Skip to content

Comment on Framework discloses data breach via Metabase 0-day

Comments

While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days.

I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use that where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house.

As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily.

Just don't use the cloud version of Metabase. You can self host it and not allow accessing it over the internet.

Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ultimately forces them to be solely responsible for their customers' data. Using the cloud versions of these products shifts the blame from the company itself to the vendor when things go sideways, so it makes more sense for them to do this instead of taking responsibility.

Salesforce hasn't ever been hacked to the best of my knowledge.

"Yes, Salesforce has experienced multiple hacking incidents, particularly involving social engineering attacks that targeted its customers, leading to significant data breaches. Notably, the hacking group ShinyHunters has claimed responsibility for exploiting vulnerabilities in Salesforce's systems, affecting numerous high-profile companies." Source: https://duckduckgo.com/?q=has+salesforce+ever+been+hacked%3F... Yes, *Salesforce has experienced multiple hacking incidents*, particularly involving social engineering attacks that targeted its customers, leading to significant data breaches. Notably, the hacking group ShinyHunters has claimed responsibility for exploiting vulnerabilities in Salesforce's systems, affecting numerous high-profile companies.

Cloudflare also reported one as recent as 4 days ago, impacting over 700 companies. Source: https://dailysecurityreview.com/cyber-security/cloudflare-co...

"Social engineering attacks that targeted its customers" is not being hacked.

The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.

That is already the case for where I live, and yet I am on that breach, with names, addresses, etc. all leaked. Unfortunately it's not enough to collect "only necessary" if what's necessary is too much in the hands of the attacker.

There are people that pre-ordered their latest PC that are currently waiting for the remaining batches to become available, finish paying the PC price in full, and have it shipped to them. So this information does fullfill a direct customer need.

I have never made a purchase via Framework and still got the email from them. Probably because I once put in my data to see final shipping and import costs.

This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place.

Can't they store that information encrypted? What analytics can be extracted from phone numbers? It's only good to sell on black market.

I'm waiting for this for 7 years already: I'm too lazy to setup proper analytics with 800 "legitimate partners" on my website

If framework did as you suggest, they would have no way to validate warranty status and recalls.

Motherboard died after 3 months? Tough luck, they have no record of you being a customer.

Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow.

These are bad examples.

Warranty status is tied to hardware* serials. It's not like there are third-party Framework sellers.

Sending a recall notice via email doesn't require name, address, dob, etc.

Companies are in a bad habit of not actually clearing customer data they don't need.

Of course they do. How do you think warranty works for in-person cash purchases?

Put a sticker with a unique ID on parts.

Sounds like GDPR?

I'm impressed with Framework's handling of this issue

I'm not. I'd like to see some sort of tangible compensation from them, not just a "we're sorry". Maybe a discount code or a freebie, or actual hard cash. I'd also like to see them pursue legal action against Metabase. And finally, I'd like them to be upfront with how they store and use PII. Had I known that they were going go store it with a third-party - and that too, unsalted and unencrypted - I would've never even signed up.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.