Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

21–30 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#23

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

I had some contact with Wipro. It was their standard operating procedure to call us up and yell at support team members that X "Hasn't worked for months and you haven't done anything." + escalate up the chain as high as possible to put pressure on the tech support staff from some other vendor, when in fact they just opened the ticket. They would lie and reference the first old ticket they could think of and say it was the same issue (it never was, they wouldn't even lie well enough to reference the same equipment).

They would declare everything was a P1 ticket and demand it be fixed immediately. Then we would get some output from the machine or even remotely access it and find that outside of testing at the factory this was the first time it was powered on. When we would ask them for configurations ... they were evasive.

If you got their end customer on the line you would find that they had been lying to them for months. This happened a lot ...

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#24
post #10

Earlier quoted context omitted.

Pretty sure GitHub runs a system that will automatically revoke every (AWS and other) key to ever become part of a repository.

Not in my experience dealing with customers who had AWS email them saying 'Hey, we found one of your keys on GitHub'.

I’ve worked on a team where Github was the one who reached out about a leaked AWS secret key, not AWS. They apparently usually do this a few minutes before the key makes it into their search index. It’s not much but it’s better than nothing.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#25
Many years ago, I did some consulting work on a project that had been "delivered" by Infosys. It was, to put it lightly, a complete and utter mess in every way. Just from a security vulnerability standpoint, it had: SQL injection, plaintext passwords for user accounts, zero protection against URL manipulation, etc. And those are just the ones that come to mind immediately.

Glad to see nothing has changed.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#26

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

> Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die.

This could be true but you cant really generalize and it has nothing to do with the article. Infosys is not the only company leaking keys online. pretty sure tons of Amarican companies have done that

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#28

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

> Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. This could be true but you cant really generalize and it has nothing to do with the article. Infosys is not the only company leaking keys online. pretty sure tons of Amarican companies have done that

I think that post goes on to explain why that might be relevant.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#29
post #11

Lol, I love how he just opted to delete it. Great on ya for having some balls instead of walking on eggshells like most of these security back and forth dialogues.

Reading the recent posts about an Android bug and how difficult it was for the researcher to get them to fix and how he was reluctant to disclose or even threaten to disclose reminds me of a time gone past of… harder… type of hackers.

It’s like the completely backwards on the wrong foot.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#30
post #5

Wow. Really crazy. I know it was not right to revoke the key, he touched into their system. He probably broke someone’s production. But it was also absolutely the right thing to do. A god mode key floating around for over a year unrevoked, with real human beings’s medical data on the other side… I am glad the post author revoked the key. It is probably too little too late but they did close that door and maybe saved…

It wasn't right to issue a fraudulent takedown either.
Post reply on HN