32 ms·
Hacking India's largest automaker: Tata Motors
- guluarte 11mo agoprotip: never trust the client
- speckx 11mo agoThe fact that they put their AWS secret keys on their website is incredible.
- YetAnotherNick 11mo agoSending it with AES encryption(with the key that the client has access to) makes it even worse, as someone knew this shouldn't be shared to client yet they shared it anyway.
- deleted 11mo ago[deleted]
- horns4lyfe 11mo agoIf you’ve ever worked with Indian outsourcing firms it’s not
- quickthrowman 11mo agoThat’s exactly the kind of work I’d expect from TCS, I’m not sure why you are surprised.
- darth_avocado 11mo agoEven more importantly, why do the root keys expose EVERYTHING? Do they just have one account for all of their infra?
- Linkd 11mo agoThe fact that it's nicely commented is even more so. Check out the other environment configs commented out, are they doing this by hand? Wild.
- ksynwa 11mo agoSo the author got nothing but a thank you out of it? That's a shame.
- tehlike 11mo agoAt least there was a "thank you". Some go on to sue such researchers.
- paxys 11mo agoYup, they said thank you and took action only because this was a US-based researcher. Had any Indian dared to do this they'd be in for a world of pain. Not through a lawsuit, but criminal charges.
- deleted 11mo ago[deleted]
- DaSHacka 11mo agoTypical 'payout' for ""responsible"" disclosure.
- sharadov 11mo agoSecurity for most Indian companies - even conglomerates is a joke. Look at the websites - most look like they've not been upgraded since the 90s, with endless popups
- Ylpertnodi 11mo ago> endless popups Ypu get popups? What are you using to browse? IE5? I sometimes get 'this site is trying to open another window -allow/ block?': answer is always 'No'.
- fakedang 11mo agoNot ad popups, site UI popups. Another example, financial services publicly traded company with a recent 99% profit decline: https://www.emkayglobal.com/ https://www.emkayglobal.com/
- renewiltord 11mo agoIn site modals.
- alephnerd 11mo agoIt's a side effect of pay. Like every other company, you get what you pay for, and for organizations that view web security as a [edit:] Cost Center (eg. Tata Motors) there's no incentive to pay market rate for a Security Engineer - who in India can now demand $60k-100k TCs. Heck, firms that provide offensive security capabilities to Indian PDs can pay $40k-50k after poaching a junior pentester or exploit developer from a PD.
- thelastgallon 11mo agoRelated: Jaguar Land Rover hack cost UK economy an estimated $2.5 billion, report says: https://news.ycombinator.com/item?id=45668008 https://news.ycombinator.com/item?id=45668008 The 'tech' for both these is by guess who? TCS! Edit: For those who don't know the relation. Tata[1] is a conglomerate, which owns both Tata Motors (Jaguar, Land Rover) and also TCS (Tata Consultancy Services) [1] https://en.wikipedia.org/wiki/Tata_Group https://en.wikipedia.org/wiki/Tata_Group
- cjs_ac 11mo agoTCS also contracts for Marks & Spencer, and the Co-op, both of which were also taken offline by hacking earlier this year.
- Mistletoe 11mo agoAt what point is it more believable that these are inside jobs done on purpose vs. incompetence? I guess that’s just Hanlon’s Razor though.
- cjbgkagh 11mo agoI have heard there is a growing trend of hackers paying kickbacks to insiders, certainly makes hacking easier.
- CommanderData 11mo agoHaving worked with Indian consultancy firms for over 10 years. I can safely say security attitudes and practices haven't changed much. There's always this culture of taking shortcuts at the expense of security and quality.
- cjbgkagh 11mo agoOne of the problems with incompetence, of which there are many, is that it gives bad actors space to operate. From a security point of view I don’t think the distinction matters all that much. That said, the situations I’ve head about were from affiliate ransomware attacks that didn’t make the news because the backup worked. It’s difficult to keep things secure from highly motivated internal bad actors. I’ve been told it’s an increasing trend but have not heard much about it publicly.
- rdtsc 11mo ago> October 23, 2023: They confirm receipt and are working on taking action. After this date and up until January 2, 2024, there were various back and forth emails trying to get Tata Motors to revoke the AWS keys. I am not sure if something was lost in translation, but it took a lot of pestering and specific instructions to get it done. Wow, they had to go out of their way and plead with Tata Motors to fix their own shit. I can only admire their patience. Can't say I would be that patient.
- spprashant 11mo agoThis is embarrassing.
- fakedang 11mo agoI'll just leave this here: > September 1, 2023: Tata Motors shared with CERT-IN (who then shared with me) that the issues are remediated. September 3, 2023: I confirm only 2/4 issues were remediated and the AWS keys were still present on the websites, and active. October 22, 2023: After no updates and finding the AWS issues still not remediated, I send over some more specific steps on what must be done. October 23, 2023: They confirm receipt and are working on taking action. After this date and up until January 2, 2024, there were various back and forth emails trying to get Tata Motors to revoke the AWS keys. I am not sure if something was lost in translation, but it took a lot of pestering and specific instructions to get it done. Stay classy TCS.
