fixed-line broadband market shares, and this page does not estimate them.
Proximity: DNS and Hosting Are Both on the Same Taiwan Backbone
For HiNet subscribers, both "looking up 0523.tw's IP" and "connecting to 0523.tw" happen entirely within Chunghwa Telecom's own backbone; for users of other Taiwan carriers, the traffic only passes through domestic Taiwan interconnection points. Because the site doesn't sit behind a CDN or an overseas cloud, there's one fewer proxy round trip, and users aren't routed to the wrong node based on resolver location. Academic measurements back this approach up: the minimum response latency for a local ISP resolver is about 11 ms, versus 24–44 ms for public resolvers (Ager et al., 2010); when a remote resolver is used, CDNs tend to route users to farther nodes, increasing median end-to-end latency by 60% (Otto et al., 2012); and per APNIC Labs' measurements from September 2026, roughly nine in ten Taiwan users' queries go through their own ISP's resolver (see the literature below).
Verifiable: Every Item Is a Public Record
The registrar, name servers and IP ownership are all public data from TWNIC and APNIC — we're not the ones asserting it; Section 7 of this page has the full verification steps.
| Measurement | Method | Result (12 runs) |
|---|---|---|
| DNS Query Time: via HiNet's Public Resolver 168.95.1.1 | dig @168.95.1.1 0523.tw A, reading the Query time | Median 5 ms, range 2–36 ms (slower on cache misses) |
| DNS Query Time: Querying the Authoritative Server admns1.hinet.net Directly | dig @admns1.hinet.net 0523.tw A | Median 3 ms, range 1–9 ms |
| HTTPS Time to First Byte (TTFB) | curl -w %{time_starttransfer}, against a cache-hit article page | Median 35.8 ms, range 34.8–37.1 ms (TCP connect 2.7–4.1 ms, TLS complete 30.9–33.2 ms) |
This is 12 measurements from a single location, single line, single time window, meant to show roughly what order of magnitude round-trip time looks like within the same backbone — it's not a promise to every user; different carriers, mobile networks, and off-peak vs. peak hours will vary. The measurement point is in the same city (Taoyuan) as the server and on the same HiNet line, which is close to a best-case scenario; the raw figures are kept by the HowBridge Editorial Team and available on request, and will be re-measured whenever the page is revised. Another verifiable fact: per root-servers.org's site data as of September 22, 2026, Taiwan hosts 7 root-server letters (D, E, F, I, K, L, M) across 10 sites, and .tw is managed by TWNIC in Taipei — when you're online in Taiwan, every layer of the DNS lookup, from the root, through .tw, to the authoritative server, can typically be completed within the country.
Does Your Personal Data Go to China? Where Is Each Type of Data Stored?
Let's start with the conclusion: the data generated when you register, log in, fill in recipient details, create a consolidation order, or make a payment on 0523.tw is stored in the server database in Taoyuan, Taiwan, and backups are also kept within Taiwan; the site does not use any DNS, CDN, hosting, cloud or database service based in China. But consolidation is a cross-border operation — the Shenzhen warehouse needs to label and ship your package, and that step requires processing the minimum necessary recipient information; this is disclosed truthfully in the "Cross-Border Data Transfer" section of HowBridge's Privacy Policy. The table below breaks down where each category of data lives:
| Data | Storage Location | Does It Leave Taiwan? | Basis |
|---|---|---|---|
| Account (email, phone number, password hash), login history | Taoyuan server database | Not for storage. When sending notifications, email is delivered via Google's mail service (U.S.) and LINE notifications via LY Corporation (Japan) — neither is a China-based service | Hosting and database are on the same server (Sections 1–2 of this page); Privacy Policy, "Data Storage and Protection" |
| Recipient name, phone, address, and — for EZ WAY (Taiwan Customs' real-name verification app) — the declarant's name, phone number and national ID number | Taoyuan server database | At shipping time, the Shenzhen warehouse uses this data to print shipping labels and picking lists — this processing is required to complete cross-border logistics and is limited to what's necessary for that operation | Privacy Policy, "Cross-Border Data Transfer: Mainland China — Warehouse Operations, Logistics Processing" |
| Consolidation orders, billing and payment records | Taoyuan server database | No; card numbers are entered and processed on a Taiwan payment processor's own payment page — HowBridge's server never handles the card number | Privacy Policy, "Data Storage and Protection" |
| Package photos | Taken at the Shenzhen warehouse, then uploaded to the Taoyuan server's file system | Originates at the Shenzhen warehouse, stored in Taiwan | Current state of the site's code |
| Recipient address house-number verification | Taoyuan server → Ministry of the Interior's TGOS (Taiwan) | No; only the address text is sent | Recipient Address House-Number Verification, Explained |
| Backups | Local on the server + a separate independent storage device (a NAS within Taiwan) | No; restic AES-256 encrypted | HowBridge's backup system (Section 6 of this page) |
| DNS queries made while browsing the site | Your resolver → TWNIC → HiNet's authoritative servers | Not on HowBridge's end | Section 2 of this page |
Because it isn't accurate enough: the consolidation warehouse is in Shenzhen, and shipping a package requires recipient information. The accurate version is — the website, DNS, database and backups are all in Taiwan; the Shenzhen warehouse only processes the minimum data needed to ship; when address verification shows a street view, only the address or coordinates (not your name or phone number) are sent to Google; and other than these two cases, your personal data is not transferred to any other country or region (from the original text of the Privacy Policy's "Cross-Border Data Transfer" section: "Other than the regions listed above, we will not transfer your personal data to any other country or region").
A DNS query looks like it's just "asking for an IP," but the query log itself can reconstruct a person's browsing behavior: a study of 3,862 real users found that even when an ISP rotates IPs daily, 73% of highly active users had nearly all of their browsing sessions linkable together within 56 days (Kirchler et al., 2016); resolver operators can see every domain a user queries, and law enforcement can subpoena the logs typically retained by resolvers (Herrmann, 2015); the IETF's RFC 9076 likewise notes that authoritative name servers can see queries as well (§6.2). So "which country the authoritative server is in, and whose laws it falls under" is the part HowBridge can decide for you — Taiwan; "which resolver you personally use" is a choice on your end.
