Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

171–180 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#171
I know a person that works as a "Cybersecurity consultant" at Infosys. Mind you, not in India. She got hired as an intern with no degree, after a few months of game testing experience and some Udemy courses. Then, got promoted after less than a year and her salary doubled. Good for her, but she openly admitted to me her best skill is Powerpoint presentations

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#172
post #143

This thread is full of generalized insults at a million people based on where they work. If someone did the same based on a different attribute of a population, they'd be banned. I've worked at one of these companies but left over a decade ago. I know how we're looked at when we do client work (part of why I left). Some of my colleagues were less competent, true. But, some will wipe the floor with the client employee…

Thank you for this! I've said the same thing and had to deal with salty downvoters earlier today. Companies pay WITCH companies billions of dollars for their services yet a lot of pretentious hackers just don't see the value.

That's just based on the ability to convince the management types though, and I'm sure you've heard of the phrase "nobody got fired for buying IBM."

For an executive, it's easier to justify outsourcing to a large consulting firm simply because of the security afforded by the choice and the ease of justification; rather than any technical abilities they may or may not possess, and certainly it does not imply its correctness.

The anecdotes you hear are from a engineering perspective, which is where the consulting firm has to walk the walk, exposing their true abilities. It is incorrect to dismiss that as being "salty" or "pretentious", and tint them with an angle of "discrimination". The lack of processes and guardrails in these consulting companies is an objective fact.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#173

I really wish this surprised me. The number of people who completely understand the stack they are working on is shrinking, even as the size of the stack grows. The power of computing is such that every organization on the planet is forced to lower the bar to get people who are marginally competent, even if they lack attention detail and cannot be relied on to solve problems of this sort. This kind of leak is the res…

I dispute this: I do not think you need to understand the whole stack to know using what effectively is "god mode" access is bad practice. Even if I pretend I don't know anything about AWS, if somebody handed me credentials with access called "FullAdminAccess" and told me to use them for my little script that only needs read-only access to S3 I would be extremely skeptical. The reality is that the culture at Infosys…

>Even if I pretend I don't know anything about AWS, if somebody handed me credentials with access called "FullAdminAccess" and told me to use them for my little script that only needs read-only access to S3 I would be extremely skeptical.

If you ask for an access key for your little script and get one, you usually only check if it works for your case and not always check if it has any other access, so I can easily see it happening without proper access controls.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#174

In 1999, I was an intern at a company in India. We wanted to put a machine in a datacenter, and the datacenter admin asked us to set the Administrator password to "password". Turns out that all the other companies that put their boxes in that datacenter did the same. Infosys was one of those companies. I wrote more about it here: https://tech.bluesmoon.info/2017/04/a-tale-of-datacenter-sec...

Epic! Hope you don't mind my quote here. I enjoyed it :-)

"...I glanced over at the other boxes, and they all had stickers on them saying "Administrator/password"...The three of us from TSPL looked at each other, and our president told me to decide. I asked the datacenter guy why he needed that. He said that sometimes they need to shutdown the boxes so they can move them to a different power strip. I asked him if it would be sufficient to give him an account that only had local access and could only reboot the box. He thought about it for a bit and said yes... So I created a new account that required a physically attached keyboard for login, and all it had was the ability to reboot the box. Our app was set up to start up automatically on boot, so we weren't worried about someone having to start it. DC guy physically locked the box to a rack, showed us that he was keeping they key, and we headed back to the office...

...We now needed to test our setup, so we asked everyone in the office to let us use the internet connection. We tried accessing our app, and it worked!...

...Since I had Admin access to our box, I was also able to open the "Network Neighbourhood" of our box in the datacenter. On that network, I saw all the other hosts that were in the datacenter. They had names identifying them from India's largest IT companies. These were companies I'd initially though of interning at...I looked at our president and grinned, and he looked back and said, "Send me a safe summary report when you're done" and walked off to his office.

I double clicked on one of the other big boxes and was prompted for a username and password to connect to it...

You can probably guess what happened next ;)..."

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#175

Earlier quoted context omitted.

