Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

211–218 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#211

Earlier quoted context omitted.

I disagree, it takes lots of time but it is possible. Personal example: I have an electronics engineering degree that was 1 semester short of a physics degree, so I learned quantum mechanics, electromagnetic field theory, transistors, and how to create a CPU (I even created a CPU out of simple gates and way too much wire wrapping). I love computer software, so I learned assembly, how to write compilers and operating…

Jack of all trades, master of none. I don't think it's bad at all: at least you can specialise at something (quicker) whenever the need arises.

It's relatively easy to learn a new language (for example) when you think, "this is like x, this is like Y, etc."

I guess my key point is that you always need to keep learning, and don't box yourself in too much. Ideas from elsewhere will show up... being aware of them makes it easier to use them and be ready for them.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#212
post #149

Earlier quoted context omitted.

I think you are misunderstanding what these companies have deals with Infosys for. It's not because they're so competent, it's because they're a convenient scapegoat when things inevitably go wrong. Things inevitably go wrong for them because people hiring a company like Infosys do not want to be told how to do tech by competent engineers (and are probably not able to distinguish competent from incompetent engineers…

Yeah, right. Vanguard is paying a billion dollars, and Daimler is paying three billion dollars to Infosys because they are a "convenient scapegoat"?

It makes me sad to hear that Daimler - or any other large company that can afford better pays something for WITCH companies

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#213

Earlier quoted context omitted.

>Programming/anything to do with PCs in India is a rich man’s hobby. This is not true. We had a good culture of self assembled PC enthusiasts in our district. This was in early 2000s. In fact it has reduced now maybe due to lack of interest or something even though the prices of PCs have dropped significantly. I see many people use their PCs as locked up phones with no curiosity of hardware. >Tinkering is not encoura…

>This is not true. It is absolutely true. Just because you don't consider yourself rich doesn't mean that these devices aren't out of the reach of a vast majority of the population. Almost everyone has access to a smartphone, but most of those are poorly made, overheating pieces of plastic - barely suitable for use as a phone, let alone as a computing device on which you can learn something. In my second statement, I…

The resources that we have now is way better than what we had in our time. The interest amongst students have been more or less the same.

>that given an average Indian programmer, they are more likely to be someone who got educated in a substandard setting among unmotivated peers

This too has not changed much from our time to now. The changes I have noticed in students is the rise of memorizing leetcode type problems due to the plentiful jobs now which need this skill for interviewing.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#214

Is it possible to do a full sweep across all tokens in all Python files (for instance) in Github and find such keys? Can you tell from the contents if it's a key or some such "important" string?

Yep, and if you don't look for them, you can be darn sure someone else is looking for them. I heard about an incident from a friend where a GitHub repo was created accidentally public (ran out of private repos and I guess the failure mode back in the day was just make it public) and that repo had developer level access keys in it. Some enterprising fellow was scanning public repos for this, grabbed the keys, opened t…

That's not nice, that's just smart. Delete production, and someone will notice right away. Leave production as it is, and they might not notice until the bill comes due.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#216
post #50

Earlier quoted context omitted.

Fun fact: Mozilla projects are now developed in part by Cognizant Softvision, including Firefox for Android. Their employees are everywhere on Mozilla bug trackers, and their numbers seem to have increased since 2020, right after Mozilla fired a quarter of its workforce. https://www.cognizantsoftvision.com/blog/pedal-metal-mozilla...

This pisses me straight off. Someone needs to fork Mozilla (the company) and bring back its hayday culture.

Already happened years ago, if you want the old Firefox with XUL extension support, full themes and zero tracking as it was before they started copying Chrome in 2011, give Pale Moon a try. It's an independent fork, the last independent browser left, with its own rendering engine Goanna that is a fork of Firefox's Gecko.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#217

> To put it bluntly, I’m not sure I trusted Infosys to revoke this key in a timely manner. So I did it for them with aws iam delete-access-key --access-key-id=$AWS_ACCESS_KEY_ID, and now the key is useless: Hilarious. Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. No competent employee stays in those companies (from what I've…

> Infosys is a known "mass recruiter" in indian colleges. WITCH (Wipro, Infosys, TCS, Cognizant, HCL) companies is where talent goes to die. This could be true but you cant really generalize and it has nothing to do with the article. Infosys is not the only company leaking keys online. pretty sure tons of Amarican companies have done that

Infosys bot spotted. 'Amarican' companies eh?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#218

Earlier quoted context omitted.

Yeah, right. Vanguard is paying a billion dollars, and Daimler is paying three billion dollars to Infosys because they are a "convenient scapegoat"?

It makes me sad to hear that Daimler - or any other large company that can afford better pays something for WITCH companies

so much salt!
Post reply on HN