Article 21 of the Personal Data Protection Act (Taiwan) provides that when a non-government agency transfers personal data internationally, the competent central authority may restrict it if any one of four conditions applies: "it involves a major national interest," "an international treaty or agreement contains a special provision," "the receiving country lacks adequate laws to protect personal data, risking harm to the data subject's rights," or "personal data is transferred to a third country/region by an indirect method to circumvent this Act" — this is a clause that authorizes the regulator to restrict transfers, not an automatic ban. The restriction order actually issued is the NCC's Order No. Tongchuan-Tongxun-Zi 10141050780 of September 25, 2012, which, in view of mainland China's then-incomplete personal-data protection laws, restricted telecommunications and broadcasting operators from transmitting their subscribers' personal data to mainland China; it binds telecom and broadcasting operators, and does not directly bind the consolidation industry. What applies directly to HowBridge is Article 8: when collecting personal data, we must disclose "the period, region, recipients and method of use," which is why the Privacy Policy spells out "Shenzhen warehouse operations" and "Google Street View" as specific regions and recipients; as well as Article 20, which requires use "within the necessary scope of the specific purpose for which it was collected." (The amended provisions published on November 11, 2025 have been promulgated but are not yet in effect; this page will be updated once they take effect.)
What's the Difference Between Hosting in Taiwan and Hosting in Mainland China? How Do the Laws on Each Side Compare?
"Which country your data sits in" matters because the law of the place where the data is located determines who can lawfully demand access to it. The table below places side by side the provisions of current Taiwan and mainland China law that directly concern "internet operators' data storage and government access to data"; the mainland China column cites the current texts of the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the National Intelligence Law of the People's Republic of China, and the Measures for the Administration of Internet Domain Names (the original provisions and links are in this page's "Sources and Limits of Verification" section):
| Aspect | Taiwan (where 0523.tw is hosted) | Mainland China |
|---|---|---|
| Basic Law on Personal Data | Personal Data Protection Act (Taiwan) (current version effective 2023-05-31; a 2025-11-11 amendment has been promulgated, with the effective date to be set by the Executive Yuan): Article 8 requires disclosure of the period, region, recipients and method of use at the time of collection; Article 20 limits use to the necessary scope of the purpose of collection; Article 27 requires adopting appropriate security measures. The Personal Data Protection Commission has not yet been established (currently only a preparatory office exists); under the current law, personal-data matters for non-government agencies remain overseen by the relevant central competent authorities. | Personal Information Protection Law (PIPL) (effective 2021-11-01): Article 13 enumerates the lawful bases for processing personal information; Articles 38 through 41 govern personal information leaving the country (security assessment, certification or standard contract, separate consent). There is also the Data Security Law (effective 2021-09-01) and the Cybersecurity Law of the PRC (amended 2025-10-28, effective 2026-01-01). |
| Operators' Duty to Cooperate with Government Authorities | Article 9 of the Telecommunications Management Act: telecom operators have a duty, under the Communication Security and Surveillance Act, to assist in executing communication surveillance and retrieving call records — following that Act's procedures: communication surveillance requires a surveillance warrant (Article 5), and retrieving call records generally requires a court-issued retrieval warrant (Article 11-1). The consolidation industry is not a telecom operator; any data request directed at HowBridge must follow statutory procedures such as those under criminal procedure law. | Article 30 of the Cybersecurity Law of the PRC (article number after the 2025 amendment; formerly Article 28): network operators shall provide technical support and assistance to public security organs and state security organs in their lawful activities to safeguard national security and investigate crimes. Article 35 of the Data Security Law: when public security or state security organs lawfully retrieve data, the relevant organizations and individuals shall cooperate. Article 7 of the National Intelligence Law: all organizations and citizens shall support, assist and cooperate with national intelligence work in accordance with the law (Article 8 further provides that intelligence work shall be carried out in accordance with the law and shall respect and protect human rights). |
| Data Localization (requiring data to be kept in-country) | There is no general data-localization requirement for private businesses. Article 11 of the Cyber Security Management Act (amended 2025-09-24, effective 2025-12-01) provides that government agencies may not use "products that endanger national cybersecurity"; Article 27 allows restricting or banning such use for specific non-government agencies — the subjects covered are government agencies and specific non-government agencies. HowBridge is not among them; keeping our hosting and data in Taiwan is a voluntary choice. | Article 39 of the Cybersecurity Law of the PRC (formerly Article 37): operators of critical information infrastructure must store personal information and important data collected and generated during operations within mainland China, and must undergo a security assessment if it truly needs to be provided overseas; Article 40 of the Personal Information Protection Law imposes the same requirement on personal-information handlers who process data above a specified volume. The subjects covered are limited — not all businesses. |
| Cross-Border Transfer Restrictions | Article 21 of the Personal Data Protection Act (Taiwan): the central competent authority may restrict international transfers under four specified conditions (this is not an automatic ban); the NCC's 2012 Order No. Tongchuan-Tongxun-Zi 10141050780 restricted telecommunications and broadcasting operators from transferring subscribers' personal data to mainland China (limited to telecom and broadcasting operators). No restriction order from any competent authority has been found for the consolidation industry; HowBridge discloses the regions data is transferred to in its Privacy Policy, per Article 8. | Article 38 of the Personal Information Protection Law: personal information leaving the country must go through one of — a security assessment by the national cyberspace administration, certification by a professional body, or a standard contract; Article 39 requires disclosure and obtaining the individual's separate consent; Article 36 of the Data Security Law: without approval from the competent authority, organizations and individuals within mainland China may not provide data stored within mainland China to foreign judicial or law-enforcement bodies. These provisions govern transfers "out of mainland China"; HowBridge's data flow runs the opposite direction (from the Taiwan server to Shenzhen warehouse operations), and this page does not apply these rules to itself. |
| Domain and DNS Management | .tw is managed by the Taiwan Network Information Center (TWNIC), a foundation (per the IANA delegation record: registered 1989-07-31, last updated 2026-04-27); since June 1, 2023, whois contact information is redacted by default (per a TWNIC announcement). 0523.tw's registrar and DNS host is Chunghwa Telecom HiNet. | Measures for the Administration of Internet Domain Names (MIIT Order No. 43, effective 2017-11-01): anyone providing domain-name services within mainland China must have their root servers, registry management system, registration service system and resolution system located within mainland China and duly licensed (Article 9); registration must include verified, true identity information (Article 30); resolution services must lawfully log and retain resolution logs (Article 36). |
It answers exactly one thing: which legal system governs 0523.tw's hosting and data — the answer is Taiwan law. The subjects covered by each provision differ (for example, the Taiwan NCC's restriction order on telecommunications and broadcasting operators binds only telecom and broadcasting operators, not consolidation companies directly; the in-country storage obligation under Article 39 of the Cybersecurity Law of the PRC applies to operators of critical information infrastructure). This page labels the covered subject for each provision, so please don't apply any single provision to every business. To be fair, it should also be said: Taiwan's telecom operators likewise have a statutory duty to assist with surveillance under the Communication Security and Surveillance Act — the difference lies in procedure (a court warrant) and scope, not in whether such a duty exists at all.
