Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

151–160 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#152
post #143

This thread is full of generalized insults at a million people based on where they work. If someone did the same based on a different attribute of a population, they'd be banned. I've worked at one of these companies but left over a decade ago. I know how we're looked at when we do client work (part of why I left). Some of my colleagues were less competent, true. But, some will wipe the floor with the client employee…

There is something to be said about the repeated displays of incompetence though. My own experiences working with WITCH employees have mirrored those of the other comments and that of the article. It is not wrong to criticize the methods that they pursue, nor the fact that they do not wish to learn from their mistakes.

Most companies the size of WITCH do not utilize access keys nor add them to source control. While a developer may make a mistake, you would expect there would be guardrails around the development process, either by way of an automated scanner or a more experienced software engineer catching it as part of a code review. The fact that none of this happened is quite concerning, IMO.

You could also perhaps say this is a management problem than an employee problem; and while that is true, such distinctions are rarely made. As an example, I'm sure you've had bad experiences with customer support which you simply summarized as "The support rep at Corp X sucks" when talking to other people; whereas the truth might be somewhere closer to "The support rep was out of luck because they didn't have a process to do A, B and C because management didn't think of it."

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#153

Earlier quoted context omitted.

> No competent employee stays in those companies I gotta say, this explains so much. We have a FTE who came from infosys and he's very good. I have such a hard time squaring that with the team that submits an initial PR with the bin and obj directories checked in, then follows it up by adding .gitignore.txt file before FINALLY submitting a .gitignore file. And then finding them representing currency as float, or find…

They employ a quarter million people. Quality may vary…

Yes. There are a number of highly skilled and talented people in Infosys and the other WITCH companies, but they're generally staffed only on the most prestigious projects and tend to move on fairly quickly. As another commenter said, in most cases they got recruited straight out of college.

So it's not that everyone at companies like Infosys are bad, it's that their hiring standards are so lax and hiring rate so high that the large proportion of their engineering people are mediocre at best, and that's why most engineers at European or American companies would've been exposed to.

The typical model of a WITCH engagement is to get a new client project that requires, say 100 engineers, and immediately go to market to hire 90% of them because they don't have a bench. Screening is minimal. They're then heavily micromanaged on the project for the first few months, where it's expected that at least half of those people will fail and either their manager or the client will demand they get rotated off and then sacked. They're replaced by another cohort freshly hired and the process repeats until you have a stable-ish team of good-enough competence about 8 months in.

It works because it's still cheaper and easier for big corps and big projects and the delivered quality is fairly shit, but still acceptable. And the margins are so good that in the rare event there are late delivery penalties they're fairly easily absorbed.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#154
post #143

This thread is full of generalized insults at a million people based on where they work. If someone did the same based on a different attribute of a population, they'd be banned. I've worked at one of these companies but left over a decade ago. I know how we're looked at when we do client work (part of why I left). Some of my colleagues were less competent, true. But, some will wipe the floor with the client employee…

I'm not quite reading it that way, but if that's the case I completely agree: You should never insult people based on where they work, or for any reason really. What I see is a general criticism of the companies, their culture and business practices.

InfoSys is not a company I worked with, so I can't and won't comment on them. TCS is a company I have had the misfortune to encounter. The problems with TCS is numerous, a few examples: they oversell, you're denied access to consultants that can actually help and they will always prefer to prolong an issue, rather than escalating to senior consultants. There's no incentive for one of their consultants to be pro-active or take responsibility. There are so many departments/team and layers in their organisation that there's always some one else to point the finger at.

The consultants are TCS aren't stupid or incompetent, but they also aren't being helped, pushed or motivated by seniors or their management. I do got the feeling that they would be reprimanded if they where to escalate an issue. In a meeting with TCS I suggested added 8GB of memory to a VM, as either a temporary fix, or a sort of "let's see what that does for the client". That suggestion was rejected because: It wouldn't fix the underlying issue (which was true, but they also didn't want to upgrade Java or the operating system, which was part of the problem. The OS being an old unsupported version of CentOS), and also wasn't something you could "just do". That would require involvement from 5 or 6 other departments. A month later, someone finally caved in an escalated to a higher up TCS consultant, which just added the memory as a fix until the service could be migrated to a new OS and JRE.

