I say this as a fan of a lot of what Framework is doing. Lets not pretend we do not all -know- virtually every SaaS sucks ass at security because it slows down sales. Companies that use these easy button services anyway are knowingly putting PII at risk and any liability should fall on those decision makers. If you do not have the security and infra staff to take user data in house securely, in highly auditable secur…
Framework discloses data breach via Metabase 0-day
21–30 of 57 posts
Re: Framework discloses data breach via Metabase 0-day
#22Still not sure what to do with this information. It's not like I can change any of the compromised information.
Re: Framework discloses data breach via Metabase 0-day
#23Re: Framework discloses data breach via Metabase 0-day
#24While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…
Just don't use the cloud version of Metabase. You can self host it and not allow accessing it over the internet.
Re: Framework discloses data breach via Metabase 0-day
#25Am I missing something or is this user out of his mind ? This ain't Bitcoin, it's just a damn laptop.
Re: Framework discloses data breach via Metabase 0-day
#26Re: Framework discloses data breach via Metabase 0-day
#27While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…
The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
Re: Framework discloses data breach via Metabase 0-day
#28Re: Framework discloses data breach via Metabase 0-day
#29While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…
The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.