Beyond DNS and Hosting Location, What Other Protections Does HowBridge Have in Place?
Hosting in Taiwan is only the first layer. Below are the protective measures you can verify yourself from your browser or public tools, plus the parts we disclose ourselves but where you can only see the outcome (we don't publish the specifics of our defenses, so as not to hand attackers a map):
| Measure | Details | How You Can Verify It |
|---|---|---|
| Site-Wide HTTPS + HSTS | All pages force encryption; HSTS max-age is set to one year, includes subdomains, and the header carries a preload directive — once a browser remembers this, it will never connect to this site over plain HTTP again (checked hstspreload.org on 2026-09-22: eligible for submission, not yet on the browser preload list) | The response header strict-transport-security; look up 0523.tw on hstspreload.org |
| Automatic TLS Certificate Renewal | Let’s Encrypt certificates default to a 90-day validity period and renew automatically before expiry, so you'll never see a "certificate expired" warning | The padlock in the address bar › Certificate validity period |
| HTTP/3 and IPv6 | Supports QUIC (HTTP/3) and dual-stack IPv6, making it less likely to drop when switching mobile networks | Response header alt-svc: h3; dig AAAA 0523.tw |
| Content Security Policy (CSP) and Clickjacking Protection | Restricts pages to loading scripts and resources only from approved sources; prevents the site from being embedded in an iframe by other websites | Response headers content-security-policy and x-frame-options: DENY |
| Hosting Protections | Firewall allowlisting, intrusion detection with automatic blocking, application sandboxing, audit logging, malware scanning, live kernel patching; the database and cache are not open to external connections | Only the categories are disclosed, not the specific rules |
| Backups | Hourly database transaction logs plus daily AES-256-encrypted snapshots, with one copy kept locally on the server and another on a separate independent storage device (a NAS within Taiwan); snapshot integrity is checked weekly | Self-disclosed by HowBridge |
| Payments | Credit card payments are completed on the payment page of Taiwan payment processor NewebPay; LINE Pay and JKoPay are completed within their own apps; the card number is processed by the payment processor on its own payment page, and HowBridge's server never handles it | At payment time, the address bar switches to the payment processor's domain |
Publishing the details of our defenses doesn't help users, but it does save attackers reconnaissance time. This page only discloses which categories of measures exist and the parts you can verify yourself; if you're a security researcher and find a vulnerability, please report it via Contact Us.
How to Verify Yourself That HowBridge's DNS and Hosting Are in Taiwan? 4 Steps
You don't have to take our word for it — check the public records directly. The steps below work in the Terminal on both macOS and Linux; on Windows, you can use PowerShell's Resolve-DnsName, or use the web-based lookup from Step 1. The whole process requires no account login at all:
1Check the Registrar and Name Servers
Go to TWNIC's web lookup (whois.twnic.tw) and enter 0523.tw, or in a terminal type whois -h whois.twnic.net.tw 0523.tw (on most systems, simply typing whois 0523.tw will also be routed to the same server). Look at three fields: "Registration Service Provider" should read HINET; "Domain servers in listed order" should show admns1.hinet.net and admns2.hinet.net; and the Registrant should show as 好運器資訊有限公司 — HowBridge's registered company name — shown in the whois English-language field as Hao Yun Ci Information Limited Company.
2Check the IP the Authoritative DNS Returns
In a terminal, type dig NS 0523.tw to confirm the name servers, then type dig @admns1.hinet.net 0523.tw A to query the authoritative server directly; the ANSWER should be 114.32.86.150. Adding dig AAAA 0523.tw shows the IPv6 address (starting with 2001:b011:).
3Check Which Operator and Country the IP Belongs To
In a terminal, type whois 114.32.86.150 (or look it up on APNIC whois). You should see netname: HINET-NET, Chunghwa Telecom Co., Ltd., and country: TW. If a website's IP turns out to belong to a CDN or an overseas cloud provider, it means you're connecting to a proxy or an overseas data center, not the site's own server.
4Check the Certificate and Security Headers
Click the padlock in the browser's address bar to view the certificate: issuer Let’s Encrypt, name including 0523.tw. In a terminal, type curl -sI https://0523.tw/ to see headers such as strict-transport-security, content-security-policy and alt-svc: h3; check hstspreload.org for HSTS preload status.
whois and DNS records are live data; if HowBridge changes its line or name servers in the future, this page's "Last verified" date and content will be updated accordingly. If what you find doesn't match this page, please let us know via Contact Us, and we'll check and correct it.
What Doesn't This Page Cover? What Limitations Should You Know First?
