Some Supabase customers are publicly exposing reams of people’s data to the web
First reported by TechCrunch ·
Your personal data, including passwords, could be exposed if you've used apps built on Supabase. The risk escalates as AI-assisted development often introduces misconfigurations that expose sensitive information.
Cybersecurity firm UpGuard has discovered that approximately 16,000 databases hosted on the development platform Supabase are publicly exposing sensitive user data. This data includes names, addresses, phone numbers, and in some cases, passwords and authentication tokens. The exposed information is linked to a variety of projects, ranging from private conversations and valet service license plates to contact details for immigration services and even interception of text messages for authentication purposes. Supabase, which recently achieved a $10 billion valuation, allows developers to store and run their databases, and has faced prior criticism regarding user security. The company states its projects are "secure by default" and emphasizes that security is a shared responsibility with its customers, noting they notify affected users of discovered issues.
The widespread data exposure on Supabase highlights a growing trend where the rapid adoption of AI tools for app development outpaces robust security practices. Developers, potentially less experienced or rushed, may inadvertently create vulnerabilities by misconfiguring database settings, leading to significant data leaks. This situation underscores the critical need for enhanced automated security checks and developer education within platforms that aim to democratize app creation.
This incident poses a considerable risk to users of applications hosted on Supabase, potentially impacting trust and increasing susceptibility to identity theft and phishing attacks. For Supabase, it represents a significant challenge to its reputation and valuation, necessitating a re-evaluation of its security defaults and customer support for configuration best practices. The ongoing debate over developer responsibility versus platform security is intensified, with calls for more proactive measures from platform providers to prevent such widespread exposures.
AI-written summary. May contain errors.