Live data from Hacker News

Hacking India's largest automaker: Tata Motors

eaton-works.com

31–40 of 108 posts

Re: Hacking India's largest automaker: Tata Motors

#31
post #17

Earlier quoted context omitted.

TCS also contracts for Marks & Spencer, and the Co-op, both of which were also taken offline by hacking earlier this year.

At what point is it more believable that these are inside jobs done on purpose vs. incompetence? I guess that’s just Hanlon’s Razor though.

Based on my experience working alongside TCS, incompetence seems far more likely. If we'd asked for a back door, we'd have gotten a solid wall.

Then again, my experience may have left me a little jaded.

Re: Hacking India's largest automaker: Tata Motors

#32
post #4

Security for most Indian companies - even conglomerates is a joke. Look at the websites - most look like they've not been upgraded since the 90s, with endless popups

It's a side effect of pay. Like every other company, you get what you pay for, and for organizations that view web security as a [edit:] Cost Center (eg. Tata Motors) there's no incentive to pay market rate for a Security Engineer - who in India can now demand $60k-100k TCs. Heck, firms that provide offensive security capabilities to Indian PDs can pay $40k-50k after poaching a junior pentester or exploit developer f…

I understand why someone might this this is a pay issue, but it's goes beyond that.

Culturually, doing something "well"(quality oriented, mindful of end-users) vs. "got it done" (transaction, pragmatic way of looking at things) is the heart of why outsourcing to many different geographical areas (India included) often results in something different than expected.

Also condemning every one in one part of the world as thinking one way is certainly not fair or true, but there are definitely unmistakable trends.

Re: Hacking India's largest automaker: Tata Motors

#33

Earlier quoted context omitted.

At what point is it more believable that these are inside jobs done on purpose vs. incompetence? I guess that’s just Hanlon’s Razor though.

I have heard there is a growing trend of hackers paying kickbacks to insiders, certainly makes hacking easier.

Having worked with Indian consultancy firms for over 10 years. I can safely say security attitudes and practices haven't changed much.

There's always this culture of taking shortcuts at the expense of security and quality.

Re: Hacking India's largest automaker: Tata Motors

#34
This is a pessimistic comment.

I'm a cofounder of a data and identity security startup operating specifically in APAC. Data security in india a joke.

I would argue even with DPDPA, RBI C-Site and cyber resilience framework from SEBI, it is just going to not happen here.

The list PAN card the blog is taking about is probably already leaked by some other services.

The recent flipkart cash on delivery scams [1] are example of how your personal information is just out there in wild in india, open for exploitation.

There are lot of who do security in good faith (often driven by compliance) and lot of them are our customers too but I hope to see rest of indian tech ecosystem take security seriously.

[1] https://www.reddit.com/r/FuckFlipkart/comments/1hhrw9w/what_...

Re: Hacking India's largest automaker: Tata Motors

#35
post #32

Earlier quoted context omitted.

It's a side effect of pay. Like every other company, you get what you pay for, and for organizations that view web security as a [edit:] Cost Center (eg. Tata Motors) there's no incentive to pay market rate for a Security Engineer - who in India can now demand $60k-100k TCs. Heck, firms that provide offensive security capabilities to Indian PDs can pay $40k-50k after poaching a junior pentester or exploit developer f…

I understand why someone might this this is a pay issue, but it's goes beyond that. Culturually, doing something "well"(quality oriented, mindful of end-users) vs. "got it done" (transaction, pragmatic way of looking at things) is the heart of why outsourcing to many different geographical areas (India included) often results in something different than expected. Also condemning every one in one part of the world as…

Becuase it is about pay.

For example, most of the security portfolio that GCP provides is developed and product managed out of the Google Hyderabad office, as is a fairly major Israeli CNAPP product that starts with "A", a large CNAPP from a public Israeli-American security company that is directly positioned against Wiz, and a major security vuln mgmt and redteaming tool used by the DoD, GitHub, and Google. But all these employers pay $60k-130k TC for mid-career security professionals in India.

