| ▲ | parable 2 days ago |
| While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days. I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use that where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house. As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily. |
|
| ▲ | vermon 2 days ago | parent | next [-] |
| Just don't use the cloud version of Metabase. You can self host it and not allow accessing it over the internet. |
| |
| ▲ | parable 2 days ago | parent [-] | | Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ultimately forces them to be solely responsible for their customers' data. Using the cloud versions of these products shifts the blame from the company itself to the vendor when things go sideways, so it makes more sense for them to do this instead of taking responsibility. | | |
|
|
| ▲ | account42 2 days ago | parent | prev | next [-] |
| The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact. |
| |
| ▲ | cassianoleal 2 days ago | parent | next [-] | | That is already the case for where I live, and yet I am on that breach, with names, addresses, etc. all leaked. Unfortunately it's not enough to collect "only necessary" if what's necessary is too much in the hands of the attacker. | |
| ▲ | BlueTemplar 2 days ago | parent | prev | next [-] | | There are people that pre-ordered their latest PC that are currently waiting for the remaining batches to become available, finish paying the PC price in full, and have it shipped to them. So this information does fullfill a direct customer need. | | |
| ▲ | KlutzySofa 2 days ago | parent [-] | | I have never made a purchase via Framework and still got the email from them. Probably because I once put in my data to see final shipping and import costs. |
| |
| ▲ | parable 2 days ago | parent | prev | next [-] | | This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place. | |
| ▲ | GoblinSlayer 2 days ago | parent | prev | next [-] | | Can't they store that information encrypted? What analytics can be extracted from phone numbers? It's only good to sell on black market. | |
| ▲ | yread 2 days ago | parent | prev | next [-] | | I'm waiting for this for 7 years already: I'm too lazy to setup proper analytics with 800 "legitimate partners" on my website | |
| ▲ | bityard 2 days ago | parent | prev | next [-] | | If framework did as you suggest, they would have no way to validate warranty status and recalls. Motherboard died after 3 months? Tough luck, they have no record of you being a customer. Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow. | | |
| ▲ | ang_cire 2 days ago | parent | next [-] | | These are bad examples. Warranty status is tied to hardware* serials. It's not like there are third-party Framework sellers. Sending a recall notice via email doesn't require name, address, dob, etc. Companies are in a bad habit of not actually clearing customer data they don't need. | |
| ▲ | account42 2 days ago | parent | prev | next [-] | | Of course they do. How do you think warranty works for in-person cash purchases? | |
| ▲ | okasaki 2 days ago | parent | prev [-] | | Put a sticker with a unique ID on parts. |
| |
| ▲ | codedokode 2 days ago | parent | prev [-] | | Sounds like GDPR? |
|
|
| ▲ | d3Xt3r 2 days ago | parent | prev [-] |
| > I'm impressed with Framework's handling of this issue I'm not. I'd like to see some sort of tangible compensation from them, not just a "we're sorry". Maybe a discount code or a freebie, or actual hard cash. I'd also like to see them pursue legal action against Metabase. And finally, I'd like them to be upfront with how they store and use PII. Had I known that they were going go store it with a third-party - and that too, unsalted and unencrypted - I would've never even signed up. |