this post was submitted on 21 Mar 2024
65 points (93.3% liked)

Privacy

31876 readers
579 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
65
Firebase leaks datas (www.securityweek.com)
submitted 7 months ago* (last edited 7 months ago) by [email protected] to c/[email protected]
 

Hundreds of websites misconfigured Google Firebase, leaking more than 125 million user records, including plaintext passwords, security researchers warn.

Once again do not use google based apps, degoogled yourself, and don't trust big companies, have a (de)goo(gle)d day!

top 6 comments
sorted by: hot top controversial new old
[–] [email protected] 11 points 7 months ago* (last edited 7 months ago)

*have a degoogled day

Edit: love the edit!

[–] [email protected] 9 points 7 months ago* (last edited 7 months ago) (2 children)

The issue here isn't so much Google. Just people being stupid and not taking the time to learn how to secure something

[–] [email protected] 5 points 7 months ago

Seriously if you’re using Firebase already how the hell do you mess up auth? Firebase offers a free auth solution that’s pretty much a prerequisite to using any of the other services.

[–] [email protected] 2 points 7 months ago

The issue here isn't so much Google. Just people being stupid and not taking the time to learn how to secure something

I'd argue there's poor design that could be patched here. From an article detailing the vulnerability (https://mrbruh.com/chattr/):

My hunch was that in the rush to push their new shiny product, someone would take a shortcut and forget to implement proper security rules.

The hunch was right, and it was worse than I could’ve ever guessed.

then later:

if you use Firebase’s registration feature to create a new user (you cannot register on their site), you get full privileges (read/write) to the Firebase DB.

That it's somehow faster or easier to (mis)configure a system such that you have full read/write is poor design. Secure by default, principles of least privilege; stuff that you want the implementers of the system to stick to so that when you're a user (restaurants), you don't need to think about this sort of thing.

Of course the restaurants are also at fault for putting people's personal info into yet another charlatan AI SaaS.

[–] [email protected] 4 points 7 months ago (1 children)

So the "hack" was to just go an create a new admin account? Damn what have we come to

[–] [email protected] 1 points 7 months ago