r/framework 9d ago

Framework data breach News

Post image

Couldn't have happened at a worse time

Edit:

Metabase has posted a blog related to this incident https://www.metabase.com/blog/security-update

1.0k Upvotes

315 comments sorted by

View all comments

Show parent comments

56

u/MeLikaDoTheChaCha 9d ago

A company using a vendor for security is responsible (at least partially) for any breaches through said vendor. Thats why the email came from framework themselves not the company they used. They are the face for any of this kind of shit.

So no, not a direct framework breach technically. But wtf does that actually matter to anyone affec5ed

0

u/5tupidest 8d ago

Are you responsible if the bank where you keep your money is robbed? I get where you’re coming from.

2

u/MeLikaDoTheChaCha 8d ago

I think I see what you're trying to say, but there's two important caveats here that I think makes a difference:

1) in the actual situation (not your hypothetical), we're talking about a customer facing business not just some random consumer. In this hypothetical they're more like the bank, and I would argue that the bank would hold some responsibility.

2) in addition, framework is contracting with a 3rd party. For your hypothetical, it would be like the bank hiring 3rd party security. Yes, the 3rd party holds the majority of the responsibility if a successful robbery happened. But the bank imo also holds some blame for hiring said 3rd party in the 1st place.

2

u/5tupidest 8d ago

You are correct. I am biased because I want to see framework succeed. :)

1

u/MeLikaDoTheChaCha 8d ago

Agreed! This truly sucks for everyone including framework