Top
Best
New

Posted by RobinHirst11 1 day ago

Framework discloses data breach via Metabase 0-day(community.frame.work)
143 points | 53 commentspage 2
anon7000 15 hours ago|
> Its disappointing another company has chosen to share our personal information with another third party

This forum poster would be… shocked to see how many SaaS companies are critical dependencies at most tech companies.

Imo, we need to get better at self hosting these kinds of tools. When I did a brief stint in BI tooling, we were basically using local tools with data exported from (gasp) SAP, and there was a dinky windows server behind someone’s desk where it’d run automated reports based on what we’d build and send out emails.

Certainly orders of magnitude cheaper. Maybe there was occasional downtime, but it didn’t really matter. You could always get the Oncall to generate the report you needed anyways

srcz 10 hours ago||
Any IOCs identified for the threat actor?
esafak 11 hours ago||
tally.so also got affected. https://www.metabase.com/blog/security-update
doublerabbit 23 hours ago||
Beacon CRS was also exploited, I wonder if related somehow.
edent 1 day ago||
[flagged]
philipallstar 1 day ago||
I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.
account42 23 hours ago|||
Stop being reasonable we are all gathered here to burn the witch.
OuterVale 1 day ago||||
This is a pretty decent run down (and DHH has taken it much further since this post was published): https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thoug...
phoronixrly 23 hours ago|||
Enjoy https://world.hey.com/dhh/wolves-sheep-and-gypsies-ba44af6a
philipallstar 19 hours ago|||
I still don't see racism there. I agree people, foreign or domestic, shouldn't be camping in public spaces. If the law is only enforced against domestic transgressors (or they are just raised in a culture that doesn't require enforcement) then it's right to criticise policies that turn a blind eye to foreign transgressors.
lelanthran 19 hours ago||||
If you think that's racist then you're the reason people like trump win elections and the opposition loses.
Georgelemental 19 hours ago|||
"point and sputter" is not an argument
vaylian 23 hours ago||
I agree that sponsoring DHH was a mistake. But I don't see how Framework could have used more money on security to prevent a zeroday in a third party product.
wigger1 23 hours ago||
They could have sponsored the political activists driving NixOS instead.
BlueTemplar 18 hours ago||
Those Microsoft pawns ?
bravetraveler 22 hours ago|
Business intelligence, vendor free: I'm done buying from them. Call it harsh, that's fine. That's business, baby.
nisegami 14 hours ago|
Who are you gonna buy from instead?
bravetraveler 14 hours ago||
Your point, I suspect, is well-taken: choices are limited. Preference would be... any business which doesn't have the information to leak it in the first place. Retail, cash? Does that still exist? Anyway, this "we'll share excessive information with too many partners" pattern is far too normalized. Eventually I may be forced to choose the forest over buying [or building] another computer.

Realistically, if I had to buy: my employer, probably, given a reasonable discount. Unless you know a business that doesn't eagerly share personally identifiable information [which ends up leaked]... I'll aim for reduction, not resolution. I'm sure you've heard the quip about making Perfect the enemy of Better.

Regardless, and more fairly: with prices squeezed, and the pile of hardware I already own and ignore [including several old-school towers, both Framework desktop/laptop, and Steam Deck/Machine], I'm not foreseeing much shopping. Big loss on their part, I know; wish that was the intention.