Rendered at 19:10:19 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
hnacobsxph 2 days ago [-]
Braze API keys end up in a dozen CI configs and nobody rotates them. Campaign send is one POST.
domaaju 2 days ago [-]
I received the push notification via the app this morning as well. Extremely bizarre and not how normally one finds out about a company getting hacked.
jagged-chisel 2 days ago [-]
You probably found out before they did
vachina 2 days ago [-]
Why do you have an app installed just to buy clothes
domaaju 2 days ago [-]
As the person above. I enjoy clothes browsing and shopping, and the app provides a very good experience, plus you normally tend to get app-only discounts. From a retailer perspective, (if the app is good) they get better retention and order value numbers from app customers.
m4tthumphrey 2 days ago [-]
Because I buy a lot of clothes and the ASOS app is well built and its slightly easier to use than the site.
drbscl 2 days ago [-]
Most people do these days; it's convenient. Businesses push it because it improves retention too.
wat10000 2 days ago [-]
Installing an app takes two seconds. It’s not a big effort.
iamacyborg 2 days ago [-]
I am genuinely impressed at the lack of tech literacy in the live feed about this from the beeb.
roryirvine 2 days ago [-]
Yeah, I noticed they were recommending that users log in and reset their password - at a time when ASOS still hadn't said anything about the extent of the problem.
For all they knew, the attackers could have been able to subvert the reset process to collect plaintext passwords, so the Beeb's advice risked turning a disaster for ASOS into a catastrophe for their users.
altcognito 2 days ago [-]
I'm not sure who is recommending that, but if it is in the general channel it could be the proverbial bad guys making that recommendation in order to grab more account credentials.
cube00 2 days ago [-]
> Asos did not immediately respond to the BBC's requests for comment.
Amazing how companies think if they say nothing it'll somehow just go away. Couldn't even be bothered to reply to say they're looking into it.
hnlmorg 2 days ago [-]
Usually the lack of response is because an official response hasn’t yet been approved by the legal department, and then signed off by the board. These things take longer than modern journalism takes to publish an article.
mcintyre1994 2 days ago [-]
I wonder how little time "immediate" means though. They probably have an overwhelming amount of incoming - from journalists, security service providers, and opportunist scammers posing as both of those groups among other things.
2 days ago [-]
quickthrowman 2 days ago [-]
I assume they sent the email at least one minute prior to publishing the article when the sentence is phrased like that, it doesn’t really mean anything other than “We have asked them a question and have yet to receive any reply”. The waiting period could actually be a single minute and still be truthful.
Aurornis 2 days ago [-]
Notice the word “immediately” in that statement.
The journalists were in a rush to publish breaking news. They weren’t going to wait for a response.
This is just a CYA statement to say that they sent a message to the company to do their job but, quite literally, did not immediately get a response.
everfrustrated 2 days ago [-]
It just means the author fired an email in the second before they pressed "publish" on the article.
andruschakartem 2 days ago [-]
The ransom note was addressed to their DPO, customers just got CC'd via push.
rithdmc 2 days ago [-]
Does Snowflake allow you to push messages via in-app messaging? I didn't think it did. This breach might be a little broader than reported.
jmkni 2 days ago [-]
I've seen comments from people claiming they used to work at Asos saying that they have a Braze/Snowflake integration, and the push notification was sent from Braze
UK-Al05 2 days ago [-]
When I used to work there they used databricks not snowflake. So it gave me a bit wtf when i got the notification.
potatoproduct 2 days ago [-]
Yep, my first thought is they probably are probably getting the candidate push notifications from snowflake.
rithdmc 2 days ago [-]
That'll do it. Thank you.
jmkni 2 days ago [-]
Speculating, but it could also be they don't actually have Braze access, but there is a table in snowflake to schedule push notifications
Or they are lying about having snowflake access and only actually have Braze
Lots of fun possibilities!
iamacyborg 2 days ago [-]
As far as I know, the Braze/Snowflake integration is just to pull contact data and event feeds into Braze and to sync out performance data.
If they’ve gained access to Braze presumably they’ll have access to the contact db stored in there along with whatever other information is pushed in to support segmentation and personalisation but it’s definitely limited in scope vs just gaining access to their snowflake db.
This assumes they implemented things sanely with the db user for Braze having limited access rights…
paulcapewell 13 hours ago [-]
Literally "as seen on screen".
eameam 2 days ago [-]
Seems more likely to me that the braze api key was exposed
m4tthumphrey 2 days ago [-]
Stock down 13% today. Interestingly ASOS has been steadily growing this year, would be interested to see Polymarkets today...
ChrisRR 2 days ago [-]
Why does a clothes store need an app in the first place?
m4tthumphrey 2 days ago [-]
As per my other comment to the same question:
> Because I buy a lot of clothes and the ASOS app is well built and its slightly easier to use than the site.
UK-Al05 2 days ago [-]
80% of their orders come through the app
glownagger 2 days ago [-]
Five popups. Five. To read this article that doesn't even tell me what ASOS is.
Zhyl 2 days ago [-]
It's a BBC article for a British retailer. I reckon the knowledge was reasonably assumed for the intended audience.
ifwinterco 2 days ago [-]
It’s extremely well known in the UK which is the intended audience, although even here older readers might not have heard of it
ameliaquining 2 days ago [-]
Second paragraph mentions that it's a "clothing and beauty store".
ChrisRR 2 days ago [-]
Literally the second sentence says it's a clothing store
(ignoring the fact that it's extremely well known in the UK and doesn't need introducing in the UK)
For all they knew, the attackers could have been able to subvert the reset process to collect plaintext passwords, so the Beeb's advice risked turning a disaster for ASOS into a catastrophe for their users.
Amazing how companies think if they say nothing it'll somehow just go away. Couldn't even be bothered to reply to say they're looking into it.
The journalists were in a rush to publish breaking news. They weren’t going to wait for a response.
This is just a CYA statement to say that they sent a message to the company to do their job but, quite literally, did not immediately get a response.
Or they are lying about having snowflake access and only actually have Braze
Lots of fun possibilities!
If they’ve gained access to Braze presumably they’ll have access to the contact db stored in there along with whatever other information is pushed in to support segmentation and personalisation but it’s definitely limited in scope vs just gaining access to their snowflake db.
This assumes they implemented things sanely with the db user for Braze having limited access rights…
> Because I buy a lot of clothes and the ASOS app is well built and its slightly easier to use than the site.
(ignoring the fact that it's extremely well known in the UK and doesn't need introducing in the UK)