Infosys leaked FullAdminAccess AWS keys on PyPi for over a year. The key was still active and still had access to what appeared to be patient data. This is definitely something that should be reported to them. It’s not a good idea to assign these to long-lived credentials issued to developers.

4m read timeFrom tomforb.es
Post cover image
Table of contents
Infosys has a lot to say about securityThe LeakThe KeysThe BucketThe PermissionsThe TakedownThe CleanupThe Conclusion

Sort: