47 points helsinkiandrew 3 hours ago 29 comments

rithdmc 2 hours ago | parent

Does Snowflake allow you to push messages via in-app messaging? I didn't think it did. This breach might be a little broader than reported.

jmkni 1 hour ago | parent

I've seen comments from people claiming they used to work at Asos saying that they have a Braze/Snowflake integration, and the push notification was sent from Braze

rithdmc 1 hour ago | parent

That'll do it. Thank you.

jmkni 1 hour ago | parent

Speculating, but it could also be they don't actually have Braze access, but there is a table in snowflake to schedule push notifications

Or they are lying about having snowflake access and only actually have Braze

Lots of fun possibilities!

iamacyborg 47 minutes ago | parent

As far as I know, the Braze/Snowflake integration is just to pull contact data and event feeds into Braze and to sync out performance data.

If they’ve gained access to Braze presumably they’ll have access to the contact db stored in there along with whatever other information is pushed in to support segmentation and personalisation but it’s definitely limited in scope vs just gaining access to their snowflake db.

This assumes they implemented things sanely with the db user for Braze having limited access rights…

potatoproduct 1 hour ago | parent

Yep, my first thought is they probably are probably getting the candidate push notifications from snowflake.

domaaju 1 hour ago | parent

I received the push notification via the app this morning as well. Extremely bizarre and not how normally one finds out about a company getting hacked.

jagged-chisel 1 hour ago | parent

You probably found out before they did

vachina 47 minutes ago | parent

Why do you have an app installed just to buy clothes

m4tthumphrey 42 minutes ago | parent

Because I buy a lot of clothes and the ASOS app is well built and its slightly easier to use than the site.

domaaju 7 minutes ago | parent

As the person above. I enjoy clothes browsing and shopping, and the app provides a very good experience, plus you normally tend to get app-only discounts. From a retailer perspective, (if the app is good) they get better retention and order value numbers from app customers.

andruschakartem 1 hour ago | parent

The ransom note was addressed to their DPO, customers just got CC'd via push.

glownagger 1 hour ago | parent

Five popups. Five. To read this article that doesn't even tell me what ASOS is.

m4tthumphrey 1 hour ago | parent

For others its a huge online fashion retailer in the UK (and maybe elsewhere?).

theoreticalmal 1 hour ago | parent

Maybe the hackers were trying to do us a favor?

ameliaquining 1 hour ago | parent

Second paragraph mentions that it's a "clothing and beauty store".

Zhyl 55 minutes ago | parent

It's a BBC article for a British retailer. I reckon the knowledge was reasonably assumed for the intended audience.

ifwinterco 33 minutes ago | parent

It’s extremely well known in the UK which is the intended audience, although even here older readers might not have heard of it

m4tthumphrey 1 hour ago | parent

Stock down 13% today. Interestingly ASOS has been steadily growing this year, would be interested to see Polymarkets today...

hnacobsxph 1 hour ago | parent

Braze API keys end up in a dozen CI configs and nobody rotates them. Campaign send is one POST.

iamacyborg 50 minutes ago | parent

I am genuinely impressed at the lack of tech literacy in the live feed about this from the beeb.

eameam 45 minutes ago | parent

Seems more likely to me that the braze api key was exposed

NoHedgeAllBets 38 minutes ago | parent

Thanks to this hack I now know what ASOS is.

cube00 36 minutes ago | parent

> Asos did not immediately respond to the BBC's requests for comment.

Amazing how companies think if they say nothing it'll somehow just go away. Couldn't even be bothered to reply to say they're looking into it.

mcintyre1994 13 minutes ago | parent

I wonder how little time "immediate" means though. They probably have an overwhelming amount of incoming - from journalists, security service providers, and opportunist scammers posing as both of those groups among other things.

cube00 10 minutes ago | parent

Considering they haven't put any statement on their own site [1] after they know the story is running on mainstream media I'm inclined to be less charitable.

[1]: https://www.asosplc.com/news-and-media/latest-news/

Aurornis 9 minutes ago | parent

Notice the word “immediately” in that statement.

The journalists were in a rush to publish breaking news. They weren’t going to wait for a response.

This is just a CYA statement to say that they sent a message to the company to do their job but, quite literally, did not immediately get a response.

hnlmorg 9 minutes ago | parent

Usually the lack of response is because an official response hasn’t yet been approved by the legal department, and then signed off by the board. These things take longer than modern journalism takes to publish an article.