No matter how clearly we explain "the domain and hosting are in Taiwan," that's still only part of data protection. Below are the things this page deliberately does not promise, or cannot yet deliver — stated upfront:
| Item | Current Status | Explanation |
|---|---|---|
| DNSSEC | This domain has not been signed yet (the .tw top-level domain itself has DNSSEC deployed) | HiNet's official FAQ for its free DNS hosting lists only five record types — A/AAAA/CNAME/MX/TXT — and doesn't mention zone signing; although the registrar's control panel has a DS record field, the hosting side would still need to sign the zone, which hasn't been done for this domain. DNSSEC protects against "tampering with resolution results" and has nothing to do with where data is stored; this page will be updated if it's enabled in the future |
| The Resolver on Your End | Determined by your device, router, or carrier | Which recursive resolver you use and what it logs is something HowBridge cannot see or control; if this matters to you, you can choose a resolver with a public privacy statement (for example, TWNIC's Quad101 supports DNSSEC, DoT and DoH, and its privacy policy states that temporary logs include the source IP and are kept for at most 30 days) |
| Operational Data at the Shenzhen Warehouse | The recipient information needed for shipping is processed at the Shenzhen warehouse | This is a necessary step of the consolidation service itself, handled under the Privacy Policy's "Cross-Border Data Transfer" section and limited to the minimum data necessary; this page avoids the word "absolute" |
| Third-Party Services Outside Taiwan | Google Fonts, cdnjs (icon fonts), Microsoft Clarity, LINE notifications, the email delivery service, and Google Street View for address verification | The font, icon and analytics services only load static assets or record anonymized interaction behavior, and cannot obtain your login credentials; LINE and email notification content is retained under the policies of LY Corporation (Japan) and Google (U.S.) respectively; Street View verification only sends the address or coordinates. None of the above is a China-based service |
| WeChat Customer Service Channel | HowBridge also offers a WeChat customer service account (Tencent, China) | Any message you choose to send us via WeChat passes through Tencent's servers — that's a contact method you've chosen, and it has nothing to do with the website's hosting or database; if you'd rather avoid it, you can use LINE, email, or on-site customer service instead |
| "Hosted in Taiwan" Does Not Equal "Immune to Intrusion" | No website can guarantee zero risk | Section 6 of this page lists categories of measures; we keep updating them, and welcome reports from security researchers |
| Government Certification | None | Records from Chunghwa Telecom, TWNIC and APNIC only prove "where the domain and hosting are, and who they belong to" — they are not certification or endorsement of HowBridge by any authority |
This page explains the technical setup and location; the purposes of data collection, retention periods, your rights, and the full terms on cross-border transfer are governed by the HowBridge Privacy Policy — if there is any discrepancy between the two, the Privacy Policy controls.
Terms Used on This Page
- DNS (Domain Name System)
- A distributed system that translates human-readable names like "0523.tw" into machine-usable IP addresses like "114.32.86.150"; the work is divided among root servers, top-level domain servers, authoritative name servers, and recursive resolvers.
- Authoritative Name Server (Authoritative DNS)
- The server that holds the "official answer" for a given domain. 0523.tw's authoritative name servers are HiNet's admns1.hinet.net and admns2.hinet.net; anywhere in the world, a lookup of this domain's IP ultimately has to ask them.
- Recursive Resolver
- The DNS server that performs lookups on behalf of your device, typically provided by your carrier (e.g., HiNet 168.95.1.1) or set by you; it caches answers, so a second lookup of the same domain is usually faster.
- Registrar
- The company that accepts domain applications and registers them with the registry on the customer's behalf. 0523.tw's registrar is Chunghwa Telecom HiNet (domain.hinet.net).
- .tw and TWNIC
- .tw is Taiwan's country-code top-level domain, managed by the Taiwan Network Information Center (TWNIC), a foundation; the web interface at whois.twnic.tw and the whois protocol server at whois.twnic.net.tw both offer public lookups for .tw domains.
- HiNet
- Chunghwa Telecom's internet service brand (operated by its Data Communication Business Group branch, as registered with APNIC), providing broadband internet access, domain registration, DNS hosting, and public DNS (168.95.1.1).
- IP Address Ownership (whois)
- Every public IP block is registered with a Regional Internet Registry; for the Asia-Pacific region, that's APNIC. Looking up 114.32.86.150 shows it belongs to Chunghwa Telecom, country TW.
- CDN (Content Delivery Network)
- A service that places proxy servers in many locations worldwide to respond from somewhere nearby. When a site uses a CDN, you connect to a CDN node rather than the site's own server; 0523.tw doesn't sit behind a CDN — its A record points directly to the Taiwan server.
- HTTPS/TLS
- The protocol that encrypts content between the browser and the server. Once encrypted, intermediate network nodes can only see which IP and port you're connecting to and the site name (SNI) — not your account, password, or page content.
- HSTS (HTTP Strict Transport Security)
- A response header a website uses to tell the browser "only ever connect to me over HTTPS from now on" (IETF RFC 6797); once added to the preload list, this rule ships built into the browser, so even the very first connection never goes over plain text (0523.tw already sends the preload header but is not yet on the list).
- DNSSEC
- Adds a digital signature to DNS responses so a resolver can verify the answer hasn't been tampered with (IETF RFC 4033); it requires the domain's DNS host to sign the zone and register a DS record with .tw. 0523.tw has not been signed yet.
- DoT (DNS over TLS)
- Carries DNS queries inside a TLS-encrypted channel (IETF RFC 7858), preventing them from being observed or tampered with in transit; it requires support from your resolver and has nothing to do with the website's side.
- DoH (DNS over HTTPS)
- Carries DNS queries inside HTTPS (IETF RFC 8484), achieving the same effect as DoT while using port 443.
- Data Localization
- A legal requirement that certain data be stored within a country's borders; whichever country data is stored in, it falls under that country's laws, including rules on lawful government access to data.
Sources and Limits of Verification
This page's domain, DNS, hosting and certificate information is based on live TWNIC whois, dig, APNIC whois and openssl checks performed on September 22, 2026; the data storage location and cross-border transfer information follows the current text of HowBridge's Privacy Policy; laws, official statistics and technical standards follow the primary sources listed below, each with a link to the original page and a verification date.
Government, Official and Standards Documents
- TWNIC .tw WHOIS Lookup (web whois.twnic.tw / protocol server whois.twnic.net.tw) — 0523.tw (retrieved 2026-09-22): “Domain servers in listed order: admns1.hinet.net admns2.hinet.net”“Registration Service Provider: HINET”“Registration Service URL: https://domain.hinet.net”「Registrant: 好運器資訊有限公司 / Hao Yun Ci Information Limited Company」“Record created on 2025-08-13”“Record expires on 2027-08-13”; per TWNIC policy, contact information shows as “(Redacted for privacy)”. Hao Yun Ci Information Limited Company is HowBridge's registered Taiwan entity.
- APNIC WHOIS — 114.32.86.150 (retrieved 2026-09-22): "netname: HINET-NET" "descr: Data Communication Business Group, Chunghwa Telecom Co.,Ltd." "country: TW"; reverse DNS hostname 114-32-86-150.hinet-ip.hinet.net, AS3462.
