Framework discloses data breach via Metabase 0-day

(community.frame.work)

24 points | by RobinHirst11 an hour ago ago

2 comments

  • pelagicAustral 2 minutes ago ago

    Metabase again?? Last 0day was catastrophic. My previous employer moved all that infrastructure back to on-prem, I guess he must be laughing now.

  • parable 7 minutes ago ago

    While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days.

    I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use that where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house.

    As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily.