news.volyx.in

Infosys leaked FullAdminAccess AWS keys on PyPI for over a year (tomforb.es)

502 points by orf · 1391 days ago · 201 comments on HN

Article summary

Infosys leaked AWS keys with FullAdminAccess on PyPI for over a year. The comments discuss the implications of this leak and the company's cybersecurity practices. The leak was eventually revoked by an external party. The incident raises concerns about the company's security awareness and practices.

Main themes

  • cybersecurity practices
  • security awareness
  • technology stack understanding
  • company culture
  • security vs productivity
  • automated scanning and revocation
  • employee competence

What commenters say

  • Leaking AWS keys with FullAdminAccess is a serious security mistake that can have significant consequences.
  • The incident reflects a lack of security awareness and poor cybersecurity practices within the company.
  • Understanding the full technology stack is not necessary to recognize and prevent basic security mistakes like this leak.
  • The culture of some companies prioritizes productivity over security, leading to a lack of attention to detail and oversight.
  • Revoking the leaked key was the right thing to do, despite potential disruptions, to prevent further security risks.
  • The leak may be a symptom of a broader problem with the company's approach to security and employee competence.
  • Automated scanning and revocation of leaked keys can help prevent similar incidents in the future.
  • Companies should prioritize security awareness and education to prevent similar mistakes.