Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

91–100 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#91

Why does Infosys get access to HIPAA data (including copying it to their own storage!) to train AI models? That seems like another large story.

They could have been doing this on behalf of a paying customer. They will sell anything with our without having any expertise. "Pay us, bring your data, and we will do the AI for you and help you".

They have case studies on it I suppose: https://www.infosys.com/industries/financial-services/case-s...

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#92

The GitHub user instead of reporting incident to their security team chose to take sneaky approach to remove the keys fearing the actions from company. They will be fired and instead of retrospectively improving the security Infosys will ban all OSS contributions from their developers.

You assume they have a security team :)

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#94

This kind of stories is one of the reason I visit Hacker News. Thank you! It's funny and annoying to read every week or so about another epic fail of a multi-billion "multinational information technology company". Good luck with outsourcing your critical services and medical data to neurodivergents. Thanks again for making my day.

> neurodivergents

Can you please explain this?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#95
I notice the author is in London. For people in the US, my suggestion is to go instead to https://www.cisa.gov/report to report things like this. Especially when you're dealing with a company that doesn't have a clear vulnerability-disclosure process, or if you have _any_ concern about your own safety (physical, legal, etc.) when making a report.

Personally, I would have stopped right before "The Cleanup", and made a report.

Which option would I choose from https://www.cisa.gov/report? None of them stand out, so I would have chosen the last option, to send an email.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#96
post #41

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

> Cognizant Someone hired those clowns as contractors as extra in a previous job, to loud protests from our development team. They produced what was quite possibly the most chaotic, copy-paste, typo-laden code I have ever seen in my life.

This is hardly surprising. Most of them would be completely clueless about the code they've "written".

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#97
post #50

Earlier quoted context omitted.

Fun fact: Mozilla projects are now developed in part by Cognizant Softvision, including Firefox for Android. Their employees are everywhere on Mozilla bug trackers, and their numbers seem to have increased since 2020, right after Mozilla fired a quarter of its workforce. https://www.cognizantsoftvision.com/blog/pedal-metal-mozilla...

This pisses me straight off. Someone needs to fork Mozilla (the company) and bring back its hayday culture.

they went woke, and are on the path to go broke. Sadly, they’re the only mainstream competition to Chrome.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#98
The Indian government has, over the years, awarded contracts worth billions of dollars to Infosys for projects like the Goods and Service Tax portal, Income Tax portal. In all these cases, the implementations are slow and super buggy. Deadlines to deliver are routinely missed. In an ideal world, these companies should not be allowed to exist.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#99
post #98

The Indian government has, over the years, awarded contracts worth billions of dollars to Infosys for projects like the Goods and Service Tax portal, Income Tax portal. In all these cases, the implementations are slow and super buggy. Deadlines to deliver are routinely missed. In an ideal world, these companies should not be allowed to exist.

Now, the interesting this is the recent complete refactor of the country’s income tax portal. It was messy, but I feel it was heavenly compared to the clusterF that was healthcare.gov. So what are your thoughts on this being a WITCH specific problem?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#100
post #55

In a world filled with more competence and less corruption, Infosys would have gone bankrupt 20 years ago. But here we are with Wipro, Infosys, TCS etc. all chugging along.

TCS -> US$25 billion Revenue in 2022 InfoSys-> US$16 billion Revenue in 2022 Wipro -> US$10 billion Revenue in 2022 I want to get out of this Universe and get into one that makes sense...

This universe makes perfect sense, you just don’t want to accept underlying equations is all.
Post reply on HN