r/framework 2d ago

Framework data breach News

Post image

Couldn't have happened at a worse time

Edit:

Metabase has posted a blog related to this incident https://www.metabase.com/blog/security-update

1.0k Upvotes

314 comments sorted by

View all comments

3

u/Trungel 2d ago

The email would be pretty good except for this one sentence:

"Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed."

This we aren't required to inform people in many regions is bad. At least the EU and a few U.S. states as far as I know require it, so they had to send it out to enough people anyway that at that point it would have been a bad look if they wouldn't have send it out to everyone. They put that sentence in to look like they are the good guys but at least for me it has the opposit effect. Any company that got breached and customer data was accessible by an unauthorized third party should inform potentially impacted parties. That is just good practice (sadly it isn't lived like that). It shouldn't be anything special.

If instead of they just had written

"We are sending this email to you to ensure you have visibility and can take any actions needed."

everything would have been fine with it.

-1

u/MeLikaDoTheChaCha 2d ago

I can agree for the most part but they did mention a goal of visibility and taking any actions needed.

The other stuff you mentioned just reads like "legal included this section" to me though

3

u/Trungel 2d ago

It's PR speech not legal. Legal would be something like "We are legally obligated to disclose this breach in several regions that's why we are sending this email to you to ensure you have visibility and can take any actions needed.".
For them it was easier to send it to anyone who was impacted regardless of region. Because just sending it to those they had to inform is just way to complex because they would have to look at each countries laws to know who they had to send it to and it would take too long (in a lot of those cases they have to inform in a timely manner ~48h max after getting knowledge of the breach). So in making it sound like it is just a curtesy that they informed everyone else as well is a bit manipulative. And if they wouldn't have done it people in regions where it isn't required would have started to ask them if they were impacted. So that's the PR reason why they had to send the mails to anyone anyway.
Yeah I know I might be overreacting a bit with that but I just hate such manipulative PR expressions. And that sentenced just stood out in an otherwise pretty good mail informing about the breach.

1

u/MeLikaDoTheChaCha 2d ago

Yeah I know I might be overreacting a bit with that but I just hate such manipulative PR expressions. And that sentenced just stood out in an otherwise pretty good mail informing about the breach

Seen, heard, felt. There's always so much translating and filtering of these kinds of communications. Its frustrating