Live data from Hacker News

Framework discloses data breach via Metabase 0-day

community.frame.work

11–20 of 57 posts

Re: Framework discloses data breach via Metabase 0-day

#11
Here's what an email from metabase looks like for those affected:

  On Monday, August 3, we discovered  that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.

  Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:

  Rotate the credentials for every database connected to your instance; and
   Review the admin accounts on your instance and remove anything you don't recognize.
   We also discovered that the attacker was able to gain access to your instance.  We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at https://store.metabase.com.

  (If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)

  This report is based on our own application logs. We did not query or read the data in your connected databases.

  Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.

  We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at eventresponse@metabase.com, and we'll get back to you as quickly as we can.

  Sameer Al-Sakran
  Founder and CEO
  Metabase

Based on what they shared in terms of logs and summary, the attacker was scanning tables for valuable data. They took the first N rows from various tables in connected DBs, kind of at random it seems. Possibly some kind of regexing. Here's an example timeline:

  | Time | Event |
  | --- | --- |
  | 13:00 | Access gained and authenticated as the administrator account |
  | 13:01 – 13:12 | 54 queries were run through that session |
  | 13:14 | API key was created (key ID `1`) tied to a service account |
  | 13:14 – 13:17 | 19 further queries were run through the API key |
  | 13:17 | API key was deleted |

Re: Framework discloses data breach via Metabase 0-day

#13
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

Just don't use the cloud version of Metabase. You can self host it and not allow accessing it over the internet.

Re: Framework discloses data breach via Metabase 0-day

#15
post #8

[flagged]

I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.

This is a pretty decent run down (and DHH has taken it much further since this post was published): https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thoug...

Re: Framework discloses data breach via Metabase 0-day

#16
post #8

[flagged]

I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.

Enjoy https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a

Re: Framework discloses data breach via Metabase 0-day

#17
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

Re: Framework discloses data breach via Metabase 0-day

#19
post #7

I say this as a fan of a lot of what Framework is doing. Lets not pretend we do not all -know- virtually every SaaS sucks ass at security because it slows down sales. Companies that use these easy button services anyway are knowingly putting PII at risk and any liability should fall on those decision makers. If you do not have the security and infra staff to take user data in house securely, in highly auditable secur…

Let's not pretend we do not all -know- virtually every company looks at security as a cover your ass exercise. The SaaS is able to provide some fort of "certification", so companies are happy to move responsibility to them. They don't actually care about protecting PII or anything.

The problem is that all responsibility being moved is who gets to shrug. There need to be nontrivial per customer damages paid for each such incident.

Re: Framework discloses data breach via Metabase 0-day

#20
post #8

[flagged]

I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.

Stop being reasonable we are all gathered here to burn the witch.
Post reply on HN