4 ms·
While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics
by parable 2mo ago
While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days.
I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use that where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house.
As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily.
- vermon 2mo agoJust don't use the cloud version of Metabase. You can self host it and not allow accessing it over the internet.
- parable 2mo agoMetabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ultimately forces them to be solely responsible for their customers' data. Using the cloud versions of these products shifts the blame from the company itself to the vendor when things go sideways, so it makes more sense for them to do this instead of taking responsibility.
- Godsend69 2mo ago[dead]
- akd 2mo agoSalesforce hasn't ever been hacked to the best of my knowledge.
- vladsanchez 2mo ago"Yes, Salesforce has experienced multiple hacking incidents, particularly involving social engineering attacks that targeted its customers, leading to significant data breaches. Notably, the hacking group ShinyHunters has claimed responsibility for exploiting vulnerabilities in Salesforce's systems, affecting numerous high-profile companies." Source: https://duckduckgo.com/?q=has+salesforce+ever+been+hacked%3F&ia=web&assist=true https://duckduckgo.com/?q=has+salesforce+ever+been+hacked%3F... Yes, *Salesforce has experienced multiple hacking incidents*, particularly involving social engineering attacks that targeted its customers, leading to significant data breaches. Notably, the hacking group ShinyHunters has claimed responsibility for exploiting vulnerabilities in Salesforce's systems, affecting numerous high-profile companies. Cloudflare also reported one as recent as 4 days ago, impacting over 700 companies. Source: https://dailysecurityreview.com/cyber-security/cloudflare-confirms-salesforce-breach-in-growing-supply-chain-attack/ https://dailysecurityreview.com/cyber-security/cloudflare-co...
- akd 1mo ago"Social engineering attacks that targeted its customers" is not being hacked.
- account42 2mo agoThe solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
- parable 2mo agoThis would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place.
- cassianoleal 2mo agoThat is already the case for where I live, and yet I am on that breach, with names, addresses, etc. all leaked. Unfortunately it's not enough to collect "only necessary" if what's necessary is too much in the hands of the attacker.
- yread 2mo agoI'm waiting for this for 7 years already: I'm too lazy to setup proper analytics with 800 "legitimate partners" on my website
- GoblinSlayer 2mo agoCan't they store that information encrypted? What analytics can be extracted from phone numbers? It's only good to sell on black market.
- bityard 2mo agoIf framework did as you suggest, they would have no way to validate warranty status and recalls. Motherboard died after 3 months? Tough luck, they have no record of you being a customer. Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow.
- d3Xt3r 2mo ago> I'm impressed with Framework's handling of this issue I'm not. I'd like to see some sort of tangible compensation from them, not just a "we're sorry". Maybe a discount code or a freebie, or actual hard cash. I'd also like to see them pursue legal action against Metabase. And finally, I'd like them to be upfront with how they store and use PII. Had I known that they were going go store it with a third-party - and that too, unsalted and unencrypted - I would've never even signed up.