Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

31–40 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#31

Is it possible to do a full sweep across all tokens in all Python files (for instance) in Github and find such keys? Can you tell from the contents if it's a key or some such "important" string?

GitHub already offers this - they scan all the code that gets uploaded to look for keys. I think the issue here is that the code wasn't on public GitHub, but the artifacts were uploaded to PyPi

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#32
post #28

Earlier quoted context omitted.

> Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. This could be true but you cant really generalize and it has nothing to do with the article. Infosys is not the only company leaking keys online. pretty sure tons of Amarican companies have done that

I think that post goes on to explain why that might be relevant.

[deleted]

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#33

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

No post body was provided.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#35
post #27
post #2

Their entire cybersecurity page is just a bunch of gibberish. It's like someone slapped together buzzwords and phrases until they filled a word count.

Quoted post unavailable.

Oh gosh... TCP/IP is a resilient protocol and would route around any countr(y/ies) opting for modern standards. The world would continue to spin.

I didn't say "puppy mill" regarding infosys... So.... Its just another puppy mill :)

https://en.m.wikipedia.org/wiki/Puppy_mill

As you were :p

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#37
This kind of stories is one of the reason I visit Hacker News. Thank you!

It's funny and annoying to read every week or so about another epic fail of a multi-billion "multinational information technology company". Good luck with outsourcing your critical services and medical data to neurodivergents.

Thanks again for making my day.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#39
post #7

Quoted post unavailable.

Yeah, that's an excerpt from Wikipedia. But when I see these lines I actually read "money laundering" and "scam".

Answer by GPT-3:

> How is information security in Infosys?

Information security at Infosys is implemented through a combination of technological and organizational measures. The company has a dedicated information security team that works to identify and mitigate risks. Technologies used to protect data include encryption, firewalls, and intrusion detection systems. Organizational measures include employee training on security policies and procedures.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#40

This kind of stories is one of the reason I visit Hacker News. Thank you! It's funny and annoying to read every week or so about another epic fail of a multi-billion "multinational information technology company". Good luck with outsourcing your critical services and medical data to neurodivergents. Thanks again for making my day.

I recommend the RISKS mailing list. https://seclists.org/risks/ But note that they sometimes take reliability too far.
Post reply on HN