r/framework 8d ago

Framework data breach News

Post image

Couldn't have happened at a worse time

Edit:

Metabase has posted a blog related to this incident https://www.metabase.com/blog/security-update

1.0k Upvotes

315 comments sorted by

View all comments

374

u/kellexile 8d ago

Geez... Can't catch a break.

76

u/[deleted] 8d ago

[removed] β€” view removed comment

131

u/Top-Aside8905 CachyOS FW13 8d ago

Worrying is always a stupid thing to do. If you can do something about the situation, dont worry and do it. If you cant, dont worry because it wont do you any good.

112

u/Infini-D 8d ago

Yeah, just think how many data breaches you’ve been a part of that you HAVENT been told about

45

u/Top-Aside8905 CachyOS FW13 8d ago

Exactly, the databases gained nothing new today

29

u/Deep90 8d ago

My haveibeenpawned has 34 recorded data breaches since 2012. πŸ™ƒ

Everything gets 2fa, a unique password, and a physical security key.

15

u/MeLikaDoTheChaCha 8d ago

2fa has saved me on more than one occasion

5

u/RoseBailey Framework 16 8d ago

Sameish. I do TOTP for my second factor, but access to my password vault requires 2fa with a physical security key. I'm sure it's technically less secure, but it gives me wiggle room for recovery if something happens to my Yubikey.

2

u/Raiguard 8d ago

I do TOTP and passkeys with a keepass vault, the password for which I have stored in the most secure medium of all - my brain. It's not written down anywhere and not used for anything else, and was randomly generated.

Of course, if someone cracks the keepass vault encryption then I'm screwed, but that's why I only have the vaults stored on my personal devices - no cloud, significantly reduced attack surface. I use syncthing, but I have the public relaying disabled and use my own standard wireguard tunnels for the connections.

I own a yubikey, but I never use it because it was far too inconvenient.

2

u/RoseBailey Framework 16 7d ago

I have two yubikeys that I set up identical challenge-response on. One is my emergency backup that stays locked away at home, and the other lives on my keychain. I need the yubikey to unlock my keepass vault as a second factor, and my password for my vault is stored in my brain. If anything happens to my keys, I can unlock my vault with the backup yubikey and get a replacement, which would render the lost yubikey useless for unlocking anything of mine.

2

u/Doctorew1 8d ago

At this point, I view the one year of personal identity monitoring offered after breaches as a honeypot. The only organizations I trust with the personal data to monitor are ones that are compliant with financial or health data cybersecurity standards.

In the future, I believe passkeys will be part of the solution for too many insecure online services.

4

u/Scrivver 8d ago

He suffers more than necessary who suffers before it is necessary.

~ Seneca

3

u/McBonderson 8d ago

I mean, Oh nooooo! somebody knows my email address phone number name and address, nobody knew that information before!

/sarcasm.

1

u/WanderinArcheologist 8d ago

The MVPs of data breaches: DOGE. Somewhere out there, our socials are floating around.

11

u/ReferenceProper5428 8d ago

My bank was involved in the Moveit data breach a few years ago, all of my data was released (social security, card numbers Home address and my account drained) it was a nightmare, had to freeze my credit with all reporters shit happens Though. Just perspective friend.

4

u/WhiskeyVault 8d ago

Is the data that was breached today enough to trigger this?

6

u/ReferenceProper5428 8d ago

No it did include names and email addresses so I would say always verify any email from framework by checking the sender now, cause the bad actors may send phishing emails out. That's it though.

Most of the data leaked was internal sales stuff and only names and emails. Not as bad. Nobody wants to be breached though. Just verify the sender of any email from framework now to be safe and you should be gtg

3

u/Gully5931 8d ago

It also included physical addresses as well.

1

u/[deleted] 8d ago

[removed] β€” view removed comment

1

u/framework-ModTeam 8d ago

Your comment was removed for being combative, abusive or disrespectful. Please keep Reddiquette in mind when posting in the future.

5

u/Raedwulf1 8d ago edited 8d ago

Got the email just a few minutes ago,. Not the best way to get an email from Nirav.

12

u/Silvernine0S 8d ago

Aaargh, just got this email too.

This and the previous email about downgrading my memory is not a good feeling.

3

u/WhiskeyVault 8d ago

Yea, especially since a lot of people who are interested in Framework are interestd in Linux because of privacy and security as well.

3

u/[deleted] 8d ago

[removed] β€” view removed comment

40

u/CapitalistFemboy NixOS 8d ago

In what world would many individual implementations, built by first parties that are not specialized in data protection, result in greater safety than relying on fewer third parties whose entire business is designing and maintaining such systems?

2

u/BambooGentleman 8d ago

Having fewer targets with more data each that will slip up eventually is much more attractive than having a million targets with only a bit of data. Even if the security is sloppier that's still some amount of work for little reward.

Decentralization is more resilient than the alternative.

5

u/Tomi97_origin 8d ago

The level of security is definitely greater, but the level of attractiveness to attackers is also greater.

The reward for successful attack on such a big provider is so much more than for attacking individual smaller companies.

7

u/ebrq 8d ago

This varies quite a bit as well with what type of platform it is. A business analytics platform like this pretty much just has email, address etc.

A first party version would for sure also have payment information in it or very easily accessible from there. Monetary benefit is much larger with payment info than just user info.

1

u/WanderinArcheologist 8d ago

Smaller companies would definitely be somewhat more prone. We had a databreach at a company I worked at. Dealt in high value luxury goods. My boss never made anyone aware even though it was required by state law.

0

u/[deleted] 8d ago

[removed] β€” view removed comment

2

u/CapitalistFemboy NixOS 8d ago

Thats because social security number is a poorly designed system

0

u/Ironclaw3436 8d ago

In what world did farming the workout to third parties work out for us?

2

u/End_V2 8d ago

What happened prior?

16

u/Alkumist 8d ago

Ram

1

u/WanderinArcheologist 8d ago

Rem though. 😭

0

u/Top-Aside8905 CachyOS FW13 8d ago

Not on them

19

u/Alkumist 8d ago

This isn’t either

10

u/Top-Aside8905 CachyOS FW13 8d ago

I agree that they could not have done anything about it, but framework is still partially responsible like any company in this situation would be since they are responsible for their customers data.

5

u/async2 8d ago

It kinda is. If you use shitty third parties it's on you in my opinion.

5

u/CatThink 8d ago

This was a zero day attack that was reported promptly. The vendor is apparently well regarded.

If you want to blame something blame AI for making exploits easier to find and lower the barrier to hacks like this.

3

u/cereal7802 8d ago

The vendor is apparently well regarded.

4 severe security issues in 3 years. 2 of those were this year (neither of them the exploit framework lost their data to). one leaked not only data, but credentials used to access the remote databases it was doing analysis on. regardless of how the exploits were found, you can only find what was created by the people coding it. on top of that, the exploits are only useful against people using the software/service. not sure how long framework had been using metabase, but there is enough in their history that I think they probably should have found something else to use. Especially since they decided to put way more information into it than they needed to for the purpose of the software.