Anyway my point is: No, it's not the staff, not as such. They skills are for the most part perfectly fine. The company did have true experts available, if required. It's just that the culture is a really bad fit for western style companies, if you're in Northern Europe it's an even worse, because we don't share many of their values and fears. This could be solved if the Indian companies better understood the market they're selling into, because they do have the technical skills. As it stands, people like me get annoyed that we have to tell the clients that we can't fix their issues, because someone in Mumbai is afraid of looking bad to their boss or ask a colleague for help. If it has to be like that, then at least have the balls to tell the client yourself why you don't care that their systems haven't been running right for a month.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#155

Can't help but be annoyed by the flock of pretentious hackers painting every Infosys/TCS employee with a broad brush. One might say this particular leak is bad on part of Infosys and they must be held accountable for this. But calling the entire company incompetent is just lazy and stupid. They make more than $3B in free cash flow, they are worth more than $80B in market-cap and they gainfully employ more than 100k p…

If the focus was primarily on value, a lot of comments would be significantly more scathing in significantly more cases. The fact of the matter is that if you work for a company that produces trash, that is fine - everyone has to eat. But nobody owes you respect for it.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#156

Can't help but be annoyed by the flock of pretentious hackers painting every Infosys/TCS employee with a broad brush. One might say this particular leak is bad on part of Infosys and they must be held accountable for this. But calling the entire company incompetent is just lazy and stupid. They make more than $3B in free cash flow, they are worth more than $80B in market-cap and they gainfully employ more than 100k p…

For those who are downvoting me, would love to hear your take instead of a salty downvote. All numbers in my post are factually correct.

The numbers don't matter, because they're not about the core issue at all. My guess is that the post reads as if you don't understand that money can in fact be spent wrong and you are downvoted for this reason.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#157

Can't help but be annoyed by the flock of pretentious hackers painting every Infosys/TCS employee with a broad brush. One might say this particular leak is bad on part of Infosys and they must be held accountable for this. But calling the entire company incompetent is just lazy and stupid. They make more than $3B in free cash flow, they are worth more than $80B in market-cap and they gainfully employ more than 100k p…

If the focus was primarily on value, a lot of comments would be significantly more scathing in significantly more cases. The fact of the matter is that if you work for a company that produces trash, that is fine - everyone has to eat. But nobody owes you respect for it.

Eh? First of all, I don't work for them. Secondly, what makes you think this company produces trash? Vanguard recently signed a $1B+ deal with Infosys to help them with cloud migration and other services. Why the heck would an established client like Vanguard pay a such huge amount for no reason? You are either ignorant or just don't understand the business value companies like Infosys provide. I'm guessing you are a Software Engineer?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#158
post #149

Can't help but be annoyed by the flock of pretentious hackers painting every Infosys/TCS employee with a broad brush. One might say this particular leak is bad on part of Infosys and they must be held accountable for this. But calling the entire company incompetent is just lazy and stupid. They make more than $3B in free cash flow, they are worth more than $80B in market-cap and they gainfully employ more than 100k p…

I think you are misunderstanding what these companies have deals with Infosys for. It's not because they're so competent, it's because they're a convenient scapegoat when things inevitably go wrong. Things inevitably go wrong for them because people hiring a company like Infosys do not want to be told how to do tech by competent engineers (and are probably not able to distinguish competent from incompetent engineers…

Yeah, right. Vanguard is paying a billion dollars, and Daimler is paying three billion dollars to Infosys because they are a "convenient scapegoat"?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#159
post #143

This thread is full of generalized insults at a million people based on where they work. If someone did the same based on a different attribute of a population, they'd be banned. I've worked at one of these companies but left over a decade ago. I know how we're looked at when we do client work (part of why I left). Some of my colleagues were less competent, true. But, some will wipe the floor with the client employee…

Thank you for this! I've said the same thing and had to deal with salty downvoters earlier today. Companies pay WITCH companies billions of dollars for their services yet a lot of pretentious hackers just don't see the value.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#160
post #143

This thread is full of generalized insults at a million people based on where they work. If someone did the same based on a different attribute of a population, they'd be banned. I've worked at one of these companies but left over a decade ago. I know how we're looked at when we do client work (part of why I left). Some of my colleagues were less competent, true. But, some will wipe the floor with the client employee…

There is something to be said about the repeated displays of incompetence though. My own experiences working with WITCH employees have mirrored those of the other comments and that of the article. It is not wrong to criticize the methods that they pursue, nor the fact that they do not wish to learn from their mistakes. Most companies the size of WITCH do not utilize access keys nor add them to source control. While a…

> Most companies the size of WITCH do not utilize access keys nor add them to source control.

Most companies the size of WITCH do not use barely out of college engineers for rock bottom prices, driving them to deliver, features, features, features at all costs.

Literally all costs. It's a lot simpler to work with AWS if you can just plonk your full access key down everywhere, and even someone just out college can understand it.

Conversely, dealing with AWS Roles/Profiles and permission is a whole separate profession by this point.

Post reply on HN