Earlier quoted context omitted.
I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.
Enjoy https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a
Framework discloses data breach via Metabase 0-day
41–50 of 57 posts
Re: Framework discloses data breach via Metabase 0-day
#42While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…
I'm not. I'd like to see some sort of tangible compensation from them, not just a "we're sorry". Maybe a discount code or a freebie, or actual hard cash. I'd also like to see them pursue legal action against Metabase. And finally, I'd like them to be upfront with how they store and use PII. Had I known that they were going go store it with a third-party - and that too, unsalted and unencrypted - I would've never even signed up.
Re: Framework discloses data breach via Metabase 0-day
#43While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…
The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
Re: Framework discloses data breach via Metabase 0-day
#44Earlier quoted context omitted.
I agree that sponsoring DHH was a mistake. But I don't see how Framework could have used more money on security to prevent a zeroday in a third party product.
They could have sponsored the political activists driving NixOS instead.
Re: Framework discloses data breach via Metabase 0-day
#45Earlier quoted context omitted.
The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
If framework did as you suggest, they would have no way to validate warranty status and recalls. Motherboard died after 3 months? Tough luck, they have no record of you being a customer. Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow.
Warranty status is tied to hardware* serials. It's not like there are third-party Framework sellers.
Sending a recall notice via email doesn't require name, address, dob, etc.
Companies are in a bad habit of not actually clearing customer data they don't need.
Re: Framework discloses data breach via Metabase 0-day
#46Metabase again?? Last 0day was catastrophic. My previous employer moved all that infrastructure back to on-prem, I guess he must be laughing now.
Even if its on the cloud, should be locked behind your VPN
Re: Framework discloses data breach via Metabase 0-day
#47While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every cust…
The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
Re: Framework discloses data breach via Metabase 0-day
#48Earlier quoted context omitted.
The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
There are people that pre-ordered their latest PC that are currently waiting for the remaining batches to become available, finish paying the PC price in full, and have it shipped to them. So this information does fullfill a direct customer need.
Re: Framework discloses data breach via Metabase 0-day
#49A bit ironic that I found out about this through this website first despite also having received a mail from Framework about the issue. Still not sure what to do with this information. It's not like I can change any of the compromised information.
Re: Framework discloses data breach via Metabase 0-day
#50This forum poster would be… shocked to see how many SaaS companies are critical dependencies at most tech companies.
Imo, we need to get better at self hosting these kinds of tools. When I did a brief stint in BI tooling, we were basically using local tools with data exported from (gasp) SAP, and there was a dinky windows server behind someone’s desk where it’d run automated reports based on what we’d build and send out emails.
Certainly orders of magnitude cheaper. Maybe there was occasional downtime, but it didn’t really matter. You could always get the Oncall to generate the report you needed anyways