Live data from Hacker News

Hacking India's largest automaker: Tata Motors

eaton-works.com

21–30 of 108 posts

Re: Hacking India's largest automaker: Tata Motors

#21
post #17

Earlier quoted context omitted.

TCS also contracts for Marks & Spencer, and the Co-op, both of which were also taken offline by hacking earlier this year.

At what point is it more believable that these are inside jobs done on purpose vs. incompetence? I guess that’s just Hanlon’s Razor though.

I have heard there is a growing trend of hackers paying kickbacks to insiders, certainly makes hacking easier.

Re: Hacking India's largest automaker: Tata Motors

#23
I'll just leave this here:

> September 1, 2023: Tata Motors shared with CERT-IN (who then shared with me) that the issues are remediated. September 3, 2023: I confirm only 2/4 issues were remediated and the AWS keys were still present on the websites, and active. October 22, 2023: After no updates and finding the AWS issues still not remediated, I send over some more specific steps on what must be done. October 23, 2023: They confirm receipt and are working on taking action. After this date and up until January 2, 2024, there were various back and forth emails trying to get Tata Motors to revoke the AWS keys. I am not sure if something was lost in translation, but it took a lot of pestering and specific instructions to get it done.

Stay classy TCS.

Re: Hacking India's largest automaker: Tata Motors

#24
post #4

Security for most Indian companies - even conglomerates is a joke. Look at the websites - most look like they've not been upgraded since the 90s, with endless popups

> endless popups Ypu get popups? What are you using to browse? IE5? I sometimes get 'this site is trying to open another window -allow/ block?': answer is always 'No'.

Not ad popups, site UI popups.

Another example, financial services publicly traded company with a recent 99% profit decline:

https://www.emkayglobal.com/

Re: Hacking India's largest automaker: Tata Motors

#26
post #4

Security for most Indian companies - even conglomerates is a joke. Look at the websites - most look like they've not been upgraded since the 90s, with endless popups

> endless popups Ypu get popups? What are you using to browse? IE5? I sometimes get 'this site is trying to open another window -allow/ block?': answer is always 'No'.

In site modals.

Re: Hacking India's largest automaker: Tata Motors

#27
post #6
post #3

So the author got nothing but a thank you out of it? That's a shame.

At least there was a "thank you". Some go on to sue such researchers.

Yup, they said thank you and took action only because this was a US-based researcher. Had any Indian dared to do this they'd be in for a world of pain. Not through a lawsuit, but criminal charges.

Re: Hacking India's largest automaker: Tata Motors

#28
post #17

Related: Jaguar Land Rover hack cost UK economy an estimated $2.5 billion, report says: https://news.ycombinator.com/item?id=45668008 The 'tech' for both these is by guess who? TCS! Edit: For those who don't know the relation. Tata[1] is a conglomerate, which owns both Tata Motors (Jaguar, Land Rover) and also TCS (Tata Consultancy Services) [1] https://en.wikipedia.org/wiki/Tata_Group

TCS also contracts for Marks & Spencer, and the Co-op, both of which were also taken offline by hacking earlier this year.

Note that M&S dropped TCS in July following the recovery. https://www.ft.com/content/289ec371-2ed4-425a-9bd0-c34e6db39... and elsewhere.

Re: Hacking India's largest automaker: Tata Motors

#29
post #17

Earlier quoted context omitted.

TCS also contracts for Marks & Spencer, and the Co-op, both of which were also taken offline by hacking earlier this year.

At what point is it more believable that these are inside jobs done on purpose vs. incompetence? I guess that’s just Hanlon’s Razor though.

It's perfectly believable. Whether it is more believable or not is a toss up. If you employ such a large number of people there are bound to be a couple of bad apples, and unless you have very good internal processes and monitoring it isn't all that hard to imagine someone doing something they shouldn't be doing. But absent hard evidence that it happened that way it interesting speculation but no more than that, besides, it can be impossible to distinguish between the two even if you have evidence of an inside job that looks like incompetence!
Post reply on HN