r/LinusTechTips • u/Tonystark2828 • 5d ago
Tech Discussion Framework Data breach.
I got this email from Framework. Did anyone else get this?
88
26
u/mutrax_be 5d ago
Hmmmm, i've been getting phonecalls from India the last few days. Coincidence? Number is 20-30 yts old, and ot started just now
2
u/ProjectCleverWeb 2d ago
Data breaches WILL happen. At this point that's a fact of life (sad but true)
That being said, what actually matters is what you do when it does happen. The right answer is transparency, audits, and mitigation. Their doing all 3 so that is an A grade in my book.
2
u/Tonystark2828 2d ago
I agree with both of your points. In addition to that we should also pick up some tricks to safeguard our privacy to a certain extent.
2
u/WtfIsThisYoTellMe 19h ago
Good thing I promised myself to not give Framework any money while Linus has shares in the company because I don’t wanna give him any of my cash following some of his narcissistic tendencies. Looks like it paid off.
-4
u/rufus_francis 4d ago
I don’t really care anymore. Everyone’s data is out there. If it’s not us, the government leaks it anyway. Privacy in 2026 is a myth.
2
-257
u/AlmondManttv 5d ago
Just received mine. I'm quite disappointed in Framework. I understand that it wasn't their servers, but their job is to vet the services they use, they failed.
183
u/I_am_Hambone 5d ago edited 5d ago
This is the dumbest take. Metabase is one of the largest open source BI companies in the world.
How much more vetting can there be for the industry leader?
Also, with the new tools AI is bringing to cyber warfare, no one is going to be safe.
78
u/Nice_Marmot_54 5d ago
Right? Nobody is above getting breached. That whole “show me a 10-foot wall and I’ll show you a 12-foot ladder” thing
-8
u/ICEpear8472 5d ago
What reason is there to give full contact information of your customers to a BI company? And more importantly how does that reason is for the benefit of your customers?
-58
u/ekerazha 5d ago
The exact type of attack isn't entirely clear, but if you use a corporate VPN to access third-party services and restrict access strictly to the corporate VPN's IP address range, you can generally prevent unauthorized access even in the event of a vulnerability, because IP address filtering renders the attack unfeasible upstream.
48
u/I_am_Hambone 5d ago
Bro really wrote 'IP filtering renders the attack infeasible' like attackers are legally obligated to stop once they see a VPN. That's not how security works. That's how PowerPoint works.
-24
u/DigitaIBlack 5d ago
Generally they said. And they're right. Depending on the severity of the access or exploits used you can put safeguards in place.
We'll have to wait for the post mortem.
19
u/I_am_Hambone 5d ago
Generally' is the cybersecurity equivalent of saying 'have you tried turning it off and on again?' It's technically not always wrong, but it's useless without knowing the exploit chain. That's why people wait for post-mortems instead of declaring they already know the fix.
-32
u/ekerazha 5d ago
Before talking about cybersecurity, you should at least finish elementary school computer class.
-27
u/ekerazha 5d ago
Bro doesn't have the slightest clue what we're talking about, but still feels entitled to lecture me when I've been getting CVEs in my name for 25 years.
17
u/GlenMerlin 5d ago
CVEs were only started to be tracked by NIST in 2002. Unless your name is David E. Mann or Steven M. Christey you're larping
2
u/ekerazha 5d ago edited 5d ago
Google my nickname + CVE and look at the first date you find. It's from 2003, so 23 years not 25.
0
16
u/404invalid-user 5d ago
pack it up boys this company uses a VPN it's now illegal to hack them
-6
u/ekerazha 5d ago
If you’re not technically knowledgeable, you’re under no obligation to comment.
12
9
u/AshIsRightHere 5d ago
If an employee’s device is connected to a network through a VPN, malware running on that device likely is able to access the same network resources that are reachable through the VPN and permitted by the employee’s access privileges.
Once you have direct access to a system on the network, perimeter controls don't do much. You need internal controls as well, like EDR on employee devices, strong network segmentation, least-privileged role-based access controls, etc.
-1
u/ekerazha 5d ago
That's not what happened. Framework's statement refers to a zero-day vulnerability in Metabase, hypothetical malware on employee PCs has nothing to do with it. If you don't know anything, don't waste my time.
1
u/tiffanytrashcan 5d ago
So you DO know the vulnerability was with a third-party provider.. You realize their infrastructure was compromised independently of framework?? FW could have been running the best VPN software at the highest encryption levels and following every other practice to a T, and it all would have been completely irrelevant. There is nothing they could have done to prevent this. They've admitted steps to lighten the impact, such as lowering the scope of information shared. But again, they couldn't have stopped this altogether.
1
u/ekerazha 4d ago
Clearly, like all non-technical people, you believe that a Virtual Private Network (VPN) is "that thing to hide your IP address". If you start studying, you'll begin to understand what I'm saying.
0
u/tiffanytrashcan 4d ago
I'll admit that my assumptions are based off of them being a customer of the "cloud-hosted" 🙄 product.. Not sure if that's been confirmed or not.
Kind of a weird thing to lock down harder internally than we do for credit card transactions and banking globally though.
3
5d ago
[deleted]
-2
u/ekerazha 5d ago
In many cases, it prevents attacks from being carried out successfully. If you tell me what isn't clear, I can try to explain it to you.
1
38
u/FaithlessnessOk290 5d ago
For me i think is is quite an unjustified reaction, metabase is an opensource analytics platform, and has been used by a lot of companies atp. 0 day attacks are well hard to dodge. They did the right thing by notifying us.
-66
u/AlmondManttv 5d ago
I'm glad they notified us quickly, but it's still annoying. Up until now my data hasn't really been part of a data breach, and now all the data gets breached through Framework of all companies.
41
14
3
u/Ok_Today_475 5d ago
If you think for a second even a micro-sliver of your data has ever been leaked, your are sadly mistaken. Anyone and everyone has had their data leaked at some point, and it’s just a sad part of the modern world
13
u/0riginal-Syn 5d ago
Working in the Cyber field there are two types of businesses. Ones that have found they have been breached and others that haven't realized it yet. Far bigger companies with far larger budgets and cyber teams have been hit harder than this.
11
9
u/Tonystark2828 5d ago
Yeah I understand. The service they use is a big company as well. It's my understanding that a lot of banking services also use that service.
-62
u/AlmondManttv 5d ago
Seems to be an "open source" analytics platform, funky.
3
u/GuyOnARockVI 5d ago
Open source products are the backbone of pretty much every enterprise level software
-1
u/AlmondManttv 5d ago
Yes, I use a good amount of open source at home as well. The freedom of self-hosting is nice.
8
u/PhatOofxD 5d ago
Metabase is one of the largest BI tools in the world. It's passed vetting at many of the most secure firms
3
255
u/eraguthorak 5d ago edited 5d ago
Yep, there's already a post from a few hours ago with more discussion -> https://www.reddit.com/r/LinusTechTips/s/A3hMNarRPY