Framawork Data Breach

13 days ago by Avid Amoeba to c/framework

Dear Valued Framework Customer,

We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.

Just arrived into my inbox.

robear 20 points 13 days ago

"Metabase - Open source AI analytics"

Yep, definitely something you really needed. Fuckin idiots.

path: 0 25170871, hotness: undefined, score: 20, children: 0
Breezy 13 points 12 days ago

I'm so sick and tired of companies keeping all of this extraneous data on us. I haven't logged into the site nor ordered anything for over a year and I also got this email. Like yes, it's technically not Framework's fault, but why are they even keeping information like IP logins or phone numbers? Why aren't they storing it in the same place they stored purchase information (which apparently has better security)?

There really is no need for these companies to even have a lot of this information. I wish there were actual punitive punishments for having data be stolen/leaked. Maybe then it'll make companies stop and truly think on "whether we really need this data in the first place." Make the fines more expensive than the profit of selling our data. I'm just super salty, because this is probably the 3rd notice I've received of my data being leaked this year alone...

path: 0 25179698, hotness: undefined, score: 13, children: 7
avidamoeba 9 points 12 days ago

There is a need though. I used to view companies as producing laptops or vehicles or whatever. From that frame of reference, there's no need to collect this kind of data. These days I look at them as profit-producing entities. That is their main product is profit. Laptops and vehicles are a temporary side effect. From this frame of reference, they need to store this data as it's another means to produce more profit. For example by more accurately targetting their prices to maximize profit, or selling the data in the future when they can't grow profits from their laptops. I'm convinced this is the correct frame to view the vast majority of for-profit companies because it predicts their actions much more accurately than the other one.

path: 0 25179698 25180160, hotness: undefined, score: 9, children: 4
Breezy 4 points 12 days ago

I get that that's just the way it is now, but it really shouldn't be.

I go to a store in person, buy a laptop with cash, no information required. Why does this have to be different for anything else? I purchased a laptop from Framework, because I wanted a repairable/upgradable laptop. Why should they be allowed to sell my data, why do they need a record of the IP addresses I've used to access their website, or keep my phone number on file, and so on?

At least here in the US there is no control of how our data is collected and sold against our will (barring some protection if you live in certain states), and then it inevitably leaks and now we have to deal with trying to not get our identity stolen and or inundated with spam and scams. It's incredibly frustrating. From the consumer's point of view there is no "need" for this.

path: 0 25179698 25180160 25180654, hotness: undefined, score: 4, children: 0
Senal 3 points 12 days ago

I agree with that as a model for prediction of behaviour, i don't agree that there is a need.

There is obviously a want , but unless there is an existential requirement for data collection like that, the need is speculative.

path: 0 25179698 25180160 25181907, hotness: undefined, score: 3, children: 2
avidamoeba 1 point 12 days ago

I think the want tends to become a need (not for every business in every market) because of a few pressures, among which is the competitive pressure for capital. If this business won't deliver growing profits, capital would move into another that would. Without capital, there's no money for procuring the means to do new product. I think that gives the basic pressure for profit maximization that we see around us. It's not universal - non-profits, private firms which don't take outside capital whose owners are opposed to profit maximization, and some others tend to not be subject to it. So for some types of businesses I think it qualifies as need, or else they risk their survival and therefore the usually high compensation of their exec layers. I'm not married to proving it need and not want, just thought you might not have looked at it from this angle.

path: 0 25179698 25180160 25181907 25182447, hotness: undefined, score: 1, children: 1
Senal 1 point 12 days ago

I have and do look at it from that angle, my point was that the need for data collection isn't a guaranteed thing.

Even if you narrow it down to just the subset of companies for which continuous "shareholder value" is a requirement.

If it was the only avenue to profit i'd agree the need was universal, but there are other ways, some mutually exclusive.

Though i will conceded that data collection is one of the common ones.

path: 0 25179698 25180160 25181907 25182447 25186312, hotness: undefined, score: 1, children: 0
chaospatterns 7 points 12 days ago

Like yes, it's technically not Framework's fault

I know it's a third party vendor that got hacked, but I really think the blame still falls on the company that contracted with the vendor.

Framework decided to hire this company and companies need to recognize the risk in hiring SaaS companies. I know at my previous job we had to go through security and privacy compliance reviews to decide it was even worth sharing data with a third party vendor.

Too many companies have a ton of SaaS providers and shovel customer data to each one.

path: 0 25179698 25181382, hotness: undefined, score: 7, children: 1
Breezy 4 points 12 days ago

Completely agreed. I just wished these companies actually faced punitive consequences instead of sending us another "oopsies, we lost your data again teehee; you're on your own!" type of responses.

path: 0 25179698 25181382 25182149, hotness: undefined, score: 4, children: 0
geneva_convenience 4 points 12 days ago

So we entered your personal information into an AI tool. But then the AI tool got hacked and now your personal information is leaked. Whoopsie!

path: 0 25180987, hotness: undefined, score: 4, children: 1
mikey 3 points 12 days ago

Metabase isn't AI, here Business Intelligence means BI tools, basically things that query a lot of data to get fancy charts, mostly for managers and bean counters.

Like sales over time, or support requests by country.

path: 0 25180987 25182779, hotness: undefined, score: 3, children: 0
AxisExperience9 4 points 13 days ago

I also got this email. Damn. Hate that.

path: 0 25172339, hotness: undefined, score: 4, children: 0
frki 3 points 13 days ago

I got the same mail. Information regarding orders doesn't seem to be included, so I hope that as long you have not saved your address information (or deleted it after ordering), the damage is minimized to just your name, IPs, and email addresses.

path: 0 25168643, hotness: undefined, score: 3, children: 2
chaospatterns 2 points 12 days ago

The email also mentions: Billing and shipping address information was leaked.

path: 0 25168643 25181401, hotness: undefined, score: 2, children: 1
superbetter 1 point 12 days ago

yep, (shipping and) billing address but not other billing info, at least according to their email.

path: 0 25168643 25181401 25182132, hotness: undefined, score: 1, children: 0
superbetter 2 points 12 days ago

I always delete my billing info so that wasn't there (they say it wasn't included this time, but it's a safety precaution I take regardless) but kicking myself that my address was there.

path: 0 25182094, hotness: undefined, score: 2, children: 0
framework
framework

@lemmy.ml

login for more options
3545
275
200

Related links:

Related communities:

go to feed...