Live data from Hacker News

Framework discloses data breach via Metabase 0-day

community.frame.work

21–30 of 57 posts

Re: Framework discloses data breach via Metabase 0-day

#21
post #7

I say this as a fan of a lot of what Framework is doing. Lets not pretend we do not all -know- virtually every SaaS sucks ass at security because it slows down sales. Companies that use these easy button services anyway are knowingly putting PII at risk and any liability should fall on those decision makers. If you do not have the security and infra staff to take user data in house securely, in highly auditable secur…

I created an account more than two years ago, and never connected to it since. EU rgpd is very clear about data retention delays. I won't report it, but to be clear I am very cross with Framework, when even Chinese companies respect my privacy more.

Re: Framework discloses data breach via Metabase 0-day

#23
post #18
post #8

[flagged]

I agree that sponsoring DHH was a mistake. But I don't see how Framework could have used more money on security to prevent a zeroday in a third party product.

They could have sponsored the political activists driving NixOS instead.

Re: Framework discloses data breach via Metabase 0-day

#24
post #13
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

Just don't use the cloud version of Metabase. You can self host it and not allow accessing it over the internet.

Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ultimately forces them to be solely responsible for their customers' data. Using the cloud versions of these products shifts the blame from the company itself to the vendor when things go sideways, so it makes more sense for them to do this instead of taking responsibility.

Re: Framework discloses data breach via Metabase 0-day

#25
> Maybe Framework is handling things well, but now with their addresses out everyone who talked publicly about their recent orders should be considered at risk of targeted physical theft due to the current prices.

Am I missing something or is this user out of his mind ? This ain't Bitcoin, it's just a damn laptop.

Re: Framework discloses data breach via Metabase 0-day

#27
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place.

Re: Framework discloses data breach via Metabase 0-day

#29
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

That is already the case for where I live, and yet I am on that breach, with names, addresses, etc. all leaked. Unfortunately it's not enough to collect "only necessary" if what's necessary is too much in the hands of the attacker.
Post reply on HN