This is good news considering the current state of government run IT services in Nepal (that the page to schedule a passport renewal appointment requires you change your local timezone or override TZ to Asia/Kathmandu should tell you the state of some of these services).
In having to interact with Nepali government websites I've noticed things like endpoints not even doing basic input sanitization, letting your run arbitrary queries on biometric data. Asking around the tech industry on how to report this it seems like this is a common occurrence. Someone even found a vulnerability that was apparently purposefully unpatched to most likely aid in corruption.
That's the case for most countries in Asia and Africa, from my travel experience. I would spot vulnerabilities that leak extremely sensitive data all the time, just by using the services normally and legally. You immediately see that the verification is broken without even having to investigate. I don't investigate or report them, as it might lead to problems.
One of the good things about these attacks is that it publicizes failings and gives data to good actors inside the government to drive reform. Surely other operators (Intel services of China, India, Pakistan, etc...; criminal syndicates) have been inside these systems for years so it's nice for the cybersecurity agency to have tools to make it clear where they're exposed.
I've started email the customer support of pages that have overzealous CF settings saying that it's a pain and that if they want to keep me as a customer they need to fix it.
Most give a canned response of "we can't do anything" ̄\_(ツ)_/ ̄ but some small sites do something. GitLab has the most annoying CF bouncer and I moved my company off them once I got the we can't do anything about it response.
Humble quite frequently locks me out with theirs and all support ever does is “have you updated your browser and restarted your router?” - it’s clear the agent has no idea what a cloudflare is and it’s not in their list of acceptable escalation reasons
Please make it possible to change email addresses, so I don't have to create a new account and verify all domains again. Thank you for the great free service.
And police officers make a living off of crime; ambulance personnel wouldn't get paid if nobody got sick or injured. What's the point of that observation?
If they find during an investigation that you're avictim of a crime they WILL tell you where they found the data and what was exactly in it.
Troy? He'll basically resell you your own stolen data, because that's the only way to know if the password leaked was 20 years or 1 month old, and to what services exactly. If you're leaked in infostealer dump, you'd learn from the police what was associated with your email in this dump, so you know to snort if it was only empty password store from your Firefox, or financial data exposing you to ruin.
Troy? Oh, he can tell you that too, but for a price. He'll sell you your personal data back.
(I've looked far and wide and there doesn't seem to be ANY way to list as much as the domains of the email/password dumps without paying for access to the API)
OK, I have no idea what are you on about, your vague generalisations attempt to throw the entire effort of this branch on me, so I'll just pass, it's not worth any more of my time.
I'm pretty certain that my data would be leaked regardless of him, so as far as objectionable businesses go, his is pretty low on my list of ones to be upset about
In some sense companies that don't protect your data make money off the back of your data being leaked (in the sense that they saved money by not spending it on security)
Are you reading it as if the Nepalese government had a data breach? Given the positive connotation of 'welcoming', I read it differently but I can see the confusion indeed
I do like the idea behind Have I Been Pwned, and honestly if a government took it over that might be nice if we had some guarantees. It feels like something that ought to be a public service with super duper special oversight to avoid it being used by law enforcement(since sending any information is necessarily bad)
Ehhhh, which government? Why would you want to build 200+ separate services for this? Would the US government report to a french citizen? Would we have two separate services from France/US?
I agree public services are great but let governments focus on more critical services.
Most people don't trust their government enough to run a service like this. For example, my government lets bridges collapse[0], and it can barely keep the roads paved. The fact that any government service works at all is nothing short of a miracle to me.
This is good news considering the current state of government run IT services in Nepal (that the page to schedule a passport renewal appointment requires you change your local timezone or override TZ to Asia/Kathmandu should tell you the state of some of these services).
In having to interact with Nepali government websites I've noticed things like endpoints not even doing basic input sanitization, letting your run arbitrary queries on biometric data. Asking around the tech industry on how to report this it seems like this is a common occurrence. Someone even found a vulnerability that was apparently purposefully unpatched to most likely aid in corruption.
That's the case for most countries in Asia and Africa, from my travel experience. I would spot vulnerabilities that leak extremely sensitive data all the time, just by using the services normally and legally. You immediately see that the verification is broken without even having to investigate. I don't investigate or report them, as it might lead to problems.
