Welcoming the Nepalese Government to Have I Been Pwned

182 points · 27 comments on HN · read original →

Points and comments are a snapshot, not live.

Nepal's government joins Have I Been Pwned's free monitoring service for cybersecurity.

Troy Hunt announced that Nepal's National Cyber Security Centre now has access to monitor Nepalese government domains against HIBP data. This enables the NCSC to identify exposure across government email addresses and respond quickly when accounts appear in new data breaches. Nepal is the 47th government onboarded to HIBP's free gov service.

The service helps national cyber teams strengthen threat monitoring and incident response by providing visibility into compromised credentials across government domains.

What commenters are saying

Commenters expressed mixed reactions. Some noted vulnerabilities in Nepali government IT services, citing issues like lack of input sanitization allowing arbitrary queries on biometric data. One commenter suggested vulnerabilities are sometimes left unpatched to aid corruption.

Others were confused by the headline, initially interpreting it as a data breach announcement rather than a cybersecurity monitoring partnership. A few criticized HIBP's business model, with one commenter arguing Troy Hunt profits by selling people their own leaked data, while others defended the service as a valuable public tool.