Live data from Hacker News

Framework discloses data breach via Metabase 0-day

community.frame.work

31–40 of 57 posts

Re: Framework discloses data breach via Metabase 0-day

#31
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

I'm waiting for this for 7 years already: I'm too lazy to setup proper analytics with 800 "legitimate partners" on my website

Re: Framework discloses data breach via Metabase 0-day

#32
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

Can't they store that information encrypted? What analytics can be extracted from phone numbers? It's only good to sell on black market.

Re: Framework discloses data breach via Metabase 0-day

#33
At some point I almost bought a Framework laptop, just didn't click the Order button. I had my address etc already filled in, so because of that I also got that email from Framework this morning. From a technical perspective I guess it makes sense that Metabase has my personal information, but it's still kind of crazy to think how much personal information you're sending "out there" just by, for example, checking a final price of a product including shipping.

Re: Framework discloses data breach via Metabase 0-day

#34
post #24
post #13

Earlier quoted context omitted.

Just don't use the cloud version of Metabase. You can self host it and not allow accessing it over the internet.

Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ultimately forces them to be solely responsible for their customers' data. Using the cloud versions of these products shifts the blame from the company itself to the vendor when things go s…

[dead]

Re: Framework discloses data breach via Metabase 0-day

#35
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

If framework did as you suggest, they would have no way to validate warranty status and recalls.

Motherboard died after 3 months? Tough luck, they have no record of you being a customer.

Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow.

Re: Framework discloses data breach via Metabase 0-day

#36
post #33

At some point I almost bought a Framework laptop, just didn't click the Order button. I had my address etc already filled in, so because of that I also got that email from Framework this morning. From a technical perspective I guess it makes sense that Metabase has my personal information, but it's still kind of crazy to think how much personal information you're sending "out there" just by, for example, checking a f…

I'm exactly in the same position, and it pisses me off.

All I can is to prepare for a upcoming wave of spam calls and phishing attempts.

At some point, these companies have to start paying for their irresponsibilities.

Re: Framework discloses data breach via Metabase 0-day

#37

Earlier quoted context omitted.

I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.

Enjoy https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a

If you think that's racist then you're the reason people like trump win elections and the opposition loses.

Re: Framework discloses data breach via Metabase 0-day

#38

Earlier quoted context omitted.

I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.

Enjoy https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a

I still don't see racism there. I agree people, foreign or domestic, shouldn't be camping in public spaces. If the law is only enforced against domestic transgressors (or they are just raised in a culture that doesn't require enforcement) then it's right to criticise policies that turn a blind eye to foreign transgressors.

Re: Framework discloses data breach via Metabase 0-day

#39
post #35

Earlier quoted context omitted.

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

If framework did as you suggest, they would have no way to validate warranty status and recalls. Motherboard died after 3 months? Tough luck, they have no record of you being a customer. Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow.

Put a sticker with a unique ID on parts.

Re: Framework discloses data breach via Metabase 0-day

#40
post #35

Earlier quoted context omitted.

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

If framework did as you suggest, they would have no way to validate warranty status and recalls. Motherboard died after 3 months? Tough luck, they have no record of you being a customer. Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow.

Of course they do. How do you think warranty works for in-person cash purchases?
Post reply on HN