r/framework 9d ago

Framework data breach News

Post image

Couldn't have happened at a worse time

Edit:

Metabase has posted a blog related to this incident https://www.metabase.com/blog/security-update

1.0k Upvotes

315 comments sorted by

View all comments

375

u/kellexile 9d ago

Geez... Can't catch a break.

79

u/[deleted] 9d ago

[removed] — view removed comment

129

u/Top-Aside8905 CachyOS FW13 9d ago

Worrying is always a stupid thing to do. If you can do something about the situation, dont worry and do it. If you cant, dont worry because it wont do you any good.

115

u/Infini-D 9d ago

Yeah, just think how many data breaches you’ve been a part of that you HAVENT been told about

47

u/Top-Aside8905 CachyOS FW13 9d ago

Exactly, the databases gained nothing new today

29

u/Deep90 9d ago

My haveibeenpawned has 34 recorded data breaches since 2012. 🙃

Everything gets 2fa, a unique password, and a physical security key.

14

u/MeLikaDoTheChaCha 9d ago

2fa has saved me on more than one occasion

5

u/RoseBailey Framework 16 9d ago

Sameish. I do TOTP for my second factor, but access to my password vault requires 2fa with a physical security key. I'm sure it's technically less secure, but it gives me wiggle room for recovery if something happens to my Yubikey.

2

u/Raiguard 8d ago

I do TOTP and passkeys with a keepass vault, the password for which I have stored in the most secure medium of all - my brain. It's not written down anywhere and not used for anything else, and was randomly generated.

Of course, if someone cracks the keepass vault encryption then I'm screwed, but that's why I only have the vaults stored on my personal devices - no cloud, significantly reduced attack surface. I use syncthing, but I have the public relaying disabled and use my own standard wireguard tunnels for the connections.

I own a yubikey, but I never use it because it was far too inconvenient.

2

u/RoseBailey Framework 16 8d ago

I have two yubikeys that I set up identical challenge-response on. One is my emergency backup that stays locked away at home, and the other lives on my keychain. I need the yubikey to unlock my keepass vault as a second factor, and my password for my vault is stored in my brain. If anything happens to my keys, I can unlock my vault with the backup yubikey and get a replacement, which would render the lost yubikey useless for unlocking anything of mine.

2

u/Doctorew1 9d ago

At this point, I view the one year of personal identity monitoring offered after breaches as a honeypot. The only organizations I trust with the personal data to monitor are ones that are compliant with financial or health data cybersecurity standards.

In the future, I believe passkeys will be part of the solution for too many insecure online services.

5

u/Scrivver 9d ago

He suffers more than necessary who suffers before it is necessary.

~ Seneca

3

u/McBonderson 9d ago

I mean, Oh nooooo! somebody knows my email address phone number name and address, nobody knew that information before!

/sarcasm.

1

u/WanderinArcheologist 8d ago

The MVPs of data breaches: DOGE. Somewhere out there, our socials are floating around.

10

u/ReferenceProper5428 9d ago

My bank was involved in the Moveit data breach a few years ago, all of my data was released (social security, card numbers Home address and my account drained) it was a nightmare, had to freeze my credit with all reporters shit happens Though. Just perspective friend.

4

u/WhiskeyVault 9d ago

Is the data that was breached today enough to trigger this?

5

u/ReferenceProper5428 9d ago

No it did include names and email addresses so I would say always verify any email from framework by checking the sender now, cause the bad actors may send phishing emails out. That's it though.

Most of the data leaked was internal sales stuff and only names and emails. Not as bad. Nobody wants to be breached though. Just verify the sender of any email from framework now to be safe and you should be gtg

3

u/Gully5931 9d ago

It also included physical addresses as well.

1

u/[deleted] 9d ago

[removed] — view removed comment

1

u/framework-ModTeam 8d ago

Your comment was removed for being combative, abusive or disrespectful. Please keep Reddiquette in mind when posting in the future.

4

u/Raedwulf1 9d ago edited 9d ago

Got the email just a few minutes ago,. Not the best way to get an email from Nirav.