Live data from Hacker News

Hacking India's largest automaker: Tata Motors

eaton-works.com

71–80 of 108 posts

Re: Hacking India's largest automaker: Tata Motors

#71

> As recently seen with Intel, there seems to be a trend where developers will do this pointless client-side decryption. When the client has the key, it’s strange that anyone would think that would be secure. I stay and work in India. Yesterday, as part of a VAPT audit by a third party auditor, the auditors "recommended" that we do exactly this. I wonder if this directive comes as part of some outdated cyber security…

lmao

burp suite babies is crazy work

Re: Hacking India's largest automaker: Tata Motors

#72

Earlier quoted context omitted.

Note that M&S dropped TCS in July following the recovery. https://www.ft.com/content/289ec371-2ed4-425a-9bd0-c34e6db39... and elsewhere.

> M&S chair, told MPs that hackers had used “sophisticated impersonation” to gain entry “involving a third party.” 20 bucks says this sophisticated impersonation was social engineering a $5/hour outsourced customer support employee > The attack is expected to lower operating profits by up to £300mn this year. that's not counting the reputation and brand damage. M&S is seen as a premium retailer and this whole hack ma…

I doubt many people shopping for a sandwich and an unfashionable suit will be thinking about the M&S hack.

Re: Hacking India's largest automaker: Tata Motors

#74
Users in India wouldn't care that much about privacy of their data as much as the Western folks do. This reduces the importance of this whole episode and I don't think this news flashed across TV screens or caused a debate anywhere.

India is a karma society. Karma doesn't mean upvotes. It means, you get what you destined for, or what you deserve. People take things in their stride and keep moving, while keeping their eyes wide open. When you are moving through a jungle, there is no point in blaming thorns or getting angry on wild animals.

Re: Hacking India's largest automaker: Tata Motors

#75
post #32

Earlier quoted context omitted.

I understand why someone might this this is a pay issue, but it's goes beyond that. Culturually, doing something "well"(quality oriented, mindful of end-users) vs. "got it done" (transaction, pragmatic way of looking at things) is the heart of why outsourcing to many different geographical areas (India included) often results in something different than expected. Also condemning every one in one part of the world as…

I dont think there's much culture when the population is just overloaded with work and traffic and stress

It's absolutely the culture, "Chalta Hai" attitude is the culture. (Take it easy, let it go)

Re: Hacking India's largest automaker: Tata Motors

#76
post #68

Earlier quoted context omitted.

This may look "boring" or "uninspired" but this is what real cybersecurity and "hacking" looks like. In most cases, security and QA are essentially two sides of the same coin - and this is why I get pissed when devs treat testing and QA as bulls**t, becuase even a relatively simple XSS attack or cred misconfig can have a massive impact.

This has nothing to do with testing. This is a lack of training. I would say they need to 'think like an attacker' at least some of the time. But this is still too high of a bar. I think this is really a problem of rewarding people when they finish things. One way or the other. It works, so on to the next project...

> This has nothing to do with testing.

A good QA can catch/test such security issues although most of such work is given to a dedicated pen tester to find weakness in the platform.

Re: Hacking India's largest automaker: Tata Motors

#77
post #74

Users in India wouldn't care that much about privacy of their data as much as the Western folks do. This reduces the importance of this whole episode and I don't think this news flashed across TV screens or caused a debate anywhere. India is a karma society. Karma doesn't mean upvotes. It means, you get what you destined for, or what you deserve. People take things in their stride and keep moving, while keeping their…

So basically you are saying that India is a society that is still soaked in an ideology that justifies the special privileges of temple staff and tells peasants that being a sharecropper in a rent for protection racket is their own fault, so hand it over, and moreso that you approve. You sound like every temple staff worker ever. Grow up.

Re: Hacking India's largest automaker: Tata Motors

#78

> As recently seen with Intel, there seems to be a trend where developers will do this pointless client-side decryption. When the client has the key, it’s strange that anyone would think that would be secure. I stay and work in India. Yesterday, as part of a VAPT audit by a third party auditor, the auditors "recommended" that we do exactly this. I wonder if this directive comes as part of some outdated cyber security…

You’re right, of course, but this reminds me of when Chrome didn’t obscure your passwords when looking at its autofill settings. The developers argued that it would just be security by obscurity -- if somebody has access to your computer when it’s unlocked, they can do anything they want, so obscuring your passwords does nothing.

The counter-argument is, even if it’s not perfectly secure, that extra bit of friction before you can see the passwords is useful, and may just save your bacon if a casual thief has access to your computer for a few seconds.

The Chrome team eventually saw sense and added some client-side password protection.

As long as you don’t only have client-side protections, of course (and maybe your clueless auditors were making that mistake).

Re: Hacking India's largest automaker: Tata Motors

#79
post #77
post #74

Users in India wouldn't care that much about privacy of their data as much as the Western folks do. This reduces the importance of this whole episode and I don't think this news flashed across TV screens or caused a debate anywhere. India is a karma society. Karma doesn't mean upvotes. It means, you get what you destined for, or what you deserve. People take things in their stride and keep moving, while keeping their…

So basically you are saying that India is a society that is still soaked in an ideology that justifies the special privileges of temple staff and tells peasants that being a sharecropper in a rent for protection racket is their own fault, so hand it over, and moreso that you approve. You sound like every temple staff worker ever. Grow up.

Go out into rural India and ask someone if they care about someone knowing their contact details. Same with 90% of city folks. By the way, growing up may not be so cool. For you.

Re: Hacking India's largest automaker: Tata Motors

#80

> As recently seen with Intel, there seems to be a trend where developers will do this pointless client-side decryption. When the client has the key, it’s strange that anyone would think that would be secure. I stay and work in India. Yesterday, as part of a VAPT audit by a third party auditor, the auditors "recommended" that we do exactly this. I wonder if this directive comes as part of some outdated cyber security…

Appreciate the insight!
Post reply on HN