Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

61–70 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#63

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

> No competent employee stays in those companies I gotta say, this explains so much. We have a FTE who came from infosys and he's very good. I have such a hard time squaring that with the team that submits an initial PR with the bin and obj directories checked in, then follows it up by adding .gitignore.txt file before FINALLY submitting a .gitignore file. And then finding them representing currency as float, or find…

They employ a quarter million people. Quality may vary…

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#64

The GitHub user instead of reporting incident to their security team chose to take sneaky approach to remove the keys fearing the actions from company. They will be fired and instead of retrospectively improving the security Infosys will ban all OSS contributions from their developers.

[deleted]

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#65

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

too bad, it's a great company name that inspires confidence... until you read a comment like this!

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#67
post #5

Wow. Really crazy. I know it was not right to revoke the key, he touched into their system. He probably broke someone’s production. But it was also absolutely the right thing to do. A god mode key floating around for over a year unrevoked, with real human beings’s medical data on the other side… I am glad the post author revoked the key. It is probably too little too late but they did close that door and maybe saved…

GitHub always freaks out at me when I include text that even looks like a PEM cert. Too bad they can't scan for AWS key / secret variables too.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#68
post #13

[dead]

Governments already observe most every financial transaction, either because they run the money transmission system (ACH/FedWire/etc), or because countries with VAT send every invoice to the tax office. It's not clear how a CBDC is actually different from the current system, but insofar as it isn't different, it's not less private.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#70

In a world filled with more competence and less corruption, Infosys would have gone bankrupt 20 years ago. But here we are with Wipro, Infosys, TCS etc. all chugging along.

I don't believe software development is their bread and butter. Traditionally these companies are known as "systems integrators" which basically means they have armies of people who have RTFM for popular enterprise software products and will provide you with bodies who sit in your office and install or provide support for the product.
Post reply on HN