6 ms·
The Stanford Daily article says “At the time, Fizz used Google’s Firestore database product to store data including user information and posts...Fizz did not ha
by icameron 3y ago
The Stanford Daily article says “At the time, Fizz used Google’s Firestore database product to store data including user information and posts...Fizz did not have the necessary security rules set up, making it possible for anyone to query the database directly...phone numbers and/or email addresses for all users were fully accessible, and that posts and upvotes were directly linkable to this identifiable information....Moreover, the database was entirely editable — it was possible for anyone to edit posts, karma values, moderator status, and so on."
That's wild!
- iancarroll 3y agoThis is unfortunately a very common issue with Firebase apps. Since the client is writing directly to the database, usually authorization is forgotten and the client is trusted to only write to their own objects. A long time ago I was able to get admin access to an electric scooter company by updating my Firebase user to have isAdmin set to true, and then I accidentally deleted the scooter I was renting from Firebase. I am not sure what happened to it after that.
- yismail 3y agoIf I recall correctly, you can set your firebase rules such that a user can only read/write/delete certain collections based on conditions such as if user.email == collection.email.
- justrealist 3y agoDoing authorization within firestore breaks down instantly outside of toy applications.
- jacquesm 3y agoI think deleting a scooter is against some law of conservation :)
- singleshot_ 3y agoOne interesting thing about the statute of limitations is “the discovery rule.” For example, say the statute of limitations for 18 USC 1030 is two years. If a person hypothetically stole a scooter by hacking, two years later, they would be in the clear, right? No. The discovery rule says that if a damaged party, for good reason, does not immediately discover their loss, the statutes of limitations is paused until they do. Accordingly, if the scooter company read a post today about a hack that happened “a long time ago” and therein discovered their loss, the statute of limitations would begin to tick today and the hacker could be in legal jeopardy for two more years.
- henriquez 3y agoDoes this apply to criminal or just civil?
- btilly 3y agoGenerally it applies to both. But some crimes (eg murder) might not have a statute of limitations. https://www.law.cornell.edu/wex/statute_of_limitations https://www.law.cornell.edu/wex/statute_of_limitations Also there are subtle questions around what discovery means here. Usually it is some sort of "could be discovered with reasonable effort". If I had proof of your wrongdoing in a letter sent to me, I am unlikely to get away with saying, "Oh, I didn't read the letter when I got it." If that proof was buried in a computer file with a million pages, I probably can reasonably say, "That was a needle in a haystack, and I didn't even know what to look for." For situations between those extremes, there will be case law that likely varies by state. This is where a lawyer gets to earn their pay.
- singleshot_ 3y agoHuge arrow pointing to “varies by state” on all of this. 1030 (which is, of course, federal law) actually has a specific discovery/statute of limitations in the text of the statute, and so may not be affected by state discovery rule law.
- iancarroll 3y ago
- dudus 3y agoIt is common. But before you curse at Google here. This is VERY well documented. When you create a database the UI screams at you that it's in dev mode, that security has not been setup etc.... if you keep ignoring the database will eventually close itself down automatically. So this is entirely on the dev team to blame.
- manicennui 3y agoWhich is why I hate that people keep claiming that you don't need to know what you are doing nor employ anyone who knows what they are doing to setup infrastructure. You might be able to stand things up without knowing what you are doing, but you probably shouldn't be running it in production that way.
- gregsadetsky 3y agoSpeaking of, are there tools to audit/explore firebase/firestore databases i.e. see if collections/documents are readable? I imagine a web tool that could take the app id and other api values (that are publicly embedded in frontend apps), optionally support a session id (for those firestore apps that use a lightweight “only visible to logged in users” security rule) and accept names of collections (found in the js code) to explore?
- saligrama 3y agoBaserunner [1] does exactly this. I described using it for Firebase security research in my blog post [2]. [1] https://github.com/iosiro/baserunner https://github.com/iosiro/baserunner [2] https://saligrama.io/blog/post/firebase-insecure-by-default/ https://saligrama.io/blog/post/firebase-insecure-by-default/
- morpheuskafka 3y agoA few years ago I found that HelloTalk (a language learning pen-pal app) stored the actual GPS coordinates of users in a SQLite that you can find in your iOS backup. The maps in-app showed only a general location (pin disappeared at a certain zoom). You could also bypass the filter preventing searching for over 18 if you are under/under if you are over, and paid-only filters like location, gender, etc. by rewriting the requests with a mitmproxy (paid status is not checked server-side).