Researchers say about 16,000 databases on Supabase, a hub for quickly built AI apps, exposed personal data. Think before you sign up.

Here's one for anybody who signs up for every shiny new app. Security firm UpGuard told TechCrunch it found around 16,000 databases hosted on Supabase, a platform where web and app developers store and run their databases, exposing some degree of personal data to the public web. Supabase reached a $10 billion valuation earlier this year thanks to a rise in developers hosting vibe-coded apps there, the kind built quickly with AI tools. TechCrunch notes that AI-generated code can contain security flaws, or an app may need specific configuration its developer doesn't know about. UpGuard found publicly accessible names, addresses, phone numbers and user passwords. The exposed data included thousands of license plates from a U.S. valet service, contact information for people who used an immigration and relocation service, and a database belonging to an African government's consulate in France. The majority of the exposed data sets appear to be in the United States. Supabase's chief information security officer, Bil Harmer, said the company hadn't seen the research and that its projects are "secure by default." "We provide secure defaults and tooling, and customers control how their own projects are configured," he said, adding that the company notifies affected customers when it finds security issues. TechCrunch notes the company has faced criticism for how it handles user security. My take: think of a self-storage lot with good locks where some renters leave the roll-up door open. The landlord says the locks work; critics say the landlord should make it harder to leave doors open. Either way, you're the one whose stuff is inside. Before you hand a new app your address or phone number, ask who built it, and use a unique password so one leak doesn't open every door you own.
Read the original article ↗JOIN THE PORCH SQUARE
Pull up a chair. Be the first to sound off.