Dear Valued Framework Customer,

We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.

Just arrived into my inbox.

  • geneva_convenience@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    2
    ·
    edit-2
    7 hours ago

    So we entered your personal information into an AI tool. But then the AI tool got hacked and now your personal information is leaked. Whoopsie!

    • Mike@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      5 hours ago

      Metabase isn’t AI, here Business Intelligence means BI tools, basically things that query a lot of data to get fancy charts, mostly for managers and bean counters.

      Like sales over time, or support requests by country.

      They are on the AI bandwagon by the virtue that they have tools that can put together the queries for you, but it’s all very boring graph stuff, not a chat-focused tool.

  • Breezy@sopuli.xyz
    link
    fedilink
    arrow-up
    11
    arrow-down
    1
    ·
    9 hours ago

    I’m so sick and tired of companies keeping all of this extraneous data on us. I haven’t logged into the site nor ordered anything for over a year and I also got this email. Like yes, it’s technically not Framework’s fault, but why are they even keeping information like IP logins or phone numbers? Why aren’t they storing it in the same place they stored purchase information (which apparently has better security)?

    There really is no need for these companies to even have a lot of this information. I wish there were actual punitive punishments for having data be stolen/leaked. Maybe then it’ll make companies stop and truly think on “whether we really need this data in the first place.” Make the fines more expensive than the profit of selling our data. I’m just super salty, because this is probably the 3rd notice I’ve received of my data being leaked this year alone…

    • chaospatterns@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      7 hours ago

      Like yes, it’s technically not Framework’s fault

      I know it’s a third party vendor that got hacked, but I really think the blame still falls on the company that contracted with the vendor.

      Framework decided to hire this company and companies need to recognize the risk in hiring SaaS companies. I know at my previous job we had to go through security and privacy compliance reviews to decide it was even worth sharing data with a third party vendor.

      Too many companies have a ton of SaaS providers and shovel customer data to each one.

      • Breezy@sopuli.xyz
        link
        fedilink
        arrow-up
        3
        ·
        6 hours ago

        Completely agreed. I just wished these companies actually faced punitive consequences instead of sending us another “oopsies, we lost your data again teehee; you’re on your own!” type of responses.

    • Avid Amoeba@lemmy.caOP
      link
      fedilink
      arrow-up
      7
      ·
      edit-2
      8 hours ago

      There is a need though. I used to view companies as producing laptops or vehicles or whatever. From that frame of reference, there’s no need to collect this kind of data. These days I look at them as profit-producing entities. That is their main product is profit. Laptops and vehicles are temporary side effects. From this frame of reference, they need to store this data as it’s another means to produce more profit. For example by more accurately targetting their prices to maximize profit, or selling the data in the future when they can’t grow profits from their laptops. I’m convinced this is the correct frame to view the vast majority of for-profit companies because it predicts their actions much more accurately than the other one.

      • Senal@programming.dev
        cake
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 hours ago

        I agree with that as a model for prediction of behaviour, i don’t agree that there is a need.

        There is obviously a want , but unless there is an existential requirement for data collection like that, the need is speculative.

        • Avid Amoeba@lemmy.caOP
          link
          fedilink
          arrow-up
          1
          ·
          5 hours ago

          I think the want tends to become a need (not for every business in every market) because of a few pressures, among which is the competitive pressure for capital. If this business won’t deliver growing profits, capital would move into another that would. Without capital, there’s no money for procuring the means to do new product. I think that gives the basic pressure for profit maximization that we see around us. It’s not universal - non-profits, private firms which don’t take outside capital whose owners are opposed to profit maximization, and some others tend to not be subject to it. So for some types of businesses I think it qualifies as need, or else they risk their survival and therefore the usually high compensation of their exec layers. I’m not married to proving it need and not want, just thought you might not have looked at it from this angle.

      • Breezy@sopuli.xyz
        link
        fedilink
        arrow-up
        6
        ·
        8 hours ago

        I get that that’s just the way it is now, but it really shouldn’t be.

        I go to a store in person, buy a laptop with cash, no information required. Why does this have to be different for anything else? I purchased a laptop from Framework, because I wanted a repairable/upgradable laptop. Why should they be allowed to sell my data, why do they need a record of the IP addresses I’ve used to access their website, or keep my phone number on file, and so on?

        At least here in the US there is no control of how our data is collected and sold against our will (barring some protection if you live in certain states), and then it inevitably leaks and now we have to deal with trying to not get our identity stolen and or inundated with spam and scams. It’s incredibly frustrating. From the consumer’s point of view there is no “need” for this.

        • Avid Amoeba@lemmy.caOP
          link
          fedilink
          arrow-up
          1
          ·
          5 hours ago

          From a consumer standpoint - 100%. I think the the brick-and-mortar store would also get this data if they could. This reminds me of the massive behaviour surveillance happening in grocery stores. They’ve done it for a long time but these days the latest tech allows them to record detailed stuff like how long you sit in front of a particular product before you pick it up, etc. I don’t know if they link it to identities but I wouldn’t be surprised if they keep face databases even if they don’t know the exact names for each face. I wouldn’t be surprised if they’ve started buying face ID data to “enrich” their datasets. If they haven’t they probably will if they think they can make more money out of it.

  • superbetter@lemmy.ml
    link
    fedilink
    arrow-up
    2
    arrow-down
    1
    ·
    6 hours ago

    I always delete my billing info so that wasn’t there (they say it wasn’t included this time, but it’s a safety precaution I take regardless) but kicking myself that my address was there.

  • robear@lemmy.zip
    link
    fedilink
    arrow-up
    23
    arrow-down
    1
    ·
    19 hours ago

    “Metabase - Open source AI analytics”

    Yep, definitely something you really needed. Fuckin idiots.

  • frki@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    23 hours ago

    I got the same mail. Information regarding orders doesn’t seem to be included, so I hope that as long you have not saved your address information (or deleted it after ordering), the damage is minimized to just your name, IPs, and email addresses.