Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

131–140 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#131

The GitHub user instead of reporting incident to their security team chose to take sneaky approach to remove the keys fearing the actions from company. They will be fired and instead of retrospectively improving the security Infosys will ban all OSS contributions from their developers.

> Infosys will ban all OSS contributions from their developers.

Sounds... good to me?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#132
post #98

The Indian government has, over the years, awarded contracts worth billions of dollars to Infosys for projects like the Goods and Service Tax portal, Income Tax portal. In all these cases, the implementations are slow and super buggy. Deadlines to deliver are routinely missed. In an ideal world, these companies should not be allowed to exist.

Now, the interesting this is the recent complete refactor of the country’s income tax portal. It was messy, but I feel it was heavenly compared to the clusterF that was healthcare.gov. So what are your thoughts on this being a WITCH specific problem?

It was fixed because a govt minister threatened them with jail time in the end. That set them straight and they fixed the monstrosity to save their ass. Can't reveal more details.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#133

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

AWITCH ... you forgot Accenture

Or IWATCH

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#134

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

These companies literally do not want to hire competent people, because they know they won't stick around. Their business model is to hire the absolute bottom of the barrel engineers, pay them the tech equivalent of minimum wage, and sell "consulting services" to overseas firms that don't know any better.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#135
post #123

Earlier quoted context omitted.

> and are on the path to go broke. Sadly, they’re the only mainstream competition to Chrome. Is it overly cynical of me to wonder if this is Google's doing? Setting someone to infiltrate Mozilla's management and sabotage it, with the long-term goal of killing all serious non-chromium alternatives. I don't know about the woke thing, I figure it's more likely to be about removing ad-block friendly API's in Manifest V3…

Nobody wants firefox to stay around more than google. Its one of their few escape cards in an antitrust trial for browser monopoly. And the woke thing is non sense.

Nobody wants firefox to stay around more than google. Its one of their few escape cards in an antitrust trial for browser monopoly.

Google wants Firefox to stay around, but in a form that's much closer to Chrome. Of all the browsers that still have significant userbase remaining, Firefox is an "anomaly" in that it's one the user has more control over, and Google is slowly trying to change that.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#136

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

AWITCH ... you forgot Accenture

Glad to find this mentioned, Accenture is absolutely an offender.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#137
post #55

In a world filled with more competence and less corruption, Infosys would have gone bankrupt 20 years ago. But here we are with Wipro, Infosys, TCS etc. all chugging along.

TCS -> US$25 billion Revenue in 2022 InfoSys-> US$16 billion Revenue in 2022 Wipro -> US$10 billion Revenue in 2022 I want to get out of this Universe and get into one that makes sense...

I think the coming recession will help that along ;) There's going to be less fraud and we'll find out who's been "swimming naked" when the tide goes out as Mr. Buffett likes to say. Like FTX..

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#138
post #86
post #50

Earlier quoted context omitted.

Fun fact: Mozilla projects are now developed in part by Cognizant Softvision, including Firefox for Android. Their employees are everywhere on Mozilla bug trackers, and their numbers seem to have increased since 2020, right after Mozilla fired a quarter of its workforce. https://www.cognizantsoftvision.com/blog/pedal-metal-mozilla...

This is a #TIL to me. I'm not sure I would trust these Mozilla projects going ahead.

Luckily, if https://wiki.mozilla.org/QA_SoftVision_Team is any indication, they're mostly babysitting test suites and reviewing submissions to the add-on store and stuff. (That and developing Firefox for Android, but Firefox for Android has sucked and included tracking SDKs for years now.)

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#139

Can't help but be annoyed by the flock of pretentious hackers painting every Infosys/TCS employee with a broad brush. One might say this particular leak is bad on part of Infosys and they must be held accountable for this. But calling the entire company incompetent is just lazy and stupid. They make more than $3B in free cash flow, they are worth more than $80B in market-cap and they gainfully employ more than 100k p…

For those who are downvoting me, would love to hear your take instead of a salty downvote. All numbers in my post are factually correct.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#140

I really wish this surprised me. The number of people who completely understand the stack they are working on is shrinking, even as the size of the stack grows. The power of computing is such that every organization on the planet is forced to lower the bar to get people who are marginally competent, even if they lack attention detail and cannot be relied on to solve problems of this sort. This kind of leak is the res…

I don’t think there are any people who understand the full stack. I don’t think anyone like that has existed in computing in a very long time. It’s truly impossible for a single human to actually understand the physics of electronics, the world of CPU micro-architecture, packet shuffling network equipment, the nuance of CSS, and the never ending complexity of UI/UX design. The only way this statement could be accurat…

If "full stack" means electronics up to JS, then there are probably quite a few people who can work at all those levels. Although a minority, at least they can understand a "fuller" stack than most, unfortunately.
Post reply on HN