hn.today

Some Supabase customers are publicly exposing reams of people's data to the web

techcrunch.com13 points0 comments

Security researchers at UpGuard found roughly 16,000 Supabase-hosted databases that were publicly accessible and contained personal information, exposing names, addresses, phone numbers and a smaller number of passwords and authentication tokens. The exposed datasets span sensitive and specific use cases: private conversations on an Indian adult streaming site, thousands of license plates from a U.S. valet service, contact records for an immigration and relocation business, a database linked to an African government consulate in France, and a virtual SIM farm used to intercept one-time passcodes for scams. While many exposed instances are hosted in the United States, the problem is global and echoes prior discoveries of misconfigured storage and databases tied to popular startups and apps.

The findings attribute the scale of exposure to simple misconfigurations and insecure defaults in quickly built “vibe-coded” or AI-generated apps, where developers can unknowingly ship insecure code or omit required protections. Supabase, now a large platform with a multibillion-dollar valuation, emphasizes that projects are “secure by default,” frames security as a shared responsibility, and says it provides tooling and notifications for affected customers while continuing to harden the platform. Researchers argue the work highlights a growing risk that rapid, AI-assisted development is fueling a new wave of data leaks unless developers and platforms harden configuration and access controls.

Read on techcrunch.com0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.