Live data from Hacker News

Hacking India's largest automaker: Tata Motors

eaton-works.com

61–70 of 108 posts

Re: Hacking India's largest automaker: Tata Motors

#61
post #60

Earlier quoted context omitted.

It's a side effect of pay. Like every other company, you get what you pay for, and for organizations that view web security as a [edit:] Cost Center (eg. Tata Motors) there's no incentive to pay market rate for a Security Engineer - who in India can now demand $60k-100k TCs. Heck, firms that provide offensive security capabilities to Indian PDs can pay $40k-50k after poaching a junior pentester or exploit developer f…

> $60k-100k TC Really? I think your numbers for the local marker are overestimated.

For our portfolio companies, we are fine paying for quality instead of quantity.

Giving a Rs 60-80 lakh TC offer in BLR or HYD makes it easier to identify and hire good talent, and ik peer security firms (private and public) that are product first are offering similar TC offers in BLR, HYD, and NCR.

On top of that, there has been a reverse brain drain going on since the COVID layoffs in early 2020, so if we want to poach good talent that returned to India from the US, we need to be able to offer Western salaries, otherwise they'd either decide to help their former employer open a GCC or they'd start their own startup.

Realistically, I'd say a $35k-60k TC offer gets you the 50 to 75th percentile in talent in much of India for security, but most product-first companies tend to hire for quality not quantity, and depending on size of FDI and the state, a company can get a $10k-20k per head subsidy which makes it easier to offer higher salaries without impacting our bottom line.

That said, if you are being hired to be a SOC, a generic pentester, or a "detection engineer" you'd be lucky to break the $20k TC mark tbh, but the SOC-to-SWE or Pentester-to-SWE conversions have been our most successful ones because it's easier to build a product for security teams when your engineers were former security practitioners.

That said, the salary pressures for getting good talent in India is high simply because we're competing with Google, Microsoft, Citadel, Nvidia, etc for similar kind of talent within India.

Earning $70k-90k TC in Hyderabad or Bangalore is doable with 10 YoE if you have the right profile (the right jobs, work experience, track record, and luck). Heck, this is why companies like Zscaler have been hiring in Tier 1.5/2 cities like Pune or Chandigarh instead because you can get away with paying $35k-50k TCs for the kind of talent that would demand a $70k-90k TC in BLR or HYD.

Re: Hacking India's largest automaker: Tata Motors

#63

This might be the first time I felt disappointed and sad reading an article like this. The commented username and password felt like something from an early 2000s tv show with the tech guy doing “hacking”. Wonder how many others stumbled upon this prior, and makes me also wonder how many other sites have things like this hidden in plain sight. Insane.

This may look "boring" or "uninspired" but this is what real cybersecurity and "hacking" looks like.

In most cases, security and QA are essentially two sides of the same coin - and this is why I get pissed when devs treat testing and QA as bulls**t, becuase even a relatively simple XSS attack or cred misconfig can have a massive impact.

Re: Hacking India's largest automaker: Tata Motors

#64

Earlier quoted context omitted.

Also, Indian companies are competing with American and Israeli founded or funded companies and startups for the same talent. If you are competent, instead of earning $15k TC working for an automotive company, you could demand $40k-70k in TC from an MNC or a well funded startup (assuming you have the skills to back it up) - and those are the numbers my portfolio companies use to target hiring in India, as well as what…

Western companies have the exact same problem though; I've dealt with plenty of incompetent people there too because the organization does not reward technical excellence and quality, so it is completely pragmatic for employees to focus their time on the things that are rewarded (engaging in politics, etc) instead. During the startup/ZIRP era there might have been people doing the "right" thing because they had skin…

> I've dealt with plenty of incompetent people there too because the organization does not reward technical excellence and quality

Organizational dysfunction transcends all boundaries, but to a certain extent the kind of issues that lead to the kind of incident such as the one above happen because the affected product (e-Dukaan) is viewed as a cost center by Tata Motors.

Sadly, in most cases, a lot of security will always be viewed as a cost center and never prioritized unless forced to due to insurance, audit, or regulatory pressure.

That said, a thesis I've had for a couple years now is that if we can successfully shift-left by turning security into a DevTool problem as well as an organizational problem, we can both reduce remediation time as well as build stickiness for security products. The AppSec category has definetly adopted this kind of mindset.

Re: Hacking India's largest automaker: Tata Motors

#66

Earlier quoted context omitted.

I have heard there is a growing trend of hackers paying kickbacks to insiders, certainly makes hacking easier.

Having worked with Indian consultancy firms for over 10 years. I can safely say security attitudes and practices haven't changed much. There's always this culture of taking shortcuts at the expense of security and quality.

The challenge is this though: companies that are outsourcing to these consultancy firms put them against each other in RFPs that incentivise whatever behaviour can get them to the lowest bid.

Inevitably quality suffers. Until customers start awarding business based on something other than the number at the bottom, this kind of thing will continue.

Re: Hacking India's largest automaker: Tata Motors

#68

This might be the first time I felt disappointed and sad reading an article like this. The commented username and password felt like something from an early 2000s tv show with the tech guy doing “hacking”. Wonder how many others stumbled upon this prior, and makes me also wonder how many other sites have things like this hidden in plain sight. Insane.

This may look "boring" or "uninspired" but this is what real cybersecurity and "hacking" looks like. In most cases, security and QA are essentially two sides of the same coin - and this is why I get pissed when devs treat testing and QA as bulls**t, becuase even a relatively simple XSS attack or cred misconfig can have a massive impact.

This has nothing to do with testing. This is a lack of training.

I would say they need to 'think like an attacker' at least some of the time. But this is still too high of a bar.

I think this is really a problem of rewarding people when they finish things. One way or the other. It works, so on to the next project...

Re: Hacking India's largest automaker: Tata Motors

#69

Related: Jaguar Land Rover hack cost UK economy an estimated $2.5 billion, report says: https://news.ycombinator.com/item?id=45668008 The 'tech' for both these is by guess who? TCS! Edit: For those who don't know the relation. Tata[1] is a conglomerate, which owns both Tata Motors (Jaguar, Land Rover) and also TCS (Tata Consultancy Services) [1] https://en.wikipedia.org/wiki/Tata_Group

Very realistically, why shouldn't these developers be replaced by AI? The anti-AI argument I've always seen here is that AI is bad at security. But human developers at orgs like TCS don't seem...any better?

Re: Hacking India's largest automaker: Tata Motors

#70
post #4

Security for most Indian companies - even conglomerates is a joke. Look at the websites - most look like they've not been upgraded since the 90s, with endless popups

The customer portal of India's largest insurer with a marketcap of $63B has literally not changed even once in the 14 years that I've been using it to pay my policy premiums
Post reply on HN