-
47 votes
-
Help with Amazon Glacier (original) data retrieval
Hi folks. I'm in way over my head with an AWS problem. Mainly because I don't understand how to use AWS at all, but in 2013 I used a tool called FastGlacier to backup my data (including baby...
Hi folks. I'm in way over my head with an AWS problem. Mainly because I don't understand how to use AWS at all, but in 2013 I used a tool called FastGlacier to backup my data (including baby picture and videos) to Amazon Glacier. I also had them on a local drive and a HDD I gave to a friend. Alas, my drive failed a few years ago, and he lost the other in a move.
Anyway, I'm not a coder, and AWS baffles me. I'd like to retrieve these data but don't know where to start. Would anybody well versed in AWS be willing to walk me through the process? The AWS guidance is over my head.
Many thanks in advance.
6 votes -
Framework customer info has been breached
Just got this email from Framework: Dear Valued Framework Customer, We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an...
Just got this email from Framework:
Dear Valued Framework Customer,
We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
What happened?
On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
Sameer Al-Sakran
Founder and CEO
Metabase
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:
- Full name
- Email address
- Login IPs
- Billing and shipping address information
- Country
- Address
- City
- State
- Zip code
- Phone number
- Company
For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
- Company
- Phone
- VAT
- EIN
- Billing Email
- No other personally identifiable information, order information, or payment information was accessed.
Note that Metabase has additionally flagged:
Important: This is a preliminary update based on our current knowledge.
We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.
We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.
Our investigation is ongoing and the information shared now is preliminary.
Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.
We’re providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.
What was done to resolve the issue?
After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.
What steps have you taken to ensure this doesn’t happen in the future?
We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.
Nirav Patel and the Framework Team
53 votes -
What Google thinks you're worth
38 votes -
Swedish non-profit has filed a class action lawsuit against Norway's Telenor, accusing it of endangering customers in Myanmar by sharing their data with the junta
10 votes -
You can finally change the goofy Gmail address you chose years ago
48 votes -
GrapheneOS refuses to comply with new age verification laws for operating systems — group says it will never require personal information
75 votes -
Proton Mail helped US FBI unmask anonymous ‘Stop Cop City’ protester
63 votes -
PornHub extorted after hackers steal Premium member activity data
33 votes -
Mozilla Firefox gets new anti-fingerprinting defenses
59 votes -
Data brokers know everything about you (ft. Yael Grauer)
22 votes -
California lets residents opt-out of a ton of data collection on the web
22 votes -
Sweden's employment agency has been tracking the online locations of thousands of citizens claiming unemployment benefits in an effort to crack down on welfare fraud
28 votes -
The EU wants to decrypt your private data by 2030
50 votes -
In a world first, Brazilians will soon be able to sell their digital data
16 votes -
Meta and Yandex are de-anonymizing Android users’ web browsing identifiers
22 votes -
eBay privacy policy update and AI opt-out
eBay is updating its privacy policy, effective next month (2025-04-27). The major change is a new section about AI processing, accompanied by a new user setting with an opt-out checkbox for having...
eBay is updating its privacy policy, effective next month (2025-04-27). The major change is a new section about AI processing, accompanied by a new user setting with an opt-out checkbox for having your personal data feed their models.
While that page specifically references European areas, the privacy selection appears to be active and remembered between visits for non-Europe customers. It may not do anything for us at all. On the other hand, it seems nearly impossible to find that page from within account settings, so I thought I'd post a direct link.
I'm well aware that I'm anomalous for having read this to begin with, much less diffed it against the previous version. But since I already know that I'm weird, and this wouldn't be much of a discussion post without questions:
- How do you stay up to date with contract changes that might affect you, outside of widespread Internet outrage (such as recent Firefox news)?
- What's your threshold -- if any -- for deciding whether to quit a company over contract changes? Alternatively, have you ever walked away from a purchase, service, or other acquisition over the terms of the contracts?
46 votes -
Firefox's new Terms of Use grants Mozilla complete data "processing" rights of all user interactions
58 votes -
Meredith Whittaker said Signal intends to exit Sweden should its government amend existing legislation essentially mandating the end of end-to-end encryption
26 votes -
Google faces US trial for collecting data on users who opted out
39 votes -
Chatbots urged teen to self-harm, suggested murdering parents, Texas lawsuit says
24 votes -
Your chatbot transcripts may be a gold mine for AI companies
25 votes -
LinkedIn is the latest to automatically opt you in to AI training
35 votes -
Paypal opted you into sharing data without your knowledge
90 votes -
Google must destroy $5 billion worth of user data illegally collected in Incognito Mode
55 votes -
Microsoft will train AI on user data
44 votes -
Tech giants should be made subject to a global tax for their use of people's personal data, according to Norway's Finance Minister Trygve Slagsvold Vedum
30 votes -
Meta hit with Norwegian complaint over its plans to use images and posts of users on Facebook and Instagram to train artificial intelligence models
27 votes -
Proton Mail discloses user data leading to arrest in Spain
41 votes -
The startup offering free toilets and coffee for delivery workers — in exchange for their data
26 votes -
FYI: This site claims to have harvested 4B+ Discord chats, today all yours for a price
41 votes -
Proton Mail on all the data that Outlook collects about your email
61 votes -
Time to delete your Glassdoor account and data
102 votes -
Tell US Congress: Stop the TikTok ban
32 votes -
Tumblr to begin selling user content to AI generative service companies, opt-out will be per blog
75 votes -
Introducing Mozilla Monitor Plus, a new tool to automatically remove your personal information from data broker sites
35 votes -
Twenty-six billion records exposed in massive leak, including data from Linkedin, X, Dropbox
44 votes -
Google promises unlimited cloud storage; then cancels plan; then tells journalist his life’s work will be deleted without enough time to transfer the data
90 votes -
Dropbox spooks users with new AI features that send data to OpenAI when used
49 votes -
Accused of violating kids' privacy, Meta sues US Federal Trade Commission, hoping to block ban on monetizing kids’ data
40 votes -
Norway's privacy battle with Meta is just getting started – regulator says it's investigating the company's new ad-free subscription services
28 votes -
Consumer Reports releases "Permission Slip" app for requesting data removal
31 votes -
Google user data has become a favorite police shortcut
54 votes -
Philips Hue will force users to upload their data to Hue cloud
72 votes -
Norway asks EU regulator European Data Protection Board to fine Facebook owner Meta over privacy breach
9 votes -
Your Fitbit is useless – unless you consent to unlawful data sharing
74 votes -
38TB of data accidentally exposed by Microsoft AI researchers
14 votes -
Meta lost a legal battle Wednesday to halt a Norwegian ban on its advertising practices that came with hefty daily fines
22 votes -
X to collect biometric and employment data
39 votes -
US Consumer Financial Protection Bureau announces plans to regulate sale of personal data
35 votes