Live data from Hacker News

Welcoming the Nepalese Government to Have I Been Pwned

troyhunt.com

31–40 of 40 posts

Re: Welcoming the Nepalese Government to Have I Been Pwned

#31

I do like the idea behind Have I Been Pwned, and honestly if a government took it over that might be nice if we had some guarantees. It feels like something that ought to be a public service with super duper special oversight to avoid it being used by law enforcement(since sending any information is necessarily bad)

Most people don't trust their government enough to run a service like this. For example, my government lets bridges collapse[0], and it can barely keep the roads paved. The fact that any government service works at all is nothing short of a miracle to me.

[0] https://www.ntsb.gov/news/press-releases/Pages/NR20240221.as...

Re: Welcoming the Nepalese Government to Have I Been Pwned

#32

This is good news considering the current state of government run IT services in Nepal (that the page to schedule a passport renewal appointment requires you change your local timezone or override TZ to Asia/Kathmandu should tell you the state of some of these services). In having to interact with Nepali government websites I've noticed things like endpoints not even doing basic input sanitization, letting your run a…

One of the good things about these attacks is that it publicizes failings and gives data to good actors inside the government to drive reform. Surely other operators (Intel services of China, India, Pakistan, etc...; criminal syndicates) have been inside these systems for years so it's nice for the cybersecurity agency to have tools to make it clear where they're exposed.

Re: Welcoming the Nepalese Government to Have I Been Pwned

#33
post #27

Earlier quoted context omitted.

Police officers help for free. If they find during an investigation that you're avictim of a crime they WILL tell you where they found the data and what was exactly in it. Troy? He'll basically resell you your own stolen data, because that's the only way to know if the password leaked was 20 years or 1 month old, and to what services exactly. If you're leaked in infostealer dump, you'd learn from the police what was…

You seem to have wildly different experiences with police than most

I'm talking specifically about this specific kind of crime, don't generalise my statement.

Re: Welcoming the Nepalese Government to Have I Been Pwned

#34
post #27

Earlier quoted context omitted.

You seem to have wildly different experiences with police than most

I'm talking specifically about this specific kind of crime, don't generalise my statement.

Touchy touchy.

You’d have to be a celebrity to get a call from any police force I’ve ever seen, for even this type of crime.

Re: Welcoming the Nepalese Government to Have I Been Pwned

#35
post #34

Earlier quoted context omitted.

I'm talking specifically about this specific kind of crime, don't generalise my statement.

Touchy touchy. You’d have to be a celebrity to get a call from any police force I’ve ever seen, for even this type of crime.

OK, I have no idea what are you on about, your vague generalisations attempt to throw the entire effort of this branch on me, so I'll just pass, it's not worth any more of my time.

Also because of the other reason.

Re: Welcoming the Nepalese Government to Have I Been Pwned

#36

I'm surprised they can get past the CF captcha, I still can't. Ever since the beginning: https://imgur.com/a/AzNSreV

I've started email the customer support of pages that have overzealous CF settings saying that it's a pain and that if they want to keep me as a customer they need to fix it. Most give a canned response of "we can't do anything" ̄\_(ツ)_/ ̄ but some small sites do something. GitLab has the most annoying CF bouncer and I moved my company off them once I got the we can't do anything about it response.

Humble quite frequently locks me out with theirs and all support ever does is “have you updated your browser and restarted your router?” - it’s clear the agent has no idea what a cloudflare is and it’s not in their list of acceptable escalation reasons

Re: Welcoming the Nepalese Government to Have I Been Pwned

#39
post #37

I'm surprised they can get past the CF captcha, I still can't. Ever since the beginning: https://imgur.com/a/AzNSreV

The secret is to never click on the check box. Click anywhere else. I haven't been stuck at the captcha in ages due to that.

Sounds Cargo cultish https://en.wikipedia.org/wiki/Cargo_cult#As_a_metaphor

I have always clicked the check box and never been stuck. Two opposing anecdotes means nothing, there must be more to it.

Re: Welcoming the Nepalese Government to Have I Been Pwned

#40

I'm surprised they can get past the CF captcha, I still can't. Ever since the beginning: https://imgur.com/a/AzNSreV

It provides me relief that I am not the only one suffering from Clownfair bot protection running amok. Condolences to you.

I moved my code off Cloudflare just because I got frustrated on other people's websites. Being the change I want to see, I guess?
Post reply on HN