If the focus was primarily on value, a lot of comments would be significantly more scathing in significantly more cases. The fact of the matter is that if you work for a company that produces trash, that is fine - everyone has to eat. But nobody owes you respect for it.

Eh? First of all, I don't work for them. Secondly, what makes you think this company produces trash? Vanguard recently signed a $1B+ deal with Infosys to help them with cloud migration and other services. Why the heck would an established client like Vanguard pay a such huge amount for no reason? You are either ignorant or just don't understand the business value companies like Infosys provide. I'm guessing you are a…

[deleted]

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#176
post #71

I applaud any bad press on InfoSys. I picked up contract gig through them a few years ago. Here are some of the takeaways from my short lived experience: - It took them over two weeks to send me a computer. - They cancelled PTO for everyone. (this was the most egregious single thing they did) - They had absolute worst internal site for accessing HR documents and accessing personal resources. Just a maze of links. You…

> When I gave my 2 week notice, they refused and said I 'owed' them at least a month. LOL not sure how they think they can control people like that

To be fair, in many countries (probably most developed ones) there are regulated mandatory min and max notice periods. E.g. in France the standard is 1 to 3 months, negotiable of course.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#177

Earlier quoted context omitted.

If the focus was primarily on value, a lot of comments would be significantly more scathing in significantly more cases. The fact of the matter is that if you work for a company that produces trash, that is fine - everyone has to eat. But nobody owes you respect for it.

Eh? First of all, I don't work for them. Secondly, what makes you think this company produces trash? Vanguard recently signed a $1B+ deal with Infosys to help them with cloud migration and other services. Why the heck would an established client like Vanguard pay a such huge amount for no reason? You are either ignorant or just don't understand the business value companies like Infosys provide. I'm guessing you are a…

> Why the heck would an established client like Vanguard pay a such huge amount for no reason?

For the same reason the Canadian government spent billions on IBM, and Hertz on Accenture, with a complete dumpster fire for a result, and other organisations still trust Accenture and IBM (Kyndryl now) with their money. It has never been about quality with these types of contracts.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#178
post #143

This thread is full of generalized insults at a million people based on where they work. If someone did the same based on a different attribute of a population, they'd be banned. I've worked at one of these companies but left over a decade ago. I know how we're looked at when we do client work (part of why I left). Some of my colleagues were less competent, true. But, some will wipe the floor with the client employee…

There is nobody responsibly for hiring of new people into any of the bannable groups, or firing from them. There is management at Infosys that is 100% responsible for the apathetic, rot that engulfs it.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#179

Earlier quoted context omitted.

AWITCH ... you forgot Accenture

Glad to find this mentioned, Accenture is absolutely an offender.

I have had some ridiculous situations with them. For one the developers in Bangalore Delivery Center 8, and what do I know, all of them?, had to work with their private computers.

A unix engineer could only work with Aix Tar and would not touch GNU Tar on Linux, because his manager had not approved it.

Onshore engineers flying home to India due to a stomach ache, instead of seeing a doctor for free in the host country due to being afraid. Of course messing up the flow of our projects.

10/10 will leave jobs to avoid such projects and situations again.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#180
post #149

Earlier quoted context omitted.

I think you are misunderstanding what these companies have deals with Infosys for. It's not because they're so competent, it's because they're a convenient scapegoat when things inevitably go wrong. Things inevitably go wrong for them because people hiring a company like Infosys do not want to be told how to do tech by competent engineers (and are probably not able to distinguish competent from incompetent engineers…

Yeah, right. Vanguard is paying a billion dollars, and Daimler is paying three billion dollars to Infosys because they are a "convenient scapegoat"?

Absolutely. Do you think any manager at Daimler wants to say/justify “I went with this noname 10 person company in the midwestern US” over “I went with Infosys because everyone in the G500 does, and have you seen those prices? I have 100 people working on this project where otherwise I’d have only 10.”

And what’s more, if one of them realizes their mistake, do you think any of them want to admit that to themselves, much less their boss, after sinking billions into it?

Post reply on HN