Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

191–200 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#191

Can't help but be annoyed by the flock of pretentious hackers painting every Infosys/TCS employee with a broad brush. One might say this particular leak is bad on part of Infosys and they must be held accountable for this. But calling the entire company incompetent is just lazy and stupid. They make more than $3B in free cash flow, they are worth more than $80B in market-cap and they gainfully employ more than 100k p…

For those who are downvoting me, would love to hear your take instead of a salty downvote. All numbers in my post are factually correct.

I don't understand why you are being down voted. I disagree with you that they provide quality though. They don't. It is also the case that the company that hires them provide any quality. All are in it for making money with lowest spend and quality that they can get by. Very few obsess over quality and ones that do are vertically integrated to control quality in each step of the process. Very few American companies are like this.

The engineers who complain here don't have any influence in the decision making or otherwise they wouldn't be crying and complaining here.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#192

Earlier quoted context omitted.

Glad to find this mentioned, Accenture is absolutely an offender.

I have had some ridiculous situations with them. For one the developers in Bangalore Delivery Center 8, and what do I know, all of them?, had to work with their private computers. A unix engineer could only work with Aix Tar and would not touch GNU Tar on Linux, because his manager had not approved it. Onshore engineers flying home to India due to a stomach ache, instead of seeing a doctor for free in the host countr…

> Onshore engineers flying home to India due to a stomach ache, instead of seeing a doctor for free in the host country due to being afraid.

This feels like an exaggeration to me, although I'm open to hearing specifics to the contrary. I know of (non resident) immigrants who delay medical visits and treatments until they get back to their home country, but flying home (spending a good deal of money on air fare) for just a stomach ache sounds pound foolish, which immigrants generally aren't.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#193
post #143

This thread is full of generalized insults at a million people based on where they work. If someone did the same based on a different attribute of a population, they'd be banned. I've worked at one of these companies but left over a decade ago. I know how we're looked at when we do client work (part of why I left). Some of my colleagues were less competent, true. But, some will wipe the floor with the client employee…

I don't see this as a India problem, it's really an incentive problem.

In my experience the further you get from the money, the less of a shit people give. At a 5 person start up the result of any effort you put in is considerably more noticable, you don't have to share the credit of a innovation with a thicket of business analysts, scrum masters, executive vice presidents, etc. In that type of environment people tend to put more effort in as generally a sizeable portion of the rewards for that effort will find it's way to them. (Side note: this has changed with the innovation of Hollywood accounting[0] for start ups, and the number of truly innovative start ups has also seemingly declined)

Now think of a large company. The rewards tend to be nearly entirely rank based. You are a Software Engineer III, that pays between $x and $y, if you want a promotion you'll need to change fields into management. Perhaps a really bright idea or large effort will result in a small bonus, so you still have some reason to put effort in but probably won't go crazy.

Now go one step further, you are a employee of a 3rd party firm working for a large corporation. A big part of the firm's value prop is that they are cheap, as in they demand less of the reward for effort, they share a small portion of that with you but also have their own thicket of business analysts, scrum masters... you get the point. At that point honestly why bother? You have so many middle men between you and the results of your efforts that it's very unlikely that you'll ever see any meaningful reward. Just do what it takes to not get fired.

[0]https://en.m.wikipedia.org/wiki/Hollywood_accounting

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#194
post #143

This thread is full of generalized insults at a million people based on where they work. If someone did the same based on a different attribute of a population, they'd be banned. I've worked at one of these companies but left over a decade ago. I know how we're looked at when we do client work (part of why I left). Some of my colleagues were less competent, true. But, some will wipe the floor with the client employee…

I’ll take a shot at being brutally honest. I feel this in a different way. I grew up in a conservative family with some racism in its more distant ranks, thankfully with a more liberal mom to balance it out. I grew up fairly well off in a white area, where there were only ever two families of color. Both families moved away in a much shorter time than the average.

I’ve noticed that for awhile I had carried an innate aversion to offshore outsourcing, but only when it’s predominately non-white. It’s difficult to rid yourself of these intentional or unintentional exposure based thought patterns.

I had the privilege and good luck of ending up in a position where I ran an educational, science focused nonprofit. Then I started a business that had needed skills far more expensive in the US, before we could quite reach that level of expenditure. You learn quickly in those kinds of situations that if you carry those innate perspectives you can end up locking yourself away from some excellent talent; capable people who can work magic if you set them up for success.

