Some Supabase customers are publicly exposing reams of people’s data to the web
Some Supabase customers are publicly exposing reams of people’s data to the web
部分 Supabase 客户正将海量用户数据暴露在公共网络上
Thousands of databases hosted by development platform Supabase are exposing people’s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found. 网络安全公司 UpGuard 的最新研究发现,开发平台 Supabase 托管的数千个数据库正将人们的敏感信息暴露在公共网络上。
UpGuard told TechCrunch that it found around 16,000 databases on which some degree of personal data was exposed while they were hosted by Supabase, which allows web and app developers to store and run their databases. UpGuard 向 TechCrunch 表示,他们发现约有 16,000 个托管在 Supabase 上的数据库存在不同程度的个人数据泄露。Supabase 允许网页和应用开发者存储并运行其数据库。
Supabase earlier this year reached a $10 billion valuation, thanks to a rise in developers hosting their vibe-coded apps on the platform. But the company has faced criticism for how it handles user security. There are widely documented cases of users misconfiguring or unknowingly exposing their databases to the broader internet, in some instances to the tune of millions of records each. 得益于开发者们纷纷在平台上托管其“氛围编程”(vibe-coded)应用,Supabase 今年早些时候估值达到了 100 亿美元。但该公司在处理用户安全方面一直饱受批评。有大量记录在案的案例显示,用户因配置错误或在不知情的情况下将数据库暴露在互联网上,某些案例中单次泄露的记录就高达数百万条。
The findings highlight how vibe-coded apps and websites can spill or expose sensitive data through basic misconfigurations and improper security. While AI tools can be used to easily build websites and apps, the generated code can often contain security flaws, or apps might require specific configuration that the developer may be ignorant of. 这些发现凸显了“氛围编程”应用和网站如何因基础配置错误和安全措施不当而导致敏感数据泄露。虽然人工智能工具可以轻松构建网站和应用,但生成的代码往往包含安全漏洞,或者应用可能需要开发者并不了解的特定配置。
Over the years, countless data breaches have been linked to improperly configured storage servers, databases and websites. Such cases have resulted in the leaks of sensitive military emails, immigration and visa applications, classified government files, hundreds of thousands of driver’s license scans, and children’s personal information. 多年来,无数的数据泄露事件都与配置不当的存储服务器、数据库和网站有关。此类事件已导致敏感军事邮件、移民和签证申请、政府机密文件、数十万份驾照扫描件以及儿童个人信息的泄露。
Now, the boom in AI vibe-coding is helping fuel a new wave of data breaches, many of which are now being linked to Supabase as people increasingly use it for storing their data. 如今,人工智能“氛围编程”的兴起正助推新一轮数据泄露浪潮,随着人们越来越多地使用 Supabase 存储数据,许多泄露事件现在都与该平台有关。
UpGuard says it sought to understand the scale of exposed data across the platform, and found publicly accessible names, addresses, phone numbers, and user passwords. The research surfaced a fewer number of passwords and authentication tokens. UpGuard 表示,他们试图了解该平台数据泄露的规模,并发现了可公开访问的姓名、地址、电话号码和用户密码。研究还发现了一定数量的密码和身份验证令牌。
The firm said the databases contained data linked to various projects, such as private conversations with sex workers on an Indian adult streaming site; thousands of license plates of a U.S. valet service; and the contact information of people who used an immigration and relocation service. 该公司称,这些数据库包含与各种项目相关的数据,例如印度成人流媒体网站上与性工作者的私人对话;美国代客泊车服务的数千个车牌号;以及使用移民和搬迁服务的人员的联系信息。
One of the databases belonged to an African government’s consulate in France, said UpGuard, while another was used to intercept text messages by a virtual SIM farm for sending one-time passcodes to verify online accounts, typically for launching scams and phishing attacks. UpGuard 表示,其中一个数据库属于某非洲国家驻法国领事馆,而另一个数据库则被一个虚拟 SIM 卡农场用于拦截短信,以发送用于验证在线账户的一次性密码,这些通常用于发起诈骗和网络钓鱼攻击。
While the majority of these exposed datasets appear to be located in the United States, UpGuard said this is a worldwide problem. The findings build on earlier research that also found a range of exposed databases hosted on Supabase, including those by Y Combinator startups and other popular apps. 虽然这些泄露的数据集大部分似乎位于美国,但 UpGuard 表示这是一个全球性问题。这些发现建立在早期的研究基础之上,该研究也曾发现 Supabase 托管的一系列暴露数据库,其中包括来自 Y Combinator 初创公司和其他热门应用的数据。
Supabase has made changes to its platform over the years, including bolstering its platform and user access to databases. When reached for comment, Supabase’s Chief Information Security Officer Bil Harmer said that while the company has not seen the research, its projects are “secure by default.” 多年来,Supabase 对其平台进行了改进,包括加强平台和用户对数据库的访问控制。在接受采访时,Supabase 的首席信息安全官 Bil Harmer 表示,虽然公司尚未看到该研究报告,但其项目是“默认安全”的。
He described security as a shared responsibility between the company and its customers. “We provide secure defaults and tooling, and customers control how their own projects are configured,” and the company notifies affected customers when security issues are discovered, he said. 他将安全描述为公司与客户共同承担的责任。他说:“我们提供安全的默认设置和工具,而客户负责控制其项目的配置方式。”当发现安全问题时,公司会通知受影响的客户。
“Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely,” said Harmer. Harmer 表示:“Supabase 的安全工作永无止境。我们非常重视并致力于做好这一点,我们将继续让每一位开发者都能更轻松地进行安全交付。”
UpGuard security researcher Greg Pollock said the company’s research was important for raising awareness about the issue of data exposures. UpGuard 安全研究员 Greg Pollock 表示,该公司的研究对于提高人们对数据泄露问题的认识非常重要。