Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

121–130 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#121
Can't help but be annoyed by the flock of pretentious hackers painting every Infosys/TCS employee with a broad brush. One might say this particular leak is bad on part of Infosys and they must be held accountable for this. But calling the entire company incompetent is just lazy and stupid.

They make more than $3B in free cash flow, they are worth more than $80B in market-cap and they gainfully employ more than 100k people. Folks commenting here about the "competency" of a company should realize this. Most of their clients are based in US and UK. These companies have been using Infosys' services for decades and also have locked in deals for the coming decade. If a company was really that incompetent, it really wouldn't be on the scale they are today.

You might call them a "boring services company" but they matter a great deal to a lot of people. Less pretension, more focus on "value", please? :)

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#122

PSA: In exposures like this, Contact the cloud provider too. They tend to have the right contacts for customers. And I'm guessing there are actions they can take as well.

Yeah, you have to digitally sign a Business Associate Addemdum in your AWS account to handle HIPAA data in it. If they didnt, they're double screwed

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#123

Earlier quoted context omitted.

they went woke, and are on the path to go broke. Sadly, they’re the only mainstream competition to Chrome.

> and are on the path to go broke. Sadly, they’re the only mainstream competition to Chrome. Is it overly cynical of me to wonder if this is Google's doing? Setting someone to infiltrate Mozilla's management and sabotage it, with the long-term goal of killing all serious non-chromium alternatives. I don't know about the woke thing, I figure it's more likely to be about removing ad-block friendly API's in Manifest V3…

Nobody wants firefox to stay around more than google. Its one of their few escape cards in an antitrust trial for browser monopoly.

And the woke thing is non sense.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#124
post #11

Lol, I love how he just opted to delete it. Great on ya for having some balls instead of walking on eggshells like most of these security back and forth dialogues.

Reading the recent posts about an Android bug and how difficult it was for the researcher to get them to fix and how he was reluctant to disclose or even threaten to disclose reminds me of a time gone past of… harder… type of hackers. It’s like the completely backwards on the wrong foot.

In good old days you could do a lot without some massive Corp dragging you to court. Are you willing to risk years of self-funded courtroom process which may not turn out well for you, just to show how hard you are as a hacker? I don't think so. We know of cases where even reporting an issue caused lawyers to threaten you without any upside otherwise.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#125

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

AWITCH ... you forgot Accenture

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#126
In 1999, I was an intern at a company in India. We wanted to put a machine in a datacenter, and the datacenter admin asked us to set the Administrator password to "password". Turns out that all the other companies that put their boxes in that datacenter did the same. Infosys was one of those companies.

I wrote more about it here: https://tech.bluesmoon.info/2017/04/a-tale-of-datacenter-sec...

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#127

Earlier quoted context omitted.

This is unfortunately common even outside of Infosys. I've experienced it at several of my former employers, although admittedly more in China than in other countries I worked. It's interesting when you sit beside a developer who does this kind of stuff in a pair-programming context, because it immediately becomes clear that they really don't have a clue how to read and understand code in the abstract. Their process…

I don’t know you at all aside from this post, so I could be off the mark, but I suspect you need to find a better place of employment. Places where people exercise discretion and aim for quality and ship quality do exist. They are not the norm, but they absolutely exist.

Thanks for the suggestion. I am pretty happy in my current place of employment where I fortunately haven't (yet) encountered this, but I have definitely been surprised in previous jobs where I encountered it despite hiring standards that theoretically should have rejected this type of candidate at the outset. I have even worked with ex-FAANG colleagues who had this approach to development. I have come to think there is only so much you can do to try solve this in the hiring funnel... Eventually people who don't code very well or don't take code quality seriously will slip through, especially in larger companies.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#128
post #5

Wow. Really crazy. I know it was not right to revoke the key, he touched into their system. He probably broke someone’s production. But it was also absolutely the right thing to do. A god mode key floating around for over a year unrevoked, with real human beings’s medical data on the other side… I am glad the post author revoked the key. It is probably too little too late but they did close that door and maybe saved…

Is it possible to create another god keys with this key? Will other keys expire also?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#130

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

> No competent employee stays in those companies I gotta say, this explains so much. We have a FTE who came from infosys and he's very good. I have such a hard time squaring that with the team that submits an initial PR with the bin and obj directories checked in, then follows it up by adding .gitignore.txt file before FINALLY submitting a .gitignore file. And then finding them representing currency as float, or find…

Programming/anything to do with PCs in India is a rich man’s hobby. Tinkering is not encouraged in colleges in the country. In any case this is a big country with a lot of talented devs. But for the same reason the pool of mediocre programmers is also pretty big.
Post reply on HN