- HiNet Domain Registration "DNS and Redirection" FAQ (domain.hinet.net) (retrieved 2026-09-22): "This service allows up to 20 DNS records to be configured," "Supports A, MX, CNAME, TXT and AAAA records," "Takes effect within about 24 hours after DNS settings are configured"; the footer reads "© Chunghwa Telecom Co., Ltd. All rights reserved — HiNet Internet Service by Chunghwa Telecom." The official page does not list the name servers' hostnames; admns1/admns2.hinet.net are based on whois and dig results.
- Chunghwa Telecom "About CHT" (retrieved 2026-09-22): "Chunghwa Telecom is the largest integrated telecom operator in Taiwan. Our core businesses cover fixed-line communications, mobile communications, and broadband access and internet services"; 2025 Form 20-F (filed with the U.S. SEC): "incorporated on July 1, 1996" "We are the largest telecommunications service provider in Taiwan"; stock code 2412 (Taiwan Stock Exchange).
- Chunghwa Telecom 2025 Annual Report (retrieved 2026-09-22): "As of the end of December in Year 114 of the Republic of China calendar, HiNet's broadband internet subscriber market share was 52.2%" (i.e., end of December 2025; an ISP-account market share calculated by Chunghwa Telecom itself, not a figure published by the regulator); "HiNet's network employs multi-path routing with a highly reliable network redundancy mechanism … for international routing, it distributes traffic across multiple submarine cable systems."
- Chunghwa Telecom Q2 2026 Operating Results Press Release (2026-08-05) (retrieved 2026-09-22): "As of end of June 2026, Chunghwa Telecom had 4.47 million broadband subscribers, up 0.6% year over year; HiNet had 3.82 million broadband subscribers, up 1.5% year over year" "Subscribers on plans of 1 Gbps or above grew 61% year over year."
- National Communications Commission (NCC) Order No. Tongchuan-Pingtai-Zi 11241012010 of June 5, 2023 (ROC Year 112) (retrieved 2026-09-22): "This Commission finds your company (Chunghwa Telecom) to hold significant market power in the fixed-network voice retail service market, the fixed-network broadband retail service market, the fixed-network wholesale service market … " (under Article 27, Paragraph 1 of the Telecommunications Management Act, among other provisions). "Holding significant market power" is a regulatory concept that only demonstrates market scale, not service quality.
- Executive Yuan Taiwan at a Glance, "Telecommunications" (retrieved 2026-09-22): "In ROC Year 113, Taiwan had 37.40 million broadband accounts, of which 7.07 million were fixed-line broadband (ADSL, FTTx, Cable Modem and Leased Line)" (ROC Year 113 = 2024); NCC, Communications Market Report for ROC Year 114: "Fixed-line broadband accounts … rose from 5.66 million in ROC Year 104 to 7.07 million in ROC Year 113; fixed-line broadband penetration … rose from 66.8% in ROC Year 104 to 74.5% in ROC Year 113" (ROC Years 104–113 = 2015–2024). The NCC has not published individual operators' fixed-line broadband market shares.
- TWNIC, 2025 Taiwan Internet Report (retrieved 2026-09-22): "The total sample size was 2,142, with a sampling error of approximately ±2.99 percentage points at a 95% confidence level" "In 2025, Taiwan's internet usage rate among the public was 88.75%" "Fixed-line broadband subscriber penetration was 69.77%"; the report did not survey ISP brand distribution or DNS usage.
- IANA Delegation Record for .TW (retrieved 2026-09-22): "ccTLD Manager: Taiwan Network Information Center (TWNIC)" "WHOIS Server: whois.twnic.net.tw" "Registration date 1989-07-31" "Record last updated 2026-04-27"; the .tw top-level domain has published a DNSSEC DS record (per dig DS tw. run from the server itself: 46902 13 2 …); 0523.tw itself has no DS record.
- Root Server Technical Operations Association (root-servers.org) Site Data (retrieved 2026-09-22): Taiwan hosts 7 root-server letters — D, E, F, I, K, L, M — across 10 sites (Taipei, New Taipei, Kaohsiung); the database does not indicate the hosting organization.
- TWNIC Quad101 Public DNS Service and Privacy Policy (effective 2025-08-04) (retrieved 2026-09-22): "Quad101 is a DNS resolution service operated by the Taiwan Network Information Center (TWNIC)" "DNSSEC, DoH and DoT are enabled"; Privacy Policy: "Temporary DNS logs … source and destination IP addresses and port numbers; query type and domain name; timestamp" "retained for a maximum of thirty (30) days" "individual user data is not sold or shared."
- TWNIC, "Announcement on Adjusting the Disclosure of WHOIS Lookup Results for .tw and Its Chinese-Character Domain" (2023-04-21) (retrieved 2026-09-22): "Starting from June 1 of ROC Year 112 … a domain name's contact information will default to non-disclosure" (ROC Year 112, June 1 = 2023-06-01) "It is recommended to use role-based or department-based contact information instead" — this is the basis for whois displaying "(Redacted for privacy)."
- Personal Data Protection Act (Taiwan) (Laws & Regulations Database of the Republic of China) (retrieved 2026-09-22): the current version in force (amended 2023-05-31): Article 8: when collecting personal data from the data subject, must clearly disclose "the period, region, recipients and method of use of the personal data"; Article 20: a non-government agency's use of personal data "shall be within the necessary scope of the specific purpose for which it was collected"; Article 21: when a non-government agency transfers personal data internationally, if any one of the following applies — "it involves a major national interest," "an international treaty or agreement contains a special provision," "the receiving country lacks adequate laws to protect personal data, risking harm to the data subject's rights," or "personal data is transferred to a third country/region by an indirect method to circumvent this Act" — the central competent authority "may restrict it"; Article 27: "shall adopt appropriate security measures to prevent personal data from being stolen, altered, damaged, destroyed or disclosed." ⚠️ A 2025-11-11 amendment (deleting Article 27 and adding Article 20-1 and Articles 21-1 through 21-5) has been promulgated, with the effective date to be set by the Executive Yuan; it had not yet taken effect as of the verification date.
