Welcoming the Nepalese Government to Have I Been Pwned
115 points - yesterday at 9:52 PM
Sourceamritananda
yesterday at 10:11 PM
This is good news considering the current state of government run IT services in Nepal (that the page to schedule a passport renewal appointment requires you change your local timezone or override TZ to Asia/Kathmandu should tell you the state of some of these services).
In having to interact with Nepali government websites I've noticed things like endpoints not even doing basic input sanitization, letting your run arbitrary queries on biometric data. Asking around the tech industry on how to report this it seems like this is a common occurrence. Someone even found a vulnerability that was apparently purposefully unpatched to most likely aid in corruption.
waschl
yesterday at 10:17 PM
First thought was: ouch, government data got leaked and added to the database.
bordercontrol
yesterday at 11:02 PM
Please make it possible to change email addresses, so I don't have to create a new account and verify all domains again. Thank you for the great free service.
I do like the idea behind Have I Been Pwned, and honestly if a government took it over that might be nice if we had some guarantees. It feels like something that ought to be a public service with super duper special oversight to avoid it being used by law enforcement(since sending any information is necessarily bad)
> if a government took it over that might be nice
> to avoid it being used by law enforcement
What?
inigyou
yesterday at 10:14 PM
Is this the new government after the old one was violently overthrown last year?
bcraven
yesterday at 10:53 PM
I know of no other governments of Nepal.
Yes, this is the new government elected in March of this year after the old one was overthrown in September of last year.
You should at least attempt to ask an LLM for advice before asking a question that contributes nothing and only takes away value from a conversation like this.
Personally I'd recommend Fable or Kimi K3. Have you tried them yet? They're better at your job than you could ever be, even in theory.
viccis
yesterday at 10:36 PM
Seems like an almost irresponsibly misleading headline.
lucb1e
yesterday at 11:14 PM
Are you reading it as if the Nepalese government had a data breach? Given the positive connotation of 'welcoming', I read it differently but I can see the confusion indeed
fn-mote
yesterday at 11:27 PM
I also read the title as a sardonic welcome (negative connotation). I was surprised to find out it was just a tiny puff piece of self-promotion.
Being โwelcomedโ to HIBP sounds a lot like being โwelcomedโ to the Bronx by a mugging.
I admit I do not follow HIBP and was unaware of this kind of outreach they do.
greenhat76
yesterday at 11:11 PM
Well Troy Hunt makes money off the back of your data being leaked so I expect nothing less.
saghm
yesterday at 11:18 PM
I'm pretty certain that my data would be leaked regardless of him, so as far as objectionable businesses go, his is pretty low on my list of ones to be upset about
In some sense companies that don't protect your data make money off the back of your data being leaked (in the sense that they saved money by not spending it on security)
lucb1e
yesterday at 11:13 PM
And police officers make a living off of crime; ambulance personnel wouldn't get paid if nobody got sick or injured. What's the point of that observation?
subscribed
today at 2:22 AM
Police officers help for free.
If they find during an investigation that you're avictim of a crime they WILL tell you where they found the data and what was exactly in it.
Troy? He'll basically resell you your own stolen data, because that's the only way to know if the password leaked was 20 years or 1 month old, and to what services exactly. If you're leaked in infostealer dump, you'd learn from the police what was associated with your email in this dump, so you know to snort if it was only empty password store from your Firefox, or financial data exposing you to ruin.
Troy? Oh, he can tell you that too, but for a price. He'll sell you your personal data back.
(I've looked far and wide and there doesn't seem to be ANY way to list as much as the domains of the email/password dumps without paying for access to the API)
niteshpant
today at 3:02 AM
[dead]