The Indian government has, over the years, awarded contracts worth billions of dollars to Infosys for projects like the Goods and Service Tax portal, Income Tax portal. In all these cases, the implementations are slow and super buggy. Deadlines to deliver are routinely missed. In an ideal world, these companies should not be allowed to exist.
Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
111–120 of 218 posts
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#112Earlier quoted context omitted.
This pisses me straight off. Someone needs to fork Mozilla (the company) and bring back its hayday culture.
they went woke, and are on the path to go broke. Sadly, they’re the only mainstream competition to Chrome.
Is it overly cynical of me to wonder if this is Google's doing? Setting someone to infiltrate Mozilla's management and sabotage it, with the long-term goal of killing all serious non-chromium alternatives.
I don't know about the woke thing, I figure it's more likely to be about removing ad-block friendly API's in Manifest V3 (and presumably even more hostile changes in some future Manifest V4).
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#113How they go about stuff with that felt so weird, cause I would never get the same recruiter, makes sense they would do something like this.
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#114Is it possible to do a full sweep across all tokens in all Python files (for instance) in Github and find such keys? Can you tell from the contents if it's a key or some such "important" string?
Yep, and if you don't look for them, you can be darn sure someone else is looking for them. I heard about an incident from a friend where a GitHub repo was created accidentally public (ran out of private repos and I guess the failure mode back in the day was just make it public) and that repo had developer level access keys in it. Some enterprising fellow was scanning public repos for this, grabbed the keys, opened t…
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#115Earlier quoted context omitted.
You assume they have a security team :)
They will have ten security teams at the minimum. You assume that their teams know what security means though :)
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#116Wow. Really crazy. I know it was not right to revoke the key, he touched into their system. He probably broke someone’s production. But it was also absolutely the right thing to do. A god mode key floating around for over a year unrevoked, with real human beings’s medical data on the other side… I am glad the post author revoked the key. It is probably too little too late but they did close that door and maybe saved…
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#117Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#118> Johns_Hopkins_Hospital/Input/Excel/Covid_patientdetails/covid_patient_details.xlsx Should I file the HIPAA complaint, or has someone else already done that? (the stupid government website for filing complaints is, of course, not loading for me now)
The breach notification to HHS typically comes from the covered entity. They often have the information on exactly what PHI was out there, how many individuals were impacted, and can provide the right info to HHS.
And with my experience in healthcare IT, I can say privacy and compliance officers take reports like this incredibly seriously. Those might not be the right people but getting an email to compliance folks inside the covered entity and saying “here’s a likely breach” will absolutely get the ball rolling.
Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
#119I really wish this surprised me. The number of people who completely understand the stack they are working on is shrinking, even as the size of the stack grows. The power of computing is such that every organization on the planet is forced to lower the bar to get people who are marginally competent, even if they lack attention detail and cannot be relied on to solve problems of this sort. This kind of leak is the res…
Even if I pretend I don't know anything about AWS, if somebody handed me credentials with access called "FullAdminAccess" and told me to use them for my little script that only needs read-only access to S3 I would be extremely skeptical.
The reality is that the culture at Infosys seems to place zero value on security of customer data.