3 ms·
Let's not oversell the fact that Amdocs' official HQ is in the US: It's an Israeli company through and through. It did more development in the US back in 2001 t
by Thr0wawayDocs 5y ago
Let's not oversell the fact that Amdocs' official HQ is in the US: It's an Israeli company through and through. It did more development in the US back in 2001 than it does now: Today, their US footprint is mostly customer sites. And you will find people brought in from Israel everywhere. It's always been bad enough that managers that don't speak Hebrew knew they were always at a disadvantage. Your best bet for saying it's not an Israeli company is to say that a whole lot of R&D is being done in other countries with cheaper labor.
While it's true that the installations are on-prem (having been to quite a few of those), Amdocs business model isn't about dropping code and going away: They are so embedded with your typical deployment that there's plenty of opportunity to exfiltrate data. Sending every CDR to Haifa? Probably not: The Sysadmins on your typical large telco are iffy, but not that iffy.
And carefully firewalled? The talent was never great, and the security practices were never all that serious: I've been handed production shells that I had no business having, because it was convenient at the time. Once again, I'd say that the best argument to claim that there's no data exfiltration is that the people writing the code aren't good enough to do this under the customer's nose.
- tguvot 5y agoI was involved in some RF*s on Amdocs side for a bunch of telecoms in USA, Europe and Asia a few years ago. Security requirements were very long and rather reasonable, to a point that it was pain in the ass to follow all of it. Part of what we had to submit was deployment architecture that included security architecture that was reviewed by security teams. We also had some meetings with security teams which were more like serious interrogations (they just could go with waterboarding to speed up things). We even had as result of those discussion to alter somewhat product architecture (not "lets stick in tls". actual changes in how system works and interacts) in order to enable more secure deployment and operations. But those were Tier 1 telecoms. Smaller one probably less strict but I don't know as I didn't deal with them