Live data from Hacker News

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

tomforb.es

111–120 of 218 posts

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#111
post #98

The Indian government has, over the years, awarded contracts worth billions of dollars to Infosys for projects like the Goods and Service Tax portal, Income Tax portal. In all these cases, the implementations are slow and super buggy. Deadlines to deliver are routinely missed. In an ideal world, these companies should not be allowed to exist.

You seem to be suffering from inferiority complex issues. Please fix your own thinking's buggy implementation before commenting about others.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#112

Earlier quoted context omitted.

This pisses me straight off. Someone needs to fork Mozilla (the company) and bring back its hayday culture.

they went woke, and are on the path to go broke. Sadly, they’re the only mainstream competition to Chrome.

> and are on the path to go broke. Sadly, they’re the only mainstream competition to Chrome.

Is it overly cynical of me to wonder if this is Google's doing? Setting someone to infiltrate Mozilla's management and sabotage it, with the long-term goal of killing all serious non-chromium alternatives.

I don't know about the woke thing, I figure it's more likely to be about removing ad-block friendly API's in Manifest V3 (and presumably even more hostile changes in some future Manifest V4).

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#113
I am so glad I did not pursue a job with them out of college, infosys that is. I told them I was no longer interested and they kept calling my parent's house and even tried recruiting my sister who was in HS.

How they go about stuff with that felt so weird, cause I would never get the same recruiter, makes sense they would do something like this.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#114

Is it possible to do a full sweep across all tokens in all Python files (for instance) in Github and find such keys? Can you tell from the contents if it's a key or some such "important" string?

Yep, and if you don't look for them, you can be darn sure someone else is looking for them. I heard about an incident from a friend where a GitHub repo was created accidentally public (ran out of private repos and I guess the failure mode back in the day was just make it public) and that repo had developer level access keys in it. Some enterprising fellow was scanning public repos for this, grabbed the keys, opened t…

No post body was provided.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#115

Earlier quoted context omitted.

You assume they have a security team :)

They will have ten security teams at the minimum. You assume that their teams know what security means though :)

This is an accurate assessment. Having worked for companies similar to Infosys, I can confirm this.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#116
post #5

Wow. Really crazy. I know it was not right to revoke the key, he touched into their system. He probably broke someone’s production. But it was also absolutely the right thing to do. A god mode key floating around for over a year unrevoked, with real human beings’s medical data on the other side… I am glad the post author revoked the key. It is probably too little too late but they did close that door and maybe saved…

What are the chances someone goes and gets a new key and then immediately checks it into git on top of the old key?

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#117
If you've ever used a third-party outsourcing company like Infosys, Tata, Cognizant, or whoever you know you get literally nothing of value back for what you pay. Unfortunately, it's usually a cost-cutting movie that executives love and defers the pain to another day and creates another mess for someone else to deal with.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#118

> Johns_Hopkins_Hospital/Input/Excel/Covid_patientdetails/covid_patient_details.xlsx Should I file the HIPAA complaint, or has someone else already done that? (the stupid government website for filing complaints is, of course, not loading for me now)

Pro tip: https://www.hopkinsmedicine.org/institutional_review_board/h...

The breach notification to HHS typically comes from the covered entity. They often have the information on exactly what PHI was out there, how many individuals were impacted, and can provide the right info to HHS.

And with my experience in healthcare IT, I can say privacy and compliance officers take reports like this incredibly seriously. Those might not be the right people but getting an email to compliance folks inside the covered entity and saying “here’s a likely breach” will absolutely get the ball rolling.

Re: Infosys leaked FullAdminAccess AWS keys on PyPI for over a year

#119

I really wish this surprised me. The number of people who completely understand the stack they are working on is shrinking, even as the size of the stack grows. The power of computing is such that every organization on the planet is forced to lower the bar to get people who are marginally competent, even if they lack attention detail and cannot be relied on to solve problems of this sort. This kind of leak is the res…

I dispute this: I do not think you need to understand the whole stack to know using what effectively is "god mode" access is bad practice.

Even if I pretend I don't know anything about AWS, if somebody handed me credentials with access called "FullAdminAccess" and told me to use them for my little script that only needs read-only access to S3 I would be extremely skeptical.

The reality is that the culture at Infosys seems to place zero value on security of customer data.

Post reply on HN