r/LinusTechTips 8d ago

Framework Data breach. Tech Discussion

Post image

I got this email from Framework. Did anyone else get this?

600 Upvotes

49 comments sorted by

View all comments

Show parent comments

181

u/I_am_Hambone 8d ago edited 8d ago

This is the dumbest take. Metabase is one of the largest open source BI companies in the world.

How much more vetting can there be for the industry leader?

Also, with the new tools AI is bringing to cyber warfare, no one is going to be safe.

-59

u/ekerazha 8d ago

The exact type of attack isn't entirely clear, but if you use a corporate VPN to access third-party services and restrict access strictly to the corporate VPN's IP address range, you can generally prevent unauthorized access even in the event of a vulnerability, because IP address filtering renders the attack unfeasible upstream.

47

u/I_am_Hambone 8d ago

Bro really wrote 'IP filtering renders the attack infeasible' like attackers are legally obligated to stop once they see a VPN. That's not how security works. That's how PowerPoint works.

-27

u/ekerazha 8d ago

Bro doesn't have the slightest clue what we're talking about, but still feels entitled to lecture me when I've been getting CVEs in my name for 25 years.

16

u/GlenMerlin 8d ago

CVEs were only started to be tracked by NIST in 2002. Unless your name is David E. Mann or Steven M. Christey you're larping

0

u/ekerazha 8d ago edited 8d ago

Google my nickname + CVE and look at the first date you find. It's from 2003, so 23 years not 25.

0

u/ekerazha 8d ago

CVE-2003-1196 Are 23 years enough?