3 ms·
[Firebase Founder] Hi Robin, You’re right, some folks don’t fully setup their security rules. We remind our developers to do this, but can -- and clearly need
by jamest 13y ago
[Firebase Founder] Hi Robin,
You’re right, some folks don’t fully setup their security rules. We remind our developers to do this, but can -- and clearly need -- to do more. Your suggestion about requiring security rules is a good one. We’ll be going through our customers and providing more personalized feedback on their security rules in the coming days. Also, we are working on additional tutorials and examples to teach our devs how to use our security rules in an interactive way.
Thanks for pointing out some of the areas we can improve our examples. They’re intended to illustrate design patterns, not be robust production apps. Again, we can do better here, and the code we use as an example should be bullet proof.
Like any application, Firebase-powered apps are only as secure as the developers make them. If you do not control access with security rules, your app could be vulnerable. XSS attacks can affect Firebase apps like any other application.
Finally, we would have really liked you to provide responsible disclosure on the specific Firebases you found issue with and given us enough time to speak with those customers before taking this public.
We’ll reach out to you via email now.
- patio11 13y agoSo good news and bad news, bad news first: There doesn't appear to be a Firebase security contact page where you spell out how to get in touch with you if a researcher discovers something like this. Industry standard practice is, for better or worse, if you do not have that page then any available textarea is an acceptable method for communication with you about security vulnerabilities in your software. The good news: you can trivially address this by adding one page in your CMS, calling it "Security", writing a few sentences of copy, and adding a) an email address which is monitored, b) a promise to write back, and c) (optional) a PGP key. Some good examples: http://www.twilio.com/docs/security/disclosure http://www.twilio.com/docs/security/disclosure http://37signals.com/security-response http://37signals.com/security-response http://technet.microsoft.com/en-us/security/ff852094.aspx http://technet.microsoft.com/en-us/security/ff852094.aspx P.S. This advice is broadly applicable to everyone here who owns or helps to manage a software company.
- jamest 13y agoThanks Patrick. Point well taken. I'll add one now.
- greenido 13y agoHey Jamest, I hear you about "...Firebase-powered apps are only as secure as the developers make them..." but I guess, you should try to do your best in order to 'tunnel' developers into the best practices of validating input/output and not relying on the client to send 'safe' data. I know it's easy to say and hard to do :) Nevertheless, it's a great goal to have. Good luck! Ido
- jamest 13y agoThanks Ido, I absolutely agree we should guide developers towards best practices. We'll be aiming to do this with future tutorials on security.