- Enforcement Rules of the Personal Data Protection Act, Article 12 (retrieved 2026-09-22): "appropriate security measures" means … technical and organizational measures adopted to prevent personal data from being stolen, altered, damaged, destroyed or disclosed," which may include any of eleven items such as "data security management and personnel management," "equipment security management," "a data security audit mechanism," and "retention of usage records, audit trails and evidence."
- National Communications Commission (NCC) Order No. Tongchuan-Tongxun-Zi 10141050780 of September 25, 2012 (ROC Year 101) (retrieved 2026-09-22): "In view of the fact that mainland China's personal data protection laws are not yet complete … pursuant to Article 24, Paragraph 3 of the (then) Computer-Processed Personal Data Protection Act, telecommunications and broadcasting operators are restricted from transmitting their subscribers' personal data to mainland China" (Executive Yuan Gazette, Vol. 18, Issue 184). The subject bound by this order is telecommunications and broadcasting operators; its legal basis was Article 24, Paragraph 3 of the then Computer-Processed Personal Data Protection Act (equivalent to Article 21, Paragraph 3 of the current Personal Data Protection Act).
- Cyber Security Management Act (amended 2025-09-24, effective 2025-12-01) (retrieved 2026-09-22): Article 2: "the competent authority for this Act is the Ministry of Digital Affairs"; Article 3, Item 11: "products that endanger national cybersecurity: refers to information and communication systems, services or products that the competent authority has determined pose a direct or indirect risk of harm to national cybersecurity …"; Article 11: "government agencies may not download, install or use products that endanger national cybersecurity"; Article 27: for specific non-government agencies, the authority "may restrict or prohibit" such use. The subjects covered are government agencies and specific non-government agencies. Also, Regulations on the Review of Products That Endanger National Cybersecurity (promulgated 2025-12-19), Article 4: "where a reported information and communication system, service or product is of a mainland Chinese brand, the competent authority may proceed directly with intelligence sharing under Article 5." The former "Principles for Agencies' Restriction on the Use of Products That Endanger National Cybersecurity" ceased to apply on 2026-01-15.
- Personal Data Protection Commission Preparatory Office (retrieved 2026-09-22): "The Executive Yuan, in order to prepare for the establishment of the Personal Data Protection Commission … has specially established the Personal Data Protection Commission Preparatory Office"; as of the verification date it was still operating under the name of the preparatory office (a notice was still issued under that name on 2026-03-09), and no promulgated organic law was found in the Laws & Regulations Database.
- Telecommunications Management Act, Articles 8 and 9 (retrieved 2026-09-22): Article 8, Paragraph 1: "when a telecom operator provides telecom services … (4) it shall adopt appropriate and necessary measures to protect the confidentiality of communications"; Article 9: "for a subscriber's … call records and billing records generated from the use of telecom services, a telecom operator shall ensure the records are accurate, retained for a set period, and kept confidential" "telecom operators and operators of public telecommunications networks have a duty, under the Communication Security and Surveillance Act, to assist in executing communication surveillance and in retrieving call records and subscriber information."
- Communication Security and Surveillance Act, Articles 5 and 11-1 (retrieved 2026-09-22): Article 5: "where there are facts sufficient to find that the defendant or suspect is implicated in one of the enumerated offenses, that it seriously endangers national security or economic or social order, that there is reasonable cause to believe the communication content is related to the case, and that evidence cannot or can hardly be gathered or investigated by other means, a communication surveillance warrant may be issued"; Article 11-1: "where a prosecutor, in investigating a crime and gathering evidence, finds facts sufficient to establish that call records or internet traffic records are necessary and relevant to the investigation, the prosecutor shall apply in writing to the competent court for a retrieval warrant, except in urgent circumstances where a prior application is not feasible" (for certain serious offenses, a prosecutor may retrieve records ex officio; when retrieved urgently, a follow-up application must be filed within twenty-four hours).
- Cybersecurity Law of the People's Republic of China (amended 2025-10-28, effective 2026-01-01; text as promulgated by the National People's Congress, republished by the Cyberspace Administration of China) (retrieved 2026-09-22): "Article 30: Network operators shall provide technical support and assistance to public security organs and state security organs for their lawful activities to safeguard national security and investigate crimes." "Article 39: Personal information and important data collected and generated by operators of critical information infrastructure during operations within the People's Republic of China shall be stored within the country. Where it is genuinely necessary to provide such data overseas due to business needs, a security assessment shall be conducted in accordance with measures formulated by the national cyberspace administration together with relevant departments of the State Council." Before the amendment (the 2016 version), the corresponding article numbers were Articles 28 and 37.
- Data Security Law of the People's Republic of China (effective 2021-09-01; National People's Congress website) (retrieved 2026-09-22): "Article 35: Where public security organs or state security organs need to retrieve data for the lawful purposes of safeguarding national security or investigating crimes, they shall do so in accordance with relevant national regulations, through strict approval procedures and in accordance with the law; the relevant organizations and individuals shall cooperate." "Article 36: … Without the approval of the competent authorities of the People's Republic of China, organizations and individuals within the country may not provide data stored within the People's Republic of China to foreign judicial or law-enforcement bodies."
- Personal Information Protection Law of the People's Republic of China (effective 2021-11-01; National People's Congress website) (retrieved 2026-09-22): "Article 38: Where a personal information handler genuinely needs to provide personal information outside the People's Republic of China due to business or other needs, it shall meet one of the following conditions: (1) … pass a security assessment organized by the national cyberspace administration; (2) … obtain personal information protection certification from a professional institution; or (3) enter into a contract with the overseas recipient using a standard contract formulated by the national cyberspace administration." "Article 39: … shall inform the individual of the overseas recipient's name, contact information, and purpose of processing … and obtain the individual's separate consent." "Article 40: Operators of critical information infrastructure and personal information handlers who process personal information in a volume specified by the national cyberspace administration shall store, within the country, the personal information they collect and generate within the People's Republic of China."
- National Intelligence Law of the People's Republic of China (effective 2017-06-28, amended 2018-04-27; National People's Congress website) (retrieved 2026-09-22): "Article 7: All organizations and citizens shall support, assist and cooperate with national intelligence work in accordance with the law, and shall keep confidential any national intelligence work secrets that come to their knowledge." "Article 8: National intelligence work shall be carried out in accordance with the law, shall respect and protect human rights, and shall safeguard the lawful rights and interests of individuals and organizations." "Article 14: National intelligence work institutions, in lawfully carrying out intelligence work, may require relevant agencies, organizations and citizens to provide necessary support, assistance and cooperation."
