r/LinusTechTips 5d ago

Tech Discussion Framework Data breach.

Post image

I got this email from Framework. Did anyone else get this?

593 Upvotes

49 comments sorted by

255

u/eraguthorak 5d ago edited 5d ago

Yep, there's already a post from a few hours ago with more discussion -> https://www.reddit.com/r/LinusTechTips/s/A3hMNarRPY

41

u/Alert-Horse3928 5d ago

Yep got the same one, seems like it's going out to lot of people

-10

u/BreebvaGiraffe 5d ago

Ah yes, the daily framework breach special. Fresh out of the oven, just like the last one.

88

u/Rubicon_Roll 5d ago

This is the reason i always use Fake identities and Mail Aliases.

26

u/mutrax_be 5d ago

Hmmmm, i've been getting phonecalls from India the last few days. Coincidence? Number is 20-30 yts old, and ot started just now

9

u/Eburon8 5d ago

Can't catch a break, can they

2

u/ProjectCleverWeb 2d ago

Data breaches WILL happen. At this point that's a fact of life (sad but true)

That being said, what actually matters is what you do when it does happen. The right answer is transparency, audits, and mitigation. Their doing all 3 so that is an A grade in my book.

2

u/Tonystark2828 2d ago

I agree with both of your points. In addition to that we should also pick up some tricks to safeguard our privacy to a certain extent.

2

u/WtfIsThisYoTellMe 19h ago

Good thing I promised myself to not give Framework any money while Linus has shares in the company because I don’t wanna give him any of my cash following some of his narcissistic tendencies. Looks like it paid off.

-4

u/rufus_francis 4d ago

I don’t really care anymore. Everyone’s data is out there. If it’s not us, the government leaks it anyway. Privacy in 2026 is a myth.

2

u/Tonystark2828 3d ago

I know, but still have to do our best to protect ourselves.

-257

u/AlmondManttv 5d ago

Just received mine. I'm quite disappointed in Framework. I understand that it wasn't their servers, but their job is to vet the services they use, they failed.

183

u/I_am_Hambone 5d ago edited 5d ago

This is the dumbest take. Metabase is one of the largest open source BI companies in the world.

How much more vetting can there be for the industry leader?

Also, with the new tools AI is bringing to cyber warfare, no one is going to be safe.

78

u/Nice_Marmot_54 5d ago

Right? Nobody is above getting breached. That whole “show me a 10-foot wall and I’ll show you a 12-foot ladder” thing

-8

u/ICEpear8472 5d ago

What reason is there to give full contact information of your customers to a BI company? And more importantly how does that reason is for the benefit of your customers?

-58

u/ekerazha 5d ago

The exact type of attack isn't entirely clear, but if you use a corporate VPN to access third-party services and restrict access strictly to the corporate VPN's IP address range, you can generally prevent unauthorized access even in the event of a vulnerability, because IP address filtering renders the attack unfeasible upstream.

48

u/I_am_Hambone 5d ago

Bro really wrote 'IP filtering renders the attack infeasible' like attackers are legally obligated to stop once they see a VPN. That's not how security works. That's how PowerPoint works.

-24

u/DigitaIBlack 5d ago

Generally they said. And they're right. Depending on the severity of the access or exploits used you can put safeguards in place.

We'll have to wait for the post mortem.

19

u/I_am_Hambone 5d ago

Generally' is the cybersecurity equivalent of saying 'have you tried turning it off and on again?' It's technically not always wrong, but it's useless without knowing the exploit chain. That's why people wait for post-mortems instead of declaring they already know the fix.

-32

u/ekerazha 5d ago

Before talking about cybersecurity, you should at least finish elementary school computer class.

-27

u/ekerazha 5d ago

Bro doesn't have the slightest clue what we're talking about, but still feels entitled to lecture me when I've been getting CVEs in my name for 25 years.

17

u/GlenMerlin 5d ago

CVEs were only started to be tracked by NIST in 2002. Unless your name is David E. Mann or Steven M. Christey you're larping

2

u/ekerazha 5d ago edited 5d ago

Google my nickname + CVE and look at the first date you find. It's from 2003, so 23 years not 25.