- paxys 11mo agoThis shouldn't be a surprise for anyone who has worked with TCS contractors in the past.
- yahoozoo 11mo agoSuperpower by 2027.
- debarshri 11mo agoThis is a pessimistic comment. I'm a cofounder of a data and identity security startup operating specifically in APAC. Data security in india a joke. I would argue even with DPDPA, RBI C-Site and cyber resilience framework from SEBI, it is just going to not happen here. The list PAN card the blog is taking about is probably already leaked by some other services. The recent flipkart cash on delivery scams [1] are example of how your personal information is just out there in wild in india, open for exploitation. There are lot of who do security in good faith (often driven by compliance) and lot of them are our customers too but I hope to see rest of indian tech ecosystem take security seriously. [1] https://www.reddit.com/r/FuckFlipkart/comments/1hhrw9w/what_is_this_new_scam_from_flipkart/ https://www.reddit.com/r/FuckFlipkart/comments/1hhrw9w/what_...
- alephnerd 11mo agoI've dealt with Indian companies for security sales and I'd say the newer generation of companies like Razorpay (YC W15) are decent at SecOps, but the older and more established companies suck at it and will continue to suck at it until there is a tangible regulatory incentive to enhance security postures. It also appears to be a side effect of compensation - why would mid-career security professional want to earn ₹15 LPA TC working for a legacy corporation if they have the skills to land at a security MNC that can afford to pay ₹35-50 LPA in TC. Ofc, it's us foreign investors who are able to afford those higher TCs ;) - especially if we can convert someone who was mid-career in the US but had to return to India due to family or visa issues. It reminds me of how the Israeli security scene was 10-15 years ago, with similar problems around compensation and brain drain to MNC offices.
- connectsnk 11mo agoAre there any open source tools that scans the code and detects such gaffes
- UltraMagnus 11mo agoNot open source, but I have used this before, and they have a very generous free tier: https://www.gitguardian.com/monitor-internal-repositories-for-secrets https://www.gitguardian.com/monitor-internal-repositories-fo... You install their Github app and give them access to your Github repo (private repos are ok too) and they run a Github workflow when each PR is submitted scanning for secrets that should not be in the code. Really happy with how their product works.
- unsungNovelty 11mo agoIf you weren't aware of it... There is a world of static application security tools (SAST) which can help you. Add them to your text editor/ci/cd to use them. https://owasp.org/www-community/Source_Code_Analysis_Tools https://owasp.org/www-community/Source_Code_Analysis_Tools
- vivzkestrel 11mo agostupid question, can we not make a regex for searching API keys for particular APIs and do a brute force scan across the internet
- richbell 11mo agoThere are a number of products and open source tools that do this. Look up "secret scanning".
- EatonZ 11mo agoTruffleHog: https://trufflesecurity.com/trufflehog https://trufflesecurity.com/trufflehog I worked for them a little bit and their product is really impressive and works great.
- heretoread9000 11mo agotrufflehog is a good starting point, then bake in your own simple regex into your github actions or equivalent and make it part of your test suite
- driverdan 11mo agoI'm curious, why wait so long to publish this? The incident was in 2023.
- tuktoyaktuk 11mo ago[dead]
- ilegitmadethisw 11mo ago[dead]
- coldfoundry 11mo agoThis might be the first time I felt disappointed and sad reading an article like this. The commented username and password felt like something from an early 2000s tv show with the tech guy doing “hacking”. Wonder how many others stumbled upon this prior, and makes me also wonder how many other sites have things like this hidden in plain sight. Insane.
- alephnerd 11mo agoThis may look "boring" or "uninspired" but this is what real cybersecurity and "hacking" looks like. In most cases, security and QA are essentially two sides of the same coin - and this is why I get pissed when devs treat testing and QA as bulls**t, becuase even a relatively simple XSS attack or cred misconfig can have a massive impact.
- hvb2 11mo agoThis has nothing to do with testing. This is a lack of training. I would say they need to 'think like an attacker' at least some of the time. But this is still too high of a bar. I think this is really a problem of rewarding people when they finish things. One way or the other. It works, so on to the next project...
- sumedh 11mo ago> This has nothing to do with testing. A good QA can catch/test such security issues although most of such work is given to a dedicated pen tester to find weakness in the platform.
- alephnerd 11mo agoAs someone who has been a SWE, PM, and VC in the cybersecurity space and constantly meets with CISOs as well as has formerly been a security practitioner (I should get back to using HackerOne again for fun), I can safely say that the overwhelming majority of security incidents are due to some form of misconfig because development and code review are orthogonal to proactive security checks. Shift-left was supposed to fix that but it failed because the primary persona to sell ended up becoming the CISO again, and not trying to find a way to make security ownership a Dev and QA responsibility as well (this is largely organizational).
