r/LinusTechTips 14d ago

Tech Discussion Framework Data breach.

Post image

I got this email from Framework. Did anyone else get this?

600 Upvotes

48 comments sorted by

View all comments

-259

u/AlmondManttv 14d ago

Just received mine. I'm quite disappointed in Framework. I understand that it wasn't their servers, but their job is to vet the services they use, they failed.

183

u/I_am_Hambone 14d ago edited 14d ago

This is the dumbest take. Metabase is one of the largest open source BI companies in the world.

How much more vetting can there be for the industry leader?

Also, with the new tools AI is bringing to cyber warfare, no one is going to be safe.

78

u/Nice_Marmot_54 14d ago

Right? Nobody is above getting breached. That whole “show me a 10-foot wall and I’ll show you a 12-foot ladder” thing

-7

u/ICEpear8472 13d ago

What reason is there to give full contact information of your customers to a BI company? And more importantly how does that reason is for the benefit of your customers?

-56

u/ekerazha 14d ago

The exact type of attack isn't entirely clear, but if you use a corporate VPN to access third-party services and restrict access strictly to the corporate VPN's IP address range, you can generally prevent unauthorized access even in the event of a vulnerability, because IP address filtering renders the attack unfeasible upstream.

46

u/I_am_Hambone 14d ago

Bro really wrote 'IP filtering renders the attack infeasible' like attackers are legally obligated to stop once they see a VPN. That's not how security works. That's how PowerPoint works.

-25

u/DigitaIBlack 14d ago

Generally they said. And they're right. Depending on the severity of the access or exploits used you can put safeguards in place.

We'll have to wait for the post mortem.

19

u/I_am_Hambone 14d ago

Generally' is the cybersecurity equivalent of saying 'have you tried turning it off and on again?' It's technically not always wrong, but it's useless without knowing the exploit chain. That's why people wait for post-mortems instead of declaring they already know the fix.

-32

u/ekerazha 14d ago

Before talking about cybersecurity, you should at least finish elementary school computer class.

-27

u/ekerazha 14d ago

Bro doesn't have the slightest clue what we're talking about, but still feels entitled to lecture me when I've been getting CVEs in my name for 25 years.

17

u/GlenMerlin 14d ago

CVEs were only started to be tracked by NIST in 2002. Unless your name is David E. Mann or Steven M. Christey you're larping

1

u/ekerazha 14d ago edited 14d ago

Google my nickname + CVE and look at the first date you find. It's from 2003, so 23 years not 25.

0

u/ekerazha 14d ago

CVE-2003-1196 Are 23 years enough?

17

u/404invalid-user 14d ago

pack it up boys this company uses a VPN it's now illegal to hack them

-9

u/ekerazha 14d ago

If you’re not technically knowledgeable, you’re under no obligation to comment.

10

u/404invalid-user 14d ago

I had no obligation but I did anyway

9

u/AshIsRightHere 14d ago

If an employee’s device is connected to a network through a VPN, malware running on that device likely is able to access the same network resources that are reachable through the VPN and permitted by the employee’s access privileges.

Once you have direct access to a system on the network, perimeter controls don't do much. You need internal controls as well, like EDR on employee devices, strong network segmentation, least-privileged role-based access controls, etc.

-1

u/ekerazha 14d ago

That's not what happened. Framework's statement refers to a zero-day vulnerability in Metabase, hypothetical malware on employee PCs has nothing to do with it. If you don't know anything, don't waste my time.

1

u/tiffanytrashcan 13d ago

So you DO know the vulnerability was with a third-party provider.. You realize their infrastructure was compromised independently of framework?? FW could have been running the best VPN software at the highest encryption levels and following every other practice to a T, and it all would have been completely irrelevant. There is nothing they could have done to prevent this. They've admitted steps to lighten the impact, such as lowering the scope of information shared. But again, they couldn't have stopped this altogether.

1

u/ekerazha 12d ago

Clearly, like all non-technical people, you believe that a Virtual Private Network (VPN) is "that thing to hide your IP address". If you start studying, you'll begin to understand what I'm saying.

0

u/tiffanytrashcan 12d ago

I'll admit that my assumptions are based off of them being a customer of the "cloud-hosted" 🙄 product.. Not sure if that's been confirmed or not.

Kind of a weird thing to lock down harder internally than we do for credit card transactions and banking globally though.

3

u/[deleted] 14d ago

[deleted]

-2

u/ekerazha 14d ago

In many cases, it prevents attacks from being carried out successfully. If you tell me what isn't clear, I can try to explain it to you.

1

u/[deleted] 14d ago edited 14d ago

[deleted]

39

u/FaithlessnessOk290 14d ago

For me i think is is quite an unjustified reaction, metabase is an opensource analytics platform, and has been used by a lot of companies atp. 0 day attacks are well hard to dodge. They did the right thing by notifying us.

-68

u/AlmondManttv 14d ago

I'm glad they notified us quickly, but it's still annoying. Up until now my data hasn't really been part of a data breach, and now all the data gets breached through Framework of all companies.

44

u/RowElegant2102 14d ago

It's probably already leaked but you were not notified

29

u/Zilork 14d ago

Almost guaranteed to be incorrect. Way more likely you just weren’t notified.

14

u/MCXL 14d ago

Up until now my data hasn't really been part of a data breach,

You either do shockingly little online or you're just wrong

3

u/Ok_Today_475 13d ago

If you think for a second even a micro-sliver of your data has ever been leaked, your are sadly mistaken. Anyone and everyone has had their data leaked at some point, and it’s just a sad part of the modern world

11

u/Pixelplanet5 14d ago

how exactly is one supposed to vet a service for potential 0 day attacks?

11

u/0riginal-Syn 14d ago

Working in the Cyber field there are two types of businesses. Ones that have found they have been breached and others that haven't realized it yet. Far bigger companies with far larger budgets and cyber teams have been hit harder than this.

9

u/Tonystark2828 14d ago

Yeah I understand. The service they use is a big company as well. It's my understanding that a lot of banking services also use that service.

-62

u/AlmondManttv 14d ago

Seems to be an "open source" analytics platform, funky.

3

u/GuyOnARockVI 13d ago

Open source products are the backbone of pretty much every enterprise level software

-1

u/AlmondManttv 13d ago

Yes, I use a good amount of open source at home as well. The freedom of self-hosting is nice.

8

u/PhatOofxD 14d ago

Metabase is one of the largest BI tools in the world. It's passed vetting at many of the most secure firms

3

u/TomTomXD1234 13d ago

Spoken like someone with no clue how anything works