12 comments

[ 0.26 ms ] story [ 10.9 ms ] thread
This is good news considering the current state of government run IT services in Nepal (that the page to schedule a passport renewal appointment requires you change your local timezone or override TZ to Asia/Kathmandu should tell you the state of some of these services).

In having to interact with Nepali government websites I've noticed things like endpoints not even doing basic input sanitization, letting your run arbitrary queries on biometric data. Asking around the tech industry on how to report this it seems like this is a common occurrence. Someone even found a vulnerability that was apparently purposefully unpatched to most likely aid in corruption.

Is this the new government after the old one was violently overthrown last year?
First thought was: ouch, government data got leaked and added to the database.
Seems like an almost irresponsibly misleading headline.
Please make it possible to change email addresses, so I don't have to create a new account and verify all domains again. Thank you for the great free service.
I do like the idea behind Have I Been Pwned, and honestly if a government took it over that might be nice if we had some guarantees. It feels like something that ought to be a public service with super duper special oversight to avoid it being used by law enforcement(since sending any information is necessarily bad)
I'm surprised they can get past the CF captcha, I still can't. Ever since the beginning: https://imgur.com/a/AzNSreV
The secret is to never click on the check box. Click anywhere else. I haven't been stuck at the captcha in ages due to that.
(comment deleted)