---
title: "Welcoming the Nepalese Government to Have I Been Pwned"
url: https://daily.dev/posts/welcoming-the-nepalese-government-to-have-i-been-pwned-jzgosuxw9
source_url: https://www.troyhunt.com/welcoming-the-nepalese-government-to-have-i-been-pwned
type: article
source: "Troy Hunt"
published: 2026-08-03T07:40:34.584Z
updated: 2026-08-07T11:49:53.389Z
tags: ["data-breach"]
reading_time: 1
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Welcoming the Nepalese Government to Have I Been Pwned

**[Troy Hunt](https://daily.dev/sources/troyhunt)** · 1 min read · 0 upvotes · 0 comments

## Summary

Nepal's National Cyber Security Centre has become the 47th government to join Have I Been Pwned's free government monitoring service. The NCSC now has access to monitor Nepalese government domains against HIBP's breach data, enabling rapid identification of compromised government email addresses and faster incident response when those accounts appear in new data breaches.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.troyhunt.com/welcoming-the-nepalese-government-to-have-i-been-pwned>

## Community take

How the wider developer community reacted, aggregated from 1 discussion and 30 comments across hackernews (as of 2026-08-07).

**TL;DR:** The community is broadly supportive of HIBP's government monitoring program, though the headline caused initial confusion (many read it as Nepal suffering a breach). Side discussions touch on Cloudflare captcha frustrations, concerns about HIBP's business model, and the poor state of Nepalese government IT security.

**Sentiment:** 35% positive · 35% mixed · 30% skeptical

**The case for**

- Nepal's government IT infrastructure has known security weaknesses, making access to breach monitoring genuinely valuable.
- HIBP's free government monitoring service gives security agencies tools to identify exposed accounts and drive internal reform.

**The pushback**

- The headline is misleading — many readers initially assumed Nepal's government had been breached rather than welcomed as a partner.
- Some commenters argue HIBP monetizes users' stolen data by gating detailed breach information behind a paid API, unlike public law enforcement.
- Cloudflare's bot protection makes the service inaccessible to some legitimate users.

**By community**

- hackernews (mixed): Broadly supportive of the program's intent, but split between headline confusion, criticism of HIBP's paid data model, and a lively side thread about Nepalese government IT vulnerabilities and Cloudflare captcha issues.

**Hottest debate:** Whether HIBP's business model is ethically sound, given that detailed breach information (e.g. which domains or passwords were exposed) requires a paid API subscription.

**Open questions**

- Should a service like HIBP be run as a public utility with government oversight rather than a private business?
- How should researchers responsibly disclose vulnerabilities in government systems that appear to be intentionally left unpatched?

**Highlights**

> This is good news considering the current state of government run IT services in Nepal (that the page to schedule a passport renewal appointment requires you change your local timezone or override TZ to Asia/Kathmandu should tell you the state of some of these services). In having to interact with Nepali government websites I've noticed things like endpoints not even doing basic input sanitization, letting your run arbitrary queries on biometric data. Asking around the tech industry on how to report this it seems like this is a common occurrence. Someone even found a vulnerability that was apparently purposefully unpatched to most likely aid in corruption.
> — [amritananda on hackernews · 2 comments](https://news.ycombinator.com/item?id=49203328)

> Police officers help for free. If they find during an investigation  that you're avictim of a crime they WILL tell you where they found the data and what was exactly in it. Troy? He'll basically resell you your own stolen data, because that's the only way to know if the password leaked was 20 years or 1 month old, and to what services exactly. If you're leaked in infostealer dump, you'd learn from the police what was associated with your email in this dump, so you know to snort if it was only empty password store from your Firefox, or financial data exposing you to ruin. Troy? Oh, he can tell you that too, but for a price. He'll sell you your personal data back. (I've looked far and wide and there doesn't seem to be ANY way to list as much as the domains of the email/password dumps without paying for access to the API)
> — [subscribed on hackernews · 1 comments](https://news.ycombinator.com/item?id=49205244)

> I also read the title as a sardonic welcome (negative connotation). I was surprised to find out it was just a tiny puff piece of self-promotion. Being “welcomed” to HIBP sounds a lot like being “welcomed” to the Bronx by a mugging. I admit I do not follow HIBP and was unaware of this kind of outreach they do.
> — [fn-mote on hackernews](https://news.ycombinator.com/item?id=49204025)

> I do like the idea behind Have I Been Pwned, and honestly if a government took it over that might be nice if we had some guarantees. It feels like something that ought to be a public service with super duper special oversight to avoid it being used by law enforcement(since sending any information is necessarily bad)
> — [Nail2680 on hackernews · 3 comments](https://news.ycombinator.com/item?id=49205447)

**Source threads**

- [hackernews](https://news.ycombinator.com/item?id=49203105) · 165 points · 30 comments

## Similar posts on daily.dev

- [Welcoming the Sri Lankan Government to Have I Been Pwned](https://daily.dev/posts/welcoming-the-sri-lankan-government-to-have-i-been-pwned-ba9hkixtr) · Troy Hunt · 0 upvotes · 0 comments

---

Tags: [#data-breach](https://daily.dev/tags/data-breach)

[View this post on daily.dev](https://daily.dev/posts/welcoming-the-nepalese-government-to-have-i-been-pwned-jzgosuxw9)
