Framework Data Breach

9 pointsposted 10 hours ago
by rkagerer

3 Comments

aunty_helen

8 hours ago

I bought one of their first garbage laptops. The ones that flatten the battery overnight.

Now 5 years later I'm being told I've had my data breached for a dashboard.

I don't even have the laptop anymore, I gave it away. I still have my Pentium M laptop from high school...

rkagerer

9 hours ago

> We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.

Or you could just stop fucking sending my data to third parties when it's for your own sole benefit rather than mine.

I realize my comment is crass, but it's getting ridiculous how pervasive the sharing of PII has become between tech companies, and the risk-laundering that's given rise to. Everyone's adopting a myriad of SaaS platforms that are deceptively easy to plug in, and it's too tempting to shed accountability. Attitudes of "it's not our fault, it was our vendor" beckon better due diligence.

I don't mean to single out Framework here - the problem is not in any way limited to them, and to be honest their response may be one of the more responsible disclosures I've seen (it's helpful it lists the specific fields and some technical data, and I'm glad they're clamping down even if it comes too late). I'm a fan of their mission, and wish them resounding success in their business.

But a forceful call to action is needed!

Tech leaders and CTO's: Let's get our act together as an industry. Treat PII like the toxic asset it is. Remember each row in that database is a real human being, and appreciate the gravity of responsibility they entrusted you with when they forked over their information. Be more rigorous vetting your vendors (think about the gauntlet Apple puts their hardware suppliers through). And for god's sake, stop indiscriminately shipping it off to every trendy service du jour.

Consumers: Avoid falling into indifference. Refuse to accept these data thefts are inevitable. And get rightly fired up and angry when the companies you trusted with custody of your data let you down.

d3Xt3r

7 hours ago

I think the important thing here is transparency - if I'd known, at the time of submitting my PII, that my details would be shared with a random third-party I never heard of - I would've never even created a Framework account in the first place.