Live data from Hacker News

Hacking India's largest automaker: Tata Motors

eaton-works.com

41–50 of 108 posts

Re: Hacking India's largest automaker: Tata Motors

#41
post #32

Earlier quoted context omitted.

I understand why someone might this this is a pay issue, but it's goes beyond that. Culturually, doing something "well"(quality oriented, mindful of end-users) vs. "got it done" (transaction, pragmatic way of looking at things) is the heart of why outsourcing to many different geographical areas (India included) often results in something different than expected. Also condemning every one in one part of the world as…

Pay should reward doing something well vs merely doing something. Of course, this would generally mean you need to pay more than the competitor which will happily pay for merely doing something. So yes it is about pay.

Also, Indian companies are competing with American and Israeli founded or funded companies and startups for the same talent.

If you are competent, instead of earning $15k TC working for an automotive company, you could demand $40k-70k in TC from an MNC or a well funded startup (assuming you have the skills to back it up) - and those are the numbers my portfolio companies use to target hiring in India, as well as what I used previously before I became a VC.

Re: Hacking India's largest automaker: Tata Motors

#42

Earlier quoted context omitted.

Pay should reward doing something well vs merely doing something. Of course, this would generally mean you need to pay more than the competitor which will happily pay for merely doing something. So yes it is about pay.

Also, Indian companies are competing with American and Israeli founded or funded companies and startups for the same talent. If you are competent, instead of earning $15k TC working for an automotive company, you could demand $40k-70k in TC from an MNC or a well funded startup (assuming you have the skills to back it up) - and those are the numbers my portfolio companies use to target hiring in India, as well as what…

Western companies have the exact same problem though; I've dealt with plenty of incompetent people there too because the organization does not reward technical excellence and quality, so it is completely pragmatic for employees to focus their time on the things that are rewarded (engaging in politics, etc) instead.

During the startup/ZIRP era there might have been people doing the "right" thing because they had skin in the game thanks to stock options or they were paid just so fucking much that they didn't care about putting in the extra work. But as total comps go downward (coupled with inflation) the output's quality tends to regress to the minimum acceptable.

Re: Hacking India's largest automaker: Tata Motors

#43
post #17

Earlier quoted context omitted.

TCS also contracts for Marks & Spencer, and the Co-op, both of which were also taken offline by hacking earlier this year.

Note that M&S dropped TCS in July following the recovery. https://www.ft.com/content/289ec371-2ed4-425a-9bd0-c34e6db39... and elsewhere.

> M&S chair, told MPs that hackers had used “sophisticated impersonation” to gain entry “involving a third party.”

20 bucks says this sophisticated impersonation was social engineering a $5/hour outsourced customer support employee

> The attack is expected to lower operating profits by up to £300mn this year.

that's not counting the reputation and brand damage. M&S is seen as a premium retailer and this whole hack made them seem utterly incompetent and unreliable

> had decided to opt for another service provider after the process had completed

i wonder where this other provider is based. i think i'm gonna place another 20 bucks on this.

> The retailer continues to use the Indian group for other services.

lol.

Re: Hacking India's largest automaker: Tata Motors

#44
post #17

Earlier quoted context omitted.

TCS also contracts for Marks & Spencer, and the Co-op, both of which were also taken offline by hacking earlier this year.

At what point is it more believable that these are inside jobs done on purpose vs. incompetence? I guess that’s just Hanlon’s Razor though.

When you pay your support employees so little, it's not difficult for someone from a wealthier place to bribe them.

Re: Hacking India's largest automaker: Tata Motors

#46
post #32

Earlier quoted context omitted.

It's a side effect of pay. Like every other company, you get what you pay for, and for organizations that view web security as a [edit:] Cost Center (eg. Tata Motors) there's no incentive to pay market rate for a Security Engineer - who in India can now demand $60k-100k TCs. Heck, firms that provide offensive security capabilities to Indian PDs can pay $40k-50k after poaching a junior pentester or exploit developer f…

I understand why someone might this this is a pay issue, but it's goes beyond that. Culturually, doing something "well"(quality oriented, mindful of end-users) vs. "got it done" (transaction, pragmatic way of looking at things) is the heart of why outsourcing to many different geographical areas (India included) often results in something different than expected. Also condemning every one in one part of the world as…

I dont think there's much culture when the population is just overloaded with work and traffic and stress

Re: Hacking India's largest automaker: Tata Motors

#47

Earlier quoted context omitted.