- hannofcart 11mo ago> As recently seen with Intel, there seems to be a trend where developers will do this pointless client-side decryption. When the client has the key, it’s strange that anyone would think that would be secure. I stay and work in India. Yesterday, as part of a VAPT audit by a third party auditor, the auditors "recommended" that we do exactly this. I wonder if this directive comes as part of some outdated cyber security guidelines that are passed around here? Not entirely sure. When I asked them about how I'd pass the secret to the client to do the client side encryption/decryption without that key being accessible to someone who is able to MITM intercept our HTTPS only API calls anyway, the guy basically couldn't understand my question and fumbled around in his 'Burp' suite pointing exasperatedly to how he is able to see the JSON body in POST requests. Most of the security people we've met here, from what I can tell are really clueless. Internally, we call these guys "burp babies" (worse than "script kiddies") who just seem to know how to follow some cookie cutter instructions on using the Burp suite.
- sayamqazi 11mo agoI am a pretty cookie cutter developer. We just make glorified CRUDs and I have tried to convince the engineering director hundreds of times that "There is no use of encrypting and decrypting localstorage with a key thats sitting right inside the client code." Yet they keep insisting on it in the code-quality checklist.
- overtomanu 11mo agoI guess they think it results in some kind of security by obscurity... Maybe ward off lazy beginner hackers..
- deleted 11mo ago[deleted]
- Royce-CMR 11mo agoMy guess - he’s avoiding political risk. If something goes bad, it’s better to say “it was encrypted but they got the keys” than to defend data wasn’t encrypted. It’s semantics in terms of actual difference to an attacker, but it’s a world of difference when explaining to executives.
- qwertytyyuu 11mo agoWoah Tata is everywhere, weren't they also the biggest youtube channel?
- sreetamdas 11mo agoI believe you're talking about T-Series? pretty sure they are not related
- defraudbah 11mo agogive this Uri Said by Deepak Gupta
- pkphilip 11mo agoIf there any any TCS employees on Hackernews, please show this post to your management. This is beyond embarrassing on so many levels.
- zkmon 11mo agoUsers in India wouldn't care that much about privacy of their data as much as the Western folks do. This reduces the importance of this whole episode and I don't think this news flashed across TV screens or caused a debate anywhere. India is a karma society. Karma doesn't mean upvotes. It means, you get what you destined for, or what you deserve. People take things in their stride and keep moving, while keeping their eyes wide open. When you are moving through a jungle, there is no point in blaming thorns or getting angry on wild animals.
- inavida 11mo agoSo basically you are saying that India is a society that is still soaked in an ideology that justifies the special privileges of temple staff and tells peasants that being a sharecropper in a rent for protection racket is their own fault, so hand it over, and moreso that you approve. You sound like every temple staff worker ever. Grow up.
- zkmon 11mo agoGo out into rural India and ask someone if they care about someone knowing their contact details. Same with 90% of city folks. By the way, growing up may not be so cool. For you.
- _yy01 11mo agoYou foreigners read first few paragraphs of wikipedia article about caste and never stopped talking about it. In practice most of Brahmins have been peasant agriculturists, teachers and clerics for centuries, and temple priests have been deservedly pretty poor unless they also had inherited land. The current PM of India is from what is considered as "other backward caste". Just noting it, so that your overly reductive american journalism won't convince you that India is a feudalist society where 5% "temple staff" rule over the 95% peasants or whatever. The caste system is mostly limited to ritual avtism and some nepotism (which happens among boomers across all castes but younger ones don't care).
- _yy01 11mo agoThe kind of cope certain people come up with to justify the faults (and lack of basic living standards) of a civilization are insane. India is not a "karma" society, India is a 'jugaad' society where everyone does just enough to get by. The lack of civilizational will power to fix things which slightly harm the entrenched elite is very well known. (case in point - the recent stray dogs issue where the life of common man was put in danger because some rich animal welfare aunties protested against it). Thankfully Indian gen Z at least accepts these problems. Look at the memes on the gen Z spaces. Internet has let them know that living standards can be much better and other countries have risen from similar poverty levels. So there's some hope. You can't keep doing this 'india is not for beginners' forever.
- babra1 11mo ago[flagged]
- chisleu 11mo agoTotal tangent, but I got to ride in some of these on a recent trip to India and I was really impressed with the build quality and utilitarian usefulness of the design.
- fred_is_fred 11mo agoHe would have had better results if he said "do the needful" in his first email to them.
- guluarte 11mo agobtw... some urls in this image contains js with vulnerabilities https://eaton-works.com/cdn-cgi/imagedelivery/VwwCqBIYNXeyNQwEQ8uyVQ/f7bd5304-12dc-4843-f776-346502798200/full https://eaton-works.com/cdn-cgi/imagedelivery/VwwCqBIYNXeyNQ... https://imgur.com/a/ybFcY5Y https://imgur.com/a/ybFcY5Y https://imgur.com/Pf7ywbK https://imgur.com/Pf7ywbK
- prettywoman 11mo ago[dead]
- prettywoman 11mo ago[dead]
- faridv 10mo agoI'm just trying to understand, how is finding keys in plain sight termed as hacking?