Framework 通过 Metabase 零日漏洞披露数据泄露事件
Framework discloses data breach via Metabase 0-day

原始链接: https://community.frame.work/t/framework-data-breach-discussion/83939

Framework 的客户正在讨论该公司针对近期 Metabase 第三方数据泄露事件所做出的回应。尽管许多用户称赞 Framework 反应迅速且透明——在发现漏洞后的六小时内即通知了客户——但仍有人持批评态度。 支持者认为,Framework 的应对措施为企业问责树立了高标准。相反,持怀疑态度的用户对第三方数据共享的常态化感到不满,并质疑为何敏感的客户信息最初会被商业智能平台访问。一些用户还批评该公司将此次事件定性为“有限的”泄露,并指出被盗数据包含重要的个人身份信息。 除了沟通本身,客户还对后续影响表示担忧。许多人担心网络钓鱼风险增加,并敦促 Framework 改变处理支付相关电子邮件的方式,以避免使用链接。此外,社区中也出现了一种更广泛的呼声,要求 Framework 在未来严格限制与第三方供应商共享的数据量。尽管迅速披露的态度受到认可,但社区对于导致此次泄露的潜在数据安全做法仍感到不安。

Framework 披露了一起涉及其商业智能提供商 Metabase 的数据泄露事件。攻击者利用 Metabase 中的一个“零日”漏洞获得了对 Framework 数据库的未经授权访问,导致客户姓名、电子邮件地址、电话号码、IP 地址以及账单/配送信息泄露。Framework 已确认支付和订单数据未受到影响。 作为应对,Framework 已轮换了其数据库凭据,目前正在评估与第三方分析平台的数据共享实践,以尽量减少访问权限。 此次事件在 Hacker News 上引发了激烈讨论。用户对涉及第三方分析和 CRM 供应商的泄露事件频发表示沮丧,并主张企业应将敏感的个人身份信息(PII)保存在内部。批评人士强调,相比密码,家庭地址等元数据更难保护或更改,并敦促企业优先实施数据最小化原则。一些客户已要求根据 GDPR 和 CCPA 删除其全部数据,而另一些客户则质疑为何最初会将如此多的个人身份信息存储在外部工具中。
相关文章

原文

I just received an email about a limited data breach, leaking customer information (no billing info though). Do you guys think Framework is handling this well? The email looked very detailed and transparent to me.

4 Likes

The transparency and especially the expediency of notification is greatly appreciated, I’d say not only by the Framework team but also by Metabase. A 3 day turnaround by Metabase from initial discovery of the incident to notify business partners is impressive. And the Framework team took only 6 HOURS from receiving Metabase’s notice before internally confirming and notifying their customers!! That is unheard of!! It seems like most companies wait months (at minimum) before notifying customers (if they do at all) because they think any security issue will cause the public to lose trust in them.

These days, it’s not a matter of when you suffer a security incident. It’s how quickly and transparently you respond to it and notify your customers. In my opinion, the Framework team far exceeded expectations, and I anticipate any updates will be met with the same level of transparency. Other companies need to take note, this is how you handle a security incident.

2 Likes

Credit card info. Need assurance that was not accessed by the hackers.

Their privacy policy states Stripe is used for handling payments, and it was already stated in the email there was no payment information.

1 Like

Its disappointing another company has chosen to share our personal information with another third party. While at this point I think all of my information has probably already been leaked, I still do not appreciate my data being shared with third party providers. Getting all your personal information leaked because a company you have never heard of or interacted with is getting insanely normalised.

6 Likes

While I appreciate Framework’s notice and transparency (moreso than most orgs), I can’t say it’s not frustrating to be part of yet another data breach. Maybe we stop sharing so much data with 3rd parties??

5 Likes

I agree. Communication at this level is appreciated. The fact remains that Framework is benefiting from storing our data with a 3rd party for whatever vague analysis they decide to use it for and we bear the consequences of having certain data exposed when it shouldn’t be.

From Framework’s Notice:

What steps have you taken to ensure this doesn’t happen in the future?

We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.

Obviously this is moving in the right direction, but it may reveal that the depth of information previously shared with this platform was excessive to begin with.

1 Like

Appreciate the transparency, but I do not appreciate the wording of the messaging. Calling this a “limited” breach right in the email subject is quite dishonest when basically all the personally identifiable information is there.

Also the email lists all the personally identifiable information and then it says “no other personally identifiable information has been taken”. Yeah, that’s all you had! This feels like a dark pattern of communication. You can do better, framework.

Also, does the business side have to have names, emails of the customers? Also, of course it sucks that only now you’re starting to ask these questions…

1 Like

I got the breach notification today. Earlier this week I got an “Action Required” email asking me to update my payment method before my laptop would ship.

I always handle emails like these by ignoring the button and logging in directly at the relevant website (this time Framework). It worked out well, and the email was clearly legitimate.

But I’d like to flag the pattern. A phishing email built off the breached data would look almost exactly like the one I received: same sender name, same layout, same urgency, same big button to update payment information.

I understand that Framework likely will not strip the link entirely, as it will make the friction of updating payment info too much for some users. But I would suggest that the email primarily asks the customer to log in through the web site and not through a link.

Most Nordic banks dropped payment links from customer emails years ago for this reason. As far as I know this has not been a problem. Given that Framework customers are now a known list of names and addresses, it seems worth revisiting.

Thanks for disclosing the breach quickly. That was handled very well. As I am now awaiting the delivery of my laptop, I will be even more vigilant than normal if I receive an email on import fees etc. that could be a targeted phishing attempt.

Frustrating that it happened. Appreciate being informed so quickly. Not sure about calling it a “limited” data breach, though, considering what was accessed.

Not sure why I got an email about it, I haven’t made a purchase but I think I signed up for a waitlist.

I appreciate the response, definitely. In some juristictions (states in the US), it’s not required to disclose ‘minor’ breaches of public info, and many companies choose not to disclose it.

I’ve been around the block for a few decades and what gave me pause was that it was claimed to be a zero-day exploit, but was immediately patched when the hack was discovered. Those two things don’t usually go together and methinks someone dropped the ball on patching.

The way I sometimes interpret ‘limited’ is that they may have gotten all of my info, but perhaps not the entire database of every customer. My idea of ‘limited’ and Framework’s idea of ‘limited’ could be two entirely different things.

I’ve been online since the gopher and usenet days and maybe it’s just my weary bones talking, but I live my life with the assumption that regardless of all the precautions I’ve taken, every address, employment record, credit card, checking account, social security number (US), etc. I’ve ever had is out there already. It’s just that no organized crime syndicate, nor just a two-bit street hustler, is gonna look at a Home Depot card with a $1000 limit and bother with it.

Maybe Framework is handling things well, but now with their addresses out everyone who talked publicly about their recent orders should be considered at risk of targeted physical theft due to the current prices.
For this reason I’d suggest that the “Batch X” topics for recent releases get deleted, but maybe some data gathering already happened there.

联系我们 contact @ memedata.com