IMO, calling the vulnerability the "Firebase vulnerability" makes it seem like it's a problem on Firebase's side. But is it really their problem? At what point do we start blaming the developers instead of the service?
IMO, calling the vulnerability the "Firebase vulnerability" makes it seem like it's a problem on Firebase's side. But is it really their problem? At what point do we start blaming the developers instead of the service?
And the security system is super simple to implement. If the built in language is too hard, a simplified templating language is also provided.
The plaintext password thing just confuses me. One of Firebase's big draws is integration with their auth system. Why in the world is anyone storing passwords in Firebase? Unencrypted?
New Firebase instances starts off locked down by default, not allowing global reads or writes.
I suspect (hope?) most of the apps still using it insecurely came from before the acquisition by Google.
How is it true that apps using Firebase “rarely” secure it properly, if only 10% of apps using Firebase are vulnerable?
A lot of mobile apps are very poorly written.
In a way I blame this on Apple/Google for making their platforms convoluted enough that people have to spend years learning how to develop Android and iOS but not have a proper understanding of the web services powering APIs.
Eventually you just get caught up in this constant flurry of learning more without actually learning anything
It’s either that or the developer simply doesn’t understand the abstraction of Firebase. You can easily check if the rules work by loading up your browser console and trying to access different branches of data with varying credentials.
If your software can be configured in an insecure manner, that's what people will do.
There are so many developers out there that every possible mistake will be made. The easier the mistake is to make, the more common it will be. If the mistake requires the developer to perform an action to avoid it, it will be ubiquitous.
In 2018, security can no longer be an afterthought. Your product must be secure out of the box. Insecure configurations must be hard or impossible to set up.
You can't offer an insecure "development mode", because that is what people will use in production.
(PS: Of course it is also the developers fault. But that is no excuse for the vendor. There are lots of incompetent developers out there. Confused developers are not an exception. Your product must be secure even if people don't read the documentation)