Framework Data Breach

6 points | by rkagerer an hour ago

1 comments

  • rkagerer 17 minutes ago

    > We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.

    Or you could just stop fucking sending my data to third parties when it's for your own sole benefit rather than mine.

    I realize my comment is crass, but it's getting ridiculous how pervasive the risk-laundering of PII has become between tech companies. Everyone's adopting a myriad of SaaS platforms that are deceptively easy to plug in, and it's too tempting to wipe your hands when it comes to accountability. Attitudes of "it's not our fault, it was our vendor" beckon better due diligence.

    I don't mean to single out Framework here - the problem is not in any way limited to them, and to be honest their response seems like one of the more responsible disclosures I've seen (it's helpful it lists the specific fields and some technical data, and it's encouraging they're clamping down scope even if it comes a little late). I'm a fan of their mission, and wish them resounding success in their business.

    Tech leaders and CTO's: We need to get our act together as an industry. Treat PII like the toxic asset it is. Appreciate the gravity of trust your users placed in you when they entrusted you with custody of their data. Be more discriminating about your vendors (think about the gauntlet Apple puts their hardware vendors through). And for god's sake, stop indiscriminately shipping it off to every trendy service du jour.