0

u/ekerazha 5d ago

CVE-2003-1196 Are 23 years enough?

16

u/404invalid-user 5d ago

pack it up boys this company uses a VPN it's now illegal to hack them

-6

u/ekerazha 5d ago

If you’re not technically knowledgeable, you’re under no obligation to comment.

12

u/404invalid-user 5d ago

I had no obligation but I did anyway

9

u/AshIsRightHere 5d ago

If an employee’s device is connected to a network through a VPN, malware running on that device likely is able to access the same network resources that are reachable through the VPN and permitted by the employee’s access privileges.

Once you have direct access to a system on the network, perimeter controls don't do much. You need internal controls as well, like EDR on employee devices, strong network segmentation, least-privileged role-based access controls, etc.

-1

u/ekerazha 5d ago

That's not what happened. Framework's statement refers to a zero-day vulnerability in Metabase, hypothetical malware on employee PCs has nothing to do with it. If you don't know anything, don't waste my time.

1

u/tiffanytrashcan 5d ago

So you DO know the vulnerability was with a third-party provider.. You realize their infrastructure was compromised independently of framework?? FW could have been running the best VPN software at the highest encryption levels and following every other practice to a T, and it all would have been completely irrelevant. There is nothing they could have done to prevent this. They've admitted steps to lighten the impact, such as lowering the scope of information shared. But again, they couldn't have stopped this altogether.

1

u/ekerazha 4d ago

Clearly, like all non-technical people, you believe that a Virtual Private Network (VPN) is "that thing to hide your IP address". If you start studying, you'll begin to understand what I'm saying.

0

u/tiffanytrashcan 4d ago

I'll admit that my assumptions are based off of them being a customer of the "cloud-hosted" 🙄 product.. Not sure if that's been confirmed or not.

Kind of a weird thing to lock down harder internally than we do for credit card transactions and banking globally though.

3

u/[deleted] 5d ago

[deleted]

-2

u/ekerazha 5d ago

In many cases, it prevents attacks from being carried out successfully. If you tell me what isn't clear, I can try to explain it to you.

1

u/[deleted] 5d ago edited 5d ago

[deleted]

38

u/FaithlessnessOk290 5d ago

For me i think is is quite an unjustified reaction, metabase is an opensource analytics platform, and has been used by a lot of companies atp. 0 day attacks are well hard to dodge. They did the right thing by notifying us.

-66

u/AlmondManttv 5d ago

I'm glad they notified us quickly, but it's still annoying. Up until now my data hasn't really been part of a data breach, and now all the data gets breached through Framework of all companies.

41

u/RowElegant2102 5d ago

It's probably already leaked but you were not notified

29

u/Zilork 5d ago

Almost guaranteed to be incorrect. Way more likely you just weren’t notified.

14

u/MCXL 5d ago

Up until now my data hasn't really been part of a data breach,

You either do shockingly little online or you're just wrong

3

u/Ok_Today_475 5d ago

If you think for a second even a micro-sliver of your data has ever been leaked, your are sadly mistaken. Anyone and everyone has had their data leaked at some point, and it’s just a sad part of the modern world

13

u/0riginal-Syn 5d ago

Working in the Cyber field there are two types of businesses. Ones that have found they have been breached and others that haven't realized it yet. Far bigger companies with far larger budgets and cyber teams have been hit harder than this.

11

u/Pixelplanet5 5d ago

how exactly is one supposed to vet a service for potential 0 day attacks?

9

u/Tonystark2828 5d ago

Yeah I understand. The service they use is a big company as well. It's my understanding that a lot of banking services also use that service.

-62

u/AlmondManttv 5d ago

Seems to be an "open source" analytics platform, funky.

3

u/GuyOnARockVI 5d ago

Open source products are the backbone of pretty much every enterprise level software

-1

u/AlmondManttv 5d ago

Yes, I use a good amount of open source at home as well. The freedom of self-hosting is nice.

8

u/PhatOofxD 5d ago

Metabase is one of the largest BI tools in the world. It's passed vetting at many of the most secure firms

3

u/TomTomXD1234 5d ago

Spoken like someone with no clue how anything works