amritananda
5 days ago
This is good news considering the current state of government run IT services in Nepal (that the page to schedule a passport renewal appointment requires you change your local timezone or override TZ to Asia/Kathmandu should tell you the state of some of these services).
In having to interact with Nepali government websites I've noticed things like endpoints not even doing basic input sanitization, letting your run arbitrary queries on biometric data. Asking around the tech industry on how to report this it seems like this is a common occurrence. Someone even found a vulnerability that was apparently purposefully unpatched to most likely aid in corruption.
bordercontrol
5 days ago
That's the case for most countries in Asia and Africa, from my travel experience. I would spot vulnerabilities that leak extremely sensitive data all the time, just by using the services normally and legally. You immediately see that the verification is broken without even having to investigate. I don't investigate or report them, as it might lead to problems.
AdamN
5 days ago
One of the good things about these attacks is that it publicizes failings and gives data to good actors inside the government to drive reform. Surely other operators (Intel services of China, India, Pakistan, etc...; criminal syndicates) have been inside these systems for years so it's nice for the cybersecurity agency to have tools to make it clear where they're exposed.