We scoop up anyone who is remotely competent at transnational firms or startups because we can afford to pay Western salaries, and traditional conglomerates in India largely do not care about web exploits unless they are a web platform first and foremost.

Tata Motors - being an automotive company - does not care about web development for the same reason GM doesn't as well: it isn't tangibly connected to revenue generation. As such, they will just contract it out to TCS (a Tata Group company, but both are independent of each other) at the lowest contract rate possible.

Re: Hacking India's largest automaker: Tata Motors

#36
post #32

Earlier quoted context omitted.

It's a side effect of pay. Like every other company, you get what you pay for, and for organizations that view web security as a [edit:] Cost Center (eg. Tata Motors) there's no incentive to pay market rate for a Security Engineer - who in India can now demand $60k-100k TCs. Heck, firms that provide offensive security capabilities to Indian PDs can pay $40k-50k after poaching a junior pentester or exploit developer f…

I understand why someone might this this is a pay issue, but it's goes beyond that. Culturually, doing something "well"(quality oriented, mindful of end-users) vs. "got it done" (transaction, pragmatic way of looking at things) is the heart of why outsourcing to many different geographical areas (India included) often results in something different than expected. Also condemning every one in one part of the world as…

That culture at WITCH and WITCh adjacent companies is itself a result of the pay.

Re: Hacking India's largest automaker: Tata Motors

#38

This is a pessimistic comment. I'm a cofounder of a data and identity security startup operating specifically in APAC. Data security in india a joke. I would argue even with DPDPA, RBI C-Site and cyber resilience framework from SEBI, it is just going to not happen here. The list PAN card the blog is taking about is probably already leaked by some other services. The recent flipkart cash on delivery scams [1] are exam…

I've dealt with Indian companies for security sales and I'd say the newer generation of companies like Razorpay (YC W15) are decent at SecOps, but the older and more established companies suck at it and will continue to suck at it until there is a tangible regulatory incentive to enhance security postures.

It also appears to be a side effect of compensation - why would mid-career security professional want to earn ₹15 LPA TC working for a legacy corporation if they have the skills to land at a security MNC that can afford to pay ₹35-50 LPA in TC.

Ofc, it's us foreign investors who are able to afford those higher TCs ;) - especially if we can convert someone who was mid-career in the US but had to return to India due to family or visa issues.

It reminds me of how the Israeli security scene was 10-15 years ago, with similar problems around compensation and brain drain to MNC offices.

Re: Hacking India's largest automaker: Tata Motors

#39
post #32

Earlier quoted context omitted.

It's a side effect of pay. Like every other company, you get what you pay for, and for organizations that view web security as a [edit:] Cost Center (eg. Tata Motors) there's no incentive to pay market rate for a Security Engineer - who in India can now demand $60k-100k TCs. Heck, firms that provide offensive security capabilities to Indian PDs can pay $40k-50k after poaching a junior pentester or exploit developer f…

I understand why someone might this this is a pay issue, but it's goes beyond that. Culturually, doing something "well"(quality oriented, mindful of end-users) vs. "got it done" (transaction, pragmatic way of looking at things) is the heart of why outsourcing to many different geographical areas (India included) often results in something different than expected. Also condemning every one in one part of the world as…

Pay should reward doing something well vs merely doing something. Of course, this would generally mean you need to pay more than the competitor which will happily pay for merely doing something. So yes it is about pay.

Re: Hacking India's largest automaker: Tata Motors

#40

Earlier quoted context omitted.

I have heard there is a growing trend of hackers paying kickbacks to insiders, certainly makes hacking easier.

Having worked with Indian consultancy firms for over 10 years. I can safely say security attitudes and practices haven't changed much. There's always this culture of taking shortcuts at the expense of security and quality.

One of the problems with incompetence, of which there are many, is that it gives bad actors space to operate. From a security point of view I don’t think the distinction matters all that much.

That said, the situations I’ve head about were from affiliate ransomware attacks that didn’t make the news because the backup worked. It’s difficult to keep things secure from highly motivated internal bad actors. I’ve been told it’s an increasing trend but have not heard much about it publicly.

Post reply on HN