i think you're missing the fact that that indeed is not a security email, and the engineering/security email i found bounced.
i had no ill intentions. stop pretending i did.
HN user
i think you're missing the fact that that indeed is not a security email, and the engineering/security email i found bounced.
i had no ill intentions. stop pretending i did.
It is for the sites, not Firebase.
Sadly, most developers don't know this and continue to write from frontend, almost all of the apps and websites we found did this.
I agree for the most, but there was some good apples (even though very few) that were very thankful and fixed it fast.
True, but also better than threat actors getting to it and dumping the DB, causing more problems for the customers.
What'd you expect, its google!
I agree! Supabase does it pretty good.
I agree, but I also disagree.
The concept with firebase DB's is flawed IMO, I never got the point of directly accessing a DB in the frontend, or allowing that even with security rules, it just seems like it would cause problems.
We believe the gambling ring is based in Indonesia, which is uncommon to use Line, but they seem to be using it here for all of their customer support across all sites.
I really doubt that this will be google's downfall, theyre too big to fall right now. I think it will be laws.
Yeah, funny how that works.
Services as time goes on makes making websites easier, and abstracts more stuff, which makes devs oblivious to what they have to configure.
Thank you! Means a lot, helps us keep going.
Must've used the twitch chat dataset
Python just isn't the language for this, really.
Rewriting it is the only real solution, I don't know your exact problem.
Setting up firebase security rules: https://firebase.google.com/docs/rules/
Would work! If you're willing to write something, go for it. I'm personally way too exhausted right now.
We confirmed that the gambling site is not fake data, I dont know about the lead one.
Why we are saying its more is there is likely other services not in our scan list that could be vulnerable.
Sadly, this is true, and theres probably much more. We did our best, sent customized emails to each of them, telling what was affected, how to fix it, and how to get in contact.
It would, except if you have a f'ed up schema like most of these companies had.
We decided to make a shared blog because we will likely have other projects we will do together, so all of us posting on our personal blogs on the same topic would be counterproductive
On certain databases, yes
We only scanned for firestore, which is a NoSQL database, conversion tools may still be possible, a good firebase alternative would be https://supabase.com, but please set up RLS, its IMO much easier then Firebase.
We tried to contact google, via support to try to help or for them to help disclose the issues to the websites. We got no response other then a response telling us that they will be creating a feature request on our behalf if we wanted instead of helping us, which is fair as I think we'd have to escalate pretty far up in Firebase to get the attention of someone who could alert project owners.