- Measures for the Administration of Internet Domain Names (MIIT Order No. 43, effective 2017-11-01; Chinese government website) (retrieved 2026-09-22): "Article 2: These Measures shall be observed by anyone engaging in internet domain name services, and related operation, maintenance and supervisory activities, within the People's Republic of China." "Article 9: Anyone establishing a domain name root server and its operating body, a domain name registry, or a domain name registration service provider within the country shall obtain the corresponding license under these Measures" (the conditions for establishment include "the domain name root server being located within the country," "the domain name management system being located within the country," and "the domain name registration service system, registration database and corresponding resolution system being located within the country") "Article 30: … shall require the domain name registration applicant to provide the true, accurate and complete identity information of the domain name holder" "Article 36: Anyone providing domain name resolution services … shall lawfully record and retain resolution logs, maintenance logs and change records."
- IETF RFC 1034 Domain names – concepts and facilities, RFC 1035, RFC 4033 DNS Security Introduction and Requirements, RFC 7858 DNS over TLS, RFC 8484 DNS Queries over HTTPS, RFC 6797 HTTP Strict Transport Security (retrieved 2026-09-22): the definitions of DNS, DNSSEC, DoT, DoH and HSTS in this page's glossary are based on these.
- Let’s Encrypt FAQ (retrieved 2026-09-22): "Our default certificates are valid for 90 days" "We recommend renewing 90 day certificates every 60 days"; a short-lived 6-day certificate option is also available. This site's certificate: issuer Let’s Encrypt (CN=YE2), covering 0523.tw and www.0523.tw, valid through 2026-10-23 (per an openssl s_client check on 2026-09-22).
- hstspreload.org — 0523.tw (retrieved 2026-09-22): the status API returns "status: unknown" (not yet on the Chromium preload list), and the eligibility API returns "errors: [], warnings: []" (eligible for submission); this site's response header is "strict-transport-security: max-age=31536000; includeSubDomains; preload."
- Chunghwa Telecom Press Release (2019-01-30) and HiNet IPv6 Subscriber Connection Reference Manual (retrieved 2026-09-22): "Chunghwa Telecom DNS service (168.95.1.1 and 168.95.192.1)"; manual: "Fixed DNS service host addresses … IPv4: 168.95.1.1 and 168.95.192.1; IPv6: 2001:b000:168::1 and 2001:b000:168::2." HiNet has not officially announced that its public DNS supports DoT/DoH.
Academic and Research Literature
Comparing DNS Resolvers in the Wild
An active-measurement study across 28 countries and 50 ISPs: for well-provisioned ISPs, the minimum response latencies for the local ISP resolver, OpenDNS, and Google DNS were 11 ms, 24 ms, and 44 ms respectively (p. 17, §4.1, Fig. 1); the paper concludes that "the latency from a user to a local ISP resolver is usually very small" (p. 21). This is the academic basis for this page's approach of keeping the resolver and the website on the same Taiwan backbone for proximity.
Content Delivery and the Natural Evolution of DNS: Remote DNS Trends, Performance Issues and Alternative Solutions
A measurement of 10,923 end hosts across 99 countries: when a remote/public DNS is used, CDNs often route users to farther nodes, increasing median end-to-end latency by 60%, with up to a 3x increase at one-fifth of locations (p. 524). This site's A record points directly to the Taiwan server without any CDN-based geo-routing, so Taiwan-based users are never routed to an overseas node based on resolver location.
Recursives in the Wild: Engineering Authoritative DNS Servers
One of the few measurement studies to directly examine "authoritative server location": roughly half of recursive resolvers prefer a closer authoritative server based on latency, with the preference growing stronger as the gap widens (p. 490, §4.2–4.3), and the paper notes that DNS can be a perceptible portion of web page latency (p. 489). 0523.tw's authoritative servers, admns1/admns2.hinet.net, sit within HiNet's own network — the nearest choice for a Taiwan-based resolver.
Cache Me If You Can: Effects of DNS Time-to-Live
After Uruguay's .uy lengthened the TTL of its DNS records, median query latency dropped from 183 ms to 28.7 ms (pp. 101–102; §5.3); the authors recommend a TTL of at least 1 hour, and ideally 4 to 24 hours, for typical domains (p. 112). This site does not rely on a CDN's dynamically short TTLs, so its records can be cached long-term by resolvers everywhere — one reason a direct connection to the server can still be fast.
Tracked Without a Trace: Linking Sessions of Users by Unsupervised Learning of Patterns in Their DNS Traffic
DNS query data from 3,862 real users: even when an ISP rotates IPs daily, 73% of highly active users had nearly all of their sessions linkable together within 56 days, and 19% could be fully tracked (p. 23). DNS query logs themselves can reconstruct a person's browsing behavior, so "whose resolver and authoritative server can see your queries, and in which jurisdiction" is a privacy issue, not just a speed issue.
Privacy issues in the Domain Name System and techniques for self-defense
Points out that resolver operators can see every domain a user queries, and that law enforcement can readily obtain the query logs typically retained by resolvers (p. 388). This explains why this page separates "which country the authoritative DNS is in" from "which resolver you personally use": the former is something HowBridge can decide (Taiwan), while the latter is a choice on your end.
DNS Privacy Considerations (RFC 9076)
The IETF's document on DNS privacy considerations: §6.1 and §6.2 explain that both recursive resolvers and authoritative name servers can see queries, and §7.1 explains the risk of re-identifying individuals from queries. This site's authoritative servers are on HiNet, meaning that records of Taiwan-based users' queries for 0523.tw never end up on an authoritative server overseas (§6.2).
Consolidation in the DNS resolver market – how much, how fast, how dangerous?
Explicitly frames "which jurisdiction the resolver is in" as a privacy risk: public resolvers are mostly operated by U.S. companies, and "users' data is often collected and processed outside the jurisdiction the user belongs to" (p. 58); consolidation ties together technical, economic and political (jurisdictional, sovereignty) risks (p. 57). Sections 4 and 5 of this page make exactly this argument — that where data sits determines which law applies.
