Live data from Hacker News

Framework discloses data breach via Metabase 0-day

community.frame.work

41–50 of 57 posts

Re: Framework discloses data breach via Metabase 0-day

#41

Earlier quoted context omitted.

I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.

Enjoy https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a

"point and sputter" is not an argument

Re: Framework discloses data breach via Metabase 0-day

#42
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

> I'm impressed with Framework's handling of this issue

I'm not. I'd like to see some sort of tangible compensation from them, not just a "we're sorry". Maybe a discount code or a freebie, or actual hard cash. I'd also like to see them pursue legal action against Metabase. And finally, I'd like them to be upfront with how they store and use PII. Had I known that they were going go store it with a third-party - and that too, unsalted and unencrypted - I would've never even signed up.

Re: Framework discloses data breach via Metabase 0-day

#43
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

There are people that pre-ordered their latest PC that are currently waiting for the remaining batches to become available, finish paying the PC price in full, and have it shipped to them. So this information does fullfill a direct customer need.

Re: Framework discloses data breach via Metabase 0-day

#44
post #23
post #18

Earlier quoted context omitted.

I agree that sponsoring DHH was a mistake. But I don't see how Framework could have used more money on security to prevent a zeroday in a third party product.

They could have sponsored the political activists driving NixOS instead.

Those Microsoft pawns ?

Re: Framework discloses data breach via Metabase 0-day

#45
post #35

Earlier quoted context omitted.

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

If framework did as you suggest, they would have no way to validate warranty status and recalls. Motherboard died after 3 months? Tough luck, they have no record of you being a customer. Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow.

These are bad examples.

Warranty status is tied to hardware* serials. It's not like there are third-party Framework sellers.

Sending a recall notice via email doesn't require name, address, dob, etc.

Companies are in a bad habit of not actually clearing customer data they don't need.

Re: Framework discloses data breach via Metabase 0-day

#46
post #14

Metabase again?? Last 0day was catastrophic. My previous employer moved all that infrastructure back to on-prem, I guess he must be laughing now.

Even if its on the cloud, should be locked behind your VPN

That's certainly one way of thinking. But it's not the only one. It's not even the only secure one

Re: Framework discloses data breach via Metabase 0-day

#47
post #2

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

Sounds like GDPR?

Re: Framework discloses data breach via Metabase 0-day

#48

Earlier quoted context omitted.

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

There are people that pre-ordered their latest PC that are currently waiting for the remaining batches to become available, finish paying the PC price in full, and have it shipped to them. So this information does fullfill a direct customer need.

I have never made a purchase via Framework and still got the email from them. Probably because I once put in my data to see final shipping and import costs.

Re: Framework discloses data breach via Metabase 0-day

#49
post #22

A bit ironic that I found out about this through this website first despite also having received a mail from Framework about the issue. Still not sure what to do with this information. It's not like I can change any of the compromised information.

I share a similar feeling. I don't have a Framework but I do self-host Metabase. Reading this headline is how I learned of the 0-day and updated my pod.

Re: Framework discloses data breach via Metabase 0-day

#50
> Its disappointing another company has chosen to share our personal information with another third party

This forum poster would be… shocked to see how many SaaS companies are critical dependencies at most tech companies.

Imo, we need to get better at self hosting these kinds of tools. When I did a brief stint in BI tooling, we were basically using local tools with data exported from (gasp) SAP, and there was a dinky windows server behind someone’s desk where it’d run automated reports based on what we’d build and send out emails.

Certainly orders of magnitude cheaper. Maybe there was occasional downtime, but it didn’t really matter. You could always get the Oncall to generate the report you needed anyways

Post reply on HN