I've seen comments from people claiming they used to work at Asos saying that they have a Braze/Snowflake integration, and the push notification was sent from Braze
As far as I know, the Braze/Snowflake integration is just to pull contact data and event feeds into Braze and to sync out performance data.
If they’ve gained access to Braze presumably they’ll have access to the contact db stored in there along with whatever other information is pushed in to support segmentation and personalisation but it’s definitely limited in scope vs just gaining access to their snowflake db.
This assumes they implemented things sanely with the db user for Braze having limited access rights…
I received the push notification via the app this morning as well. Extremely bizarre and not how normally one finds out about a company getting hacked.
As the person above. I enjoy clothes browsing and shopping, and the app provides a very good experience, plus you normally tend to get app-only discounts. From a retailer perspective, (if the app is good) they get better retention and order value numbers from app customers.
Yeah, I noticed they were recommending that users log in and reset their password - at a time when ASOS still hadn't said anything about the extent of the problem.
For all they knew, the attackers could have been able to subvert the reset process to collect plaintext passwords, so the Beeb's advice risked turning a disaster for ASOS into a catastrophe for their users.
I'm not sure who is recommending that, but if it is in the general channel it could be the proverbial bad guys making that recommendation in order to grab more account credentials.
I wonder how little time "immediate" means though. They probably have an overwhelming amount of incoming - from journalists, security service providers, and opportunist scammers posing as both of those groups among other things.
I assume they sent the email at least one minute prior to publishing the article when the sentence is phrased like that, it doesn’t really mean anything other than “We have asked them a question and have yet to receive any reply”. The waiting period could actually be a single minute and still be truthful.
Usually the lack of response is because an official response hasn’t yet been approved by the legal department, and then signed off by the board. These things take longer than modern journalism takes to publish an article.
rithdmc | 10 hours ago
jmkni | 10 hours ago
rithdmc | 10 hours ago
jmkni | 10 hours ago
Or they are lying about having snowflake access and only actually have Braze
Lots of fun possibilities!
iamacyborg | 9 hours ago
If they’ve gained access to Braze presumably they’ll have access to the contact db stored in there along with whatever other information is pushed in to support segmentation and personalisation but it’s definitely limited in scope vs just gaining access to their snowflake db.
This assumes they implemented things sanely with the db user for Braze having limited access rights…
potatoproduct | 9 hours ago
UK-Al05 | 7 hours ago
domaaju | 10 hours ago
jagged-chisel | 10 hours ago
vachina | 9 hours ago
m4tthumphrey | 9 hours ago
domaaju | 8 hours ago
drbscl | 7 hours ago
wat10000 | 5 hours ago
andruschakartem | 10 hours ago
glownagger | 9 hours ago
m4tthumphrey | 9 hours ago
theoreticalmal | 9 hours ago
ameliaquining | 9 hours ago
nstj | 9 hours ago
Zhyl | 9 hours ago
ifwinterco | 9 hours ago
nilamo | 8 hours ago
ChrisRR | 6 hours ago
(ignoring the fact that it's extremely well known in the UK and doesn't need introducing in the UK)
m4tthumphrey | 9 hours ago
hnacobsxph | 9 hours ago
iamacyborg | 9 hours ago
roryirvine | 6 hours ago
For all they knew, the attackers could have been able to subvert the reset process to collect plaintext passwords, so the Beeb's advice risked turning a disaster for ASOS into a catastrophe for their users.
altcognito | 5 hours ago
eameam | 9 hours ago
NoHedgeAllBets | 9 hours ago
Rygian | 8 hours ago
cube00 | 9 hours ago
Amazing how companies think if they say nothing it'll somehow just go away. Couldn't even be bothered to reply to say they're looking into it.
mcintyre1994 | 8 hours ago
quickthrowman | 2 hours ago
Aurornis | 8 hours ago
The journalists were in a rush to publish breaking news. They weren’t going to wait for a response.
This is just a CYA statement to say that they sent a message to the company to do their job but, quite literally, did not immediately get a response.
everfrustrated | 7 hours ago
hnlmorg | 8 hours ago
ChrisRR | 6 hours ago
m4tthumphrey | 6 hours ago
> Because I buy a lot of clothes and the ASOS app is well built and its slightly easier to use than the site.
UK-Al05 | 6 hours ago