Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
speckx
64 days ago
|
parent
|
context
|
favorite
| on:
Hacking India's largest automaker: Tata Motors
The fact that they put their AWS secret keys on their website is incredible.
quickthrowman
64 days ago
|
next
[–]
That’s exactly the kind of work I’d expect from TCS, I’m not sure why you are surprised.
Linkd
64 days ago
|
prev
|
next
[–]
The fact that it's nicely commented is even more so. Check out the other environment configs commented out, are they doing this by hand? Wild.
darth_avocado
64 days ago
|
prev
|
next
[–]
Even more importantly, why do the root keys expose EVERYTHING? Do they just have one account for all of their infra?
YetAnotherNick
64 days ago
|
prev
|
next
[–]
Sending it with AES encryption(with the key that the client has access to) makes it even worse, as someone knew this shouldn't be shared to client yet they shared it anyway.
horns4lyfe
64 days ago
|
prev
[–]
If you’ve ever worked with Indian outsourcing firms it’s not
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: