•Technology
Supabase Data Exposures Highlight Security Risks in AI-Powered App Development
View original sourceThe cybersecurity firm UpGuard has discovered that thousands of databases hosted by the platform Supabase, which recently achieved a valuation of $10 billion, are leaking sensitive information to the public. The firm identified around 16,000 databases with exposed personal data. This includes names, addresses, phone numbers, and passwords, all due to misconfigurations by users.
- Supabase is popular among developers due to its easy-to-use web and app storage solutions, but concerns over security have risen.
- The exposure of sensitive data is linked to the increasing use of AI tools in coding which, despite their efficiency, tend to introduce flaws and require specific configurations that developers might not be familiar with.
- The leaked information involves a variety of projects, including private conversations on an Indian adult streaming site and personal and governmental data.
- This issue is not isolated to the U.S.; it is a global problem, with some databases linked to international entities, such as an African consulate in France.
- Supabase claims its platform is secure by default, emphasizing the shared responsibility between the company and its users, and they actively notify customers of any security issues.
- Greg Pollock, an UpGuard researcher, stresses the importance of this research in raising awareness about data exposure vulnerabilities.