Note that M&S dropped TCS in July following the recovery. https://www.ft.com/content/289ec371-2ed4-425a-9bd0-c34e6db39... and elsewhere.

> M&S chair, told MPs that hackers had used “sophisticated impersonation” to gain entry “involving a third party.” 20 bucks says this sophisticated impersonation was social engineering a $5/hour outsourced customer support employee > The attack is expected to lower operating profits by up to £300mn this year. that's not counting the reputation and brand damage. M&S is seen as a premium retailer and this whole hack ma…

>that's not counting the reputation and brand damage. M&S is seen as a premium retailer and this whole hack made them seem utterly incompetent and unreliable

>>The retailer continues to use the Indian group for other services.

>lol.

>is seen

lol. a lot of things are seen as blah blah. doesn't mean they are blah blah.

google is seen as a world leading tech company. yet see how HNers regard them (except those desperate for FAANG salaries).

If they hired their vendors without due diligence, they may be incompetent and unreliable themselves. On the other hand:

>> M&S chair, told MPs that hackers had used “sophisticated impersonation” to gain entry “involving a third party.”

If the impersonation was sophisticated, maybe it was not so much the fault of TCS?

If it was a Western company, would you talk / think the same?

Nahi. Non. Nein. Nyet. Nada.

lol.

Re: Hacking India's largest automaker: Tata Motors

#48
post #32

Earlier quoted context omitted.

It's a side effect of pay. Like every other company, you get what you pay for, and for organizations that view web security as a [edit:] Cost Center (eg. Tata Motors) there's no incentive to pay market rate for a Security Engineer - who in India can now demand $60k-100k TCs. Heck, firms that provide offensive security capabilities to Indian PDs can pay $40k-50k after poaching a junior pentester or exploit developer f…

I understand why someone might this this is a pay issue, but it's goes beyond that. Culturually, doing something "well"(quality oriented, mindful of end-users) vs. "got it done" (transaction, pragmatic way of looking at things) is the heart of why outsourcing to many different geographical areas (India included) often results in something different than expected. Also condemning every one in one part of the world as…

It is about pay. If you don’t have someone working on 5 different items continuously straining their bandwidth they tend to do better work.

Re: Hacking India's largest automaker: Tata Motors

#49

Earlier quoted context omitted.

Note that M&S dropped TCS in July following the recovery. https://www.ft.com/content/289ec371-2ed4-425a-9bd0-c34e6db39... and elsewhere.

> M&S chair, told MPs that hackers had used “sophisticated impersonation” to gain entry “involving a third party.” 20 bucks says this sophisticated impersonation was social engineering a $5/hour outsourced customer support employee > The attack is expected to lower operating profits by up to £300mn this year. that's not counting the reputation and brand damage. M&S is seen as a premium retailer and this whole hack ma…

>20 bucks says this sophisticated impersonation was social engineering a $5/hour outsourced customer support employee

0 bucks says this below list of data breaches is much much more devastating. 0 bucks, because I don't have to bet on it, unlike you, because it's true:

>https://en.wikipedia.org/wiki/List_of_data_breaches

>This is a list of reports about data breaches, using data compiled from various sources, including press reports, government news releases, and mainstream news articles. The list includes those involving the theft or compromise of 30,000 or more records, although many smaller breaches occur continually. Breaches of large organizations where the number of records is still unknown are also listed. In addition, the various methods used in the breaches are listed, with hacking being the most common.

>Most reported breaches are in North America, at least in part because of relatively strict disclosure laws in North American countries.[citation needed] 95% of data breaches come from government, retail, or technology industries.[1] It is estimated that the average cost of a data breach will be over $150 million by 2020, with the global annual cost forecast to be $2.1 trillion.[2][3] As a result of data breaches, it is estimated that in first half of 2018 alone, about 4.5 billion records were exposed.[4] In 2019, a collection of 2.7 billion identity records, consisting of 774 million unique email addresses and 21 million unique passwords, was posted on the web for sale.[5] In January 2024, a data breach dubbed the "mother of all breaches" was uncovered.[6] Over 26 billion records, including some from Twitter, Adobe, Canva, LinkedIn, and Dropbox, were found in the database.[7][8] No organization immediately claimed responsibility.[9]

>In August 2024, one of the largest data security breaches was revealed. It involved the background check databroker, National Public Data and exposed the personal information of nearly 3 billion people.[10]

Post reply on HN