5 ms·
imho, as much as i like firebase, i think the design encourages this kind of broken security model. the default is open-to-the-world with credentials in the cli
by igor47 1y ago
imho, as much as i like firebase, i think the design encourages this kind of broken security model. the default is open-to-the-world with credentials in the client app. setting up firebase permissions is kind of a pain.
in the traditional db world, at least your db creds live on the server-side app.
- frollogaston 1y agoFirebase's DB (Firestore) being almost default-allow is even funnier, and that was the core functionality from the start, leading to tons of huge breaches over the years. At least a public file bucket is a more valid use case, except I'm guessing they left the "list files" permission open. Edit: Oh, chat DB is probably Firestore, so they left that open too, nice. Having used it several times, yeah I wouldn't entrust it to a dev team. It's gotten better lately but still seems like the gun is always pointed at your foot. Also GCP, storing secrets properly in AppEngine is notoriously difficult and prone to accidental git-commit: https://stackoverflow.com/questions/58371905/how-to-handle-secrets-in-google-app-engine https://stackoverflow.com/questions/58371905/how-to-handle-s...
- andrepd 1y agoIt's to this kind of quality engineering that they want me to entrust my ID so I can watch pr0n or insult a politician online. Jesus.
- frollogaston 1y agoAre they specifically using Firebase for that? I'm not saying GCP is unsafe in general, just Firebase.
- darth_avocado 1y agoI wonder why I learnt “deny by default is a good starting point” in an undergraduate computer science course decades ago.
- moomoo11 1y agobro going to university is so overrated, just start vibe coding xD /s btw
- sudoshred 1y agoMy naive understanding is that is the same approach taught in introductory law school.
- xorcist 1y agoThe ones that did lost in the marketplace against the competitor which was more plug-and-play. True story.
- moomoo11 1y agoI'm a fan of rolling actual databases, but please don't blame Firebase. The is completely the fault of the people who made that app. They have no fucking idea how to build systems if they can't figure out how to lock down Firebase. It isn't that hard. Source: Multiple Firebase apps back in the day.
- tbrownaw 1y agoNo, hazardous defaults can be a source of fault for the entity providing them.
- moomoo11 1y agoOk but it’s not like pg can’t stop you from doing something dumb. There are probably countless new projects today that are storing plaintext passwords, or not adding scoping, and so on. Putting in scopes and ensuring data security for both users and system wide is on the developer.
- frollogaston 1y agoIt's hard to screw up Postgres to the extent that your entire DB is made fully accessible by all users. This has happened many times with Firebase apps, for over a decade. You could have a SQL injection vuln, but any SQL lib will very clearly steer you to parameterized queries, and even then such a vuln takes some expertise to find and exploit.
- moomoo11 1y agoThat’s simply not true. I remember working with a startup founder who had Jerry rigged some crap shit together with gpt a year ago. I was able to access his data by simply accessing it figuring out his URL and other stuff. I told him to use supabase or DO deployment and set up proper roles and stuff… I think you’re being way too charitable honestly and it’s dangerous. I won’t join you on that path of absolving the developer of any blame. They don’t read the docs and they didn’t care simply put. Any production system needs to be tested especially if it will have PII data.