This comment is only in reply to the topic of race. I’m not making any judgements or assertions about Infosys or any company in particular. Some companies and some people are bad at what they do, and that’s a global truth that is blind to race, culture, creed, politics, and anything else. I’m in full agreement that this type of security failing can, will, and has affected any company no matter what their employees look like or where they are based/operate.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#195

Earlier quoted context omitted.

I dispute this: I do not think you need to understand the whole stack to know using what effectively is "god mode" access is bad practice. Even if I pretend I don't know anything about AWS, if somebody handed me credentials with access called "FullAdminAccess" and told me to use them for my little script that only needs read-only access to S3 I would be extremely skeptical. The reality is that the culture at Infosys…

>Even if I pretend I don't know anything about AWS, if somebody handed me credentials with access called "FullAdminAccess" and told me to use them for my little script that only needs read-only access to S3 I would be extremely skeptical. If you ask for an access key for your little script and get one, you usually only check if it works for your case and not always check if it has any other access, so I can easily se…

It might not necessarily be the developer who's at fault, my point is more that somebody in the chain knew the request was for S3 read access and the key was for FullAdminAccess.

At my job the alarm bells would be ringing and they would bring this up, but Infosys doesn't seem to have a culture that promotes that kind of security awareness.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#196

Earlier quoted context omitted.

For those who are downvoting me, would love to hear your take instead of a salty downvote. All numbers in my post are factually correct.

I don't understand why you are being down voted. I disagree with you that they provide quality though. They don't. It is also the case that the company that hires them provide any quality. All are in it for making money with lowest spend and quality that they can get by. Very few obsess over quality and ones that do are vertically integrated to control quality in each step of the process. Very few American companies…

The engineers here need to understand the world doesn't function well if everyone waited for 100% quality before shipping something. Business trumps Engineering always. And I say this as an engineer myself.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#197

Earlier quoted context omitted.

Thank you for this! I've said the same thing and had to deal with salty downvoters earlier today. Companies pay WITCH companies billions of dollars for their services yet a lot of pretentious hackers just don't see the value.

That's just based on the ability to convince the management types though, and I'm sure you've heard of the phrase "nobody got fired for buying IBM." For an executive, it's easier to justify outsourcing to a large consulting firm simply because of the security afforded by the choice and the ease of justification; rather than any technical abilities they may or may not possess, and certainly it does not imply its corre…

Steve, how dumb do you think management is? Why would a company spend >=$1B+ in OpEx and CapEx just because somebody convinced them instead of seeing any technical value whatsoever?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#198
post #84
post #67

Earlier quoted context omitted.

GitHub always freaks out at me when I include text that even looks like a PEM cert. Too bad they can't scan for AWS key / secret variables too.

They do, this was likely in a private repo which isn’t scanned.

I pretty sure had a PEM cert in a private repo and was alerted. Is this in their TOS somewhere?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#199

Earlier quoted context omitted.

I've seen Infosys-produced code that there was no way it was going to work... turns out that after I googled it, multiple lines were straight 1:1 copy pasta from multiple StackOverflow answers - just jammed together in the hope that something would work. I was shook.

This is unfortunately common even outside of Infosys. I've experienced it at several of my former employers, although admittedly more in China than in other countries I worked. It's interesting when you sit beside a developer who does this kind of stuff in a pair-programming context, because it immediately becomes clear that they really don't have a clue how to read and understand code in the abstract. Their process…

Somehow this triggers memories of (among all things) taking exams when I was a student.

Unless you prepared well, there's often some exam questions you are clueless about, and yet there's usually no penalty for writing some bullshit in the hopes of accidentally getting a partial score. So what students are trained to do is to write whatever bullshit that seems to be relevant and hope for the best.

I realized the mindset that makes me a quality-conscious programmer is actually the anti-thesis of this. In fact during my later years I almost couldn't do that exam-bullshitting any more. It feels so bad writing something I don't understand that I almost couldn't do it.

This might be offtopic, but I guess many people who don't have a natural OCD-tendency to deeply understand their work and care about tidiness might have to actively unlearn what they trained for at least a decade in school...

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#200

Earlier quoted context omitted.

That's just based on the ability to convince the management types though, and I'm sure you've heard of the phrase "nobody got fired for buying IBM." For an executive, it's easier to justify outsourcing to a large consulting firm simply because of the security afforded by the choice and the ease of justification; rather than any technical abilities they may or may not possess, and certainly it does not imply its corre…

Steve, how dumb do you think management is? Why would a company spend >=$1B+ in OpEx and CapEx just because somebody convinced them instead of seeing any technical value whatsoever?

Management is human, just like everyone else. They absolutely make their share of truly stupid decisions. It's just they have more power, so their stupid decisions cost way more and affect more people.
Post reply on HN