Hacking into China’s Cybersecurity Law
A law-journal, article-by-article analysis of the Cybersecurity Law of the PRC: Article 28 (the 2016 article number, renumbered Article 30 after the 2025 amendment) requires network operators to provide technical support and assistance to public security and state security organs for national-security and crime-investigation activities (p. 72); Article 37 (now Article 39) requires operators of critical information infrastructure to store personal information and important data domestically, which the author calls "the most controversial provision" (p. 79); and the paper notes that data localization is often used as a tool to facilitate domestic surveillance or law enforcement (p. 78). This page's mainland China column in Section 5 uses this as an academic footnote, with each provision's covered subject labeled as in the original text.
China’s emerging data protection framework
A recent peer-reviewed analysis of the Data Security Law and the Personal Information Protection Law: the Data Security Law imposes a duty on individuals and organizations to cooperate when public security and state security organs obtain data in the course of their duties; the Personal Information Protection Law does not impose meaningful limits on state data collection; and data leaving the country requires a security assessment, certification, or standard contract via the Cyberspace Administration of China. This page cites it in Section 5's "Operators' Duty to Cooperate with Government Authorities" and "Cross-Border Transfer Restrictions" rows.
Data Nationalism
A comparative study of data-localization regimes across 17 countries, which objectively records that Article 21 of Taiwan's Personal Data Protection Act allows the competent authority to restrict international transfers in situations such as a major national interest or inadequate protection in the receiving country (p. 708). In fairness: the authors' own position opposes "mandatory" localization; HowBridge voluntarily keeps its domain, hosting and data in Taiwan — we are not advocating mandatory legislation — and we cite this paper only for its record of Taiwan's legal framework.
Cross-border e-commerce: consumers’ intention to shop on foreign websites
An empirical study from National Taipei University (449 valid responses, 343 of them from Taiwan): the seller country's "legal structure" had a coefficient of β = 0.196 on consumer trust, and "national integrity" a coefficient of β = 0.195, both significant (HICSS version, Table 2, p. 3987). This is the only Taiwan-sample empirical evidence for this page's point that "having hosting, DNS and the database under Taiwan's legal jurisdiction is a trust signal"; this page does not claim from this alone that consumers generally care about where data is stored.
The digital divide in state vulnerability to submarine communications cable failure
Submarine cables carry about 98% of international internet traffic, with an average of roughly 100 human-caused or natural disruptions per year (p. 1); the paper cites the simultaneous failure of multiple cables near Taiwan in December 2006 as an example (p. 4). Since the domain, DNS and hosting are all within Taiwan, a Taiwan-based user connecting to this site never depends on a submarine cable — cable incidents affect cross-border connections.
Experience with Restoration of Asia Pacific Network Failures from Taiwan Earthquake
The earthquake off Taiwan's coast on December 26, 2006 severed multiple submarine cables, splitting the Asia-Pacific research network into eastern and western groups (chapter p. 362); at the time, most East Asian submarine cables ran through waters southwest of Taiwan (p. 366). Historical evidence that when submarine cables fail, it's cross-border connections that are affected — direct domestic connections are unaffected.
Use of DNS Resolvers for Taiwan (TW) — APNIC Labs measurement
In the Taiwan sample from September 19, 2026: 7.74% of queries were handled by Google Public DNS and 2.48% by Cloudflare, with every other public resolver below 0.1% — meaning roughly nine in ten Taiwan users' queries go through their own ISP's resolver; for HiNet specifically (AS3462, 72,128 samples), the figures were 6.54% and 3.26% respectively. This site's placement of its authoritative DNS on HiNet matches the actual resolution path of Taiwan-based users.
① whois and DNS records are live data that can change at any time; this page only guarantees the state as of the "last verified" date. ② IP ownership can only prove the operator and country; the city where the server sits is self-disclosed by HowBridge. ③ Our own measurements are 12 samples from a single location, single line and single time window, useful only as a rough order of magnitude. ④ The comparison of Taiwan and mainland China law excerpts only the provisions directly relevant to data storage, government access, and cross-border transfer; each provision's covered subject differs and has been labeled individually — this does not constitute legal advice. ⑤ The details of data processing at the Shenzhen warehouse follow the Privacy Policy; this page makes no separate promises about them. ⑥ Data processing by third-party services (fonts, icons, analytics, notifications, Street View for address verification) follows each provider's own privacy statement. ⑦ This domain has not yet signed DNSSEC, and HSTS has not yet been added to browsers' preload lists (see Section 8 of this page). ⑧ Email notifications are delivered via Google (U.S.), LINE notifications via LY Corporation (Japan), and WeChat customer service via Tencent (China) — these are all notification or contact channels you've chosen, unrelated to the website's hosting or database. ⑨ Our own measurement point is in the same city (Taoyuan) and on the same ISP as the server, which is close to a best-case scenario. ⑩ The Privacy Policy separately retains a general clause stating that "some data may be stored in certified data centers in other jurisdictions"; this was not the case as of the verification date, and if it changes in the future, the Privacy Policy governs.
Frequently Asked Questions
Is HowBridge's DNS really on Chunghwa Telecom?
Where is the website's server located?
Will my personal data go to China?
Why not use Cloudflare or another CDN? Wouldn't that be faster?
Does using an overseas public DNS (e.g., 8.8.8.8) to connect to HowBridge make any difference?
Does the site have DNSSEC?
Can Chunghwa Telecom see my member data?
Does hosting in Taiwan mean the site is secure?
If I'm physically in mainland China, what path does my connection to 0523.tw take?
Will these records change in the future? What happens if they do?
Further Reading
Privacy Policy
Recipient Address House-Number Verification: Passing Ministry of the Interior TGOS Review
LINE Official Account Verification and Anti-Fraud Identification
The Complete Guide to Avoiding Cross-Border Shopping Scams
The Complete Beginner's Guide to Taiwan Consolidation
HowBridge iPhone/iPad App: Features and Download Guide
About HowBridge
The Database Is in Taiwan — Your Package Arrives with Peace of Mind
The domain, DNS, hosting, database and backups are all on Chunghwa Telecom's network in Taiwan; you can verify it yourself using this page's 4 steps before deciding whether to trust us with your package.
Sign Up Free and Start Consolidating