[dead]
Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
21–30 of 218 posts
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#22Their entire cybersecurity page is just a bunch of gibberish. It's like someone slapped together buzzwords and phrases until they filled a word count.
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#23> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…
They would declare everything was a P1 ticket and demand it be fixed immediately. Then we would get some output from the machine or even remotely access it and find that outside of testing at the factory this was the first time it was powered on. When we would ask them for configurations ... they were evasive.
If you got their end customer on the line you would find that they had been lying to them for months. This happened a lot ...
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#24Earlier quoted context omitted.
Pretty sure GitHub runs a system that will automatically revoke every (AWS and other) key to ever become part of a repository.
Not in my experience dealing with customers who had AWS email them saying 'Hey, we found one of your keys on GitHub'.
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#25Glad to see nothing has changed.
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#26> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…
This could be true but you cant really generalize and it has nothing to do with the article. Infosys is not the only company leaking keys online. pretty sure tons of Amarican companies have done that
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#27Their entire cybersecurity page is just a bunch of gibberish. It's like someone slapped together buzzwords and phrases until they filled a word count.
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#28> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…
> Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. This could be true but you cant really generalize and it has nothing to do with the article. Infosys is not the only company leaking keys online. pretty sure tons of Amarican companies have done that
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#29Lol, I love how he just opted to delete it. Great on ya for having some balls instead of walking on eggshells like most of these security back and forth dialogues.
It’s like the completely backwards on the wrong foot.
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#30Wow. Really crazy. I know it was not right to revoke the key, he touched into their system. He probably broke someone’s production. But it was also absolutely the right thing to do. A god mode key floating around for over a year unrevoked, with real human beings’s medical data on the other side… I am glad the post author revoked the key. It is probably too little too late but they did close that door and maybe saved…