One of the good things about these attacks is that it publicizes failings and gives data to good actors inside the government to drive reform. Surely other operators (Intel services of China, India, Pakistan, etc...; criminal syndicates) have been inside these systems for years so it's nice for the cybersecurity agency to have tools to make it clear where they're exposed.
I'm surprised they can get past the CF captcha, I still can't. Ever since the beginning: https://imgur.com/a/AzNSreV
It provides me relief that I am not the only one suffering from Clownfair bot protection running amok. Condolences to you.
I've started email the customer support of pages that have overzealous CF settings saying that it's a pain and that if they want to keep me as a customer they need to fix it.
Most give a canned response of "we can't do anything" ̄\_(ツ)_/ ̄ but some small sites do something. GitLab has the most annoying CF bouncer and I moved my company off them once I got the we can't do anything about it response.
Humble quite frequently locks me out with theirs and all support ever does is “have you updated your browser and restarted your router?” - it’s clear the agent has no idea what a cloudflare is and it’s not in their list of acceptable escalation reasons
Someone said services like Twitter, FB or Instagram are walled gardens. Cloudflare said "Hold my beer".
I am annoyed by bots, but I am even more annoyed by the internet being less open and less accessible every day.
The secret is to never click on the check box. Click anywhere else. I haven't been stuck at the captcha in ages due to that.
First thought was: ouch, government data got leaked and added to the database.
Please make it possible to change email addresses, so I don't have to create a new account and verify all domains again. Thank you for the great free service.
Is this the new government after the old one was violently overthrown last year?
I know of no other governments of Nepal.
Yes, this is the new government elected in March of this year after the old one was overthrown in September of last year.
Viva Nepal !!!
Seems like an almost irresponsibly misleading headline.
https://www.troyhunt.com/tag/government/
It's a pattern that is used for new welcomes.
Well Troy Hunt makes money off the back of your data being leaked so I expect nothing less.
And police officers make a living off of crime; ambulance personnel wouldn't get paid if nobody got sick or injured. What's the point of that observation?
Police officers help for free.
If they find during an investigation that you're avictim of a crime they WILL tell you where they found the data and what was exactly in it.
Troy? He'll basically resell you your own stolen data, because that's the only way to know if the password leaked was 20 years or 1 month old, and to what services exactly. If you're leaked in infostealer dump, you'd learn from the police what was associated with your email in this dump, so you know to snort if it was only empty password store from your Firefox, or financial data exposing you to ruin.
Troy? Oh, he can tell you that too, but for a price. He'll sell you your personal data back.
(I've looked far and wide and there doesn't seem to be ANY way to list as much as the domains of the email/password dumps without paying for access to the API)
You seem to have wildly different experiences with police than most
I'm talking specifically about this specific kind of crime, don't generalise my statement.
Touchy touchy.
You’d have to be a celebrity to get a call from any police force I’ve ever seen, for even this type of crime.
OK, I have no idea what are you on about, your vague generalisations attempt to throw the entire effort of this branch on me, so I'll just pass, it's not worth any more of my time.
Also because of the other reason.
I'm pretty certain that my data would be leaked regardless of him, so as far as objectionable businesses go, his is pretty low on my list of ones to be upset about
In some sense companies that don't protect your data make money off the back of your data being leaked (in the sense that they saved money by not spending it on security)
Are you reading it as if the Nepalese government had a data breach? Given the positive connotation of 'welcoming', I read it differently but I can see the confusion indeed
I also read the title as a sardonic welcome (negative connotation). I was surprised to find out it was just a tiny puff piece of self-promotion.
Being “welcomed” to HIBP sounds a lot like being “welcomed” to the Bronx by a mugging.
I admit I do not follow HIBP and was unaware of this kind of outreach they do.
I do like the idea behind Have I Been Pwned, and honestly if a government took it over that might be nice if we had some guarantees. It feels like something that ought to be a public service with super duper special oversight to avoid it being used by law enforcement(since sending any information is necessarily bad)
> if a government took it over that might be nice
> to avoid it being used by law enforcement
What?
Ehhhh, which government? Why would you want to build 200+ separate services for this? Would the US government report to a french citizen? Would we have two separate services from France/US?
I agree public services are great but let governments focus on more critical services.
Most people don't trust their government enough to run a service like this. For example, my government lets bridges collapse[0], and it can barely keep the roads paved. The fact that any government service works at all is nothing short of a miracle to me.
[0] https://www.ntsb.gov/news/press-releases/Pages/NR20240221.as...