One way or another it usually end up being stored in a completely unsecured manner.
This is even more outrageous knowing how secure Firebase actually is. The documentation even contains a "Securing your Data Model" section .
One way or another it usually end up being stored in a completely unsecured manner.
This is even more outrageous knowing how secure Firebase actually is. The documentation even contains a "Securing your Data Model" section .
> 2.6 million plaintext passwords
Anyone who is actually competent knows hashing at a minimum; and it costs nothing to implement, both time and money wise.
All of this, because Johnny over here read a tutorial on how to make your own app.
The downside of development is that, you do get these people who 'stain' the title, because they just read it and followed blindly instead of actually learning.
And the difficulty of setting up firebase's auth may also have changed over time. Did they always have hosted user/password auth or did they rely on third party pre-google?
I have had to figure it out myself. It isn't hard, just took some extra effort to look into.
A few weeks ago I found out a newer hire (at senior level) decided to build his own auth system, because the current one, "doesnt work". It doesn't work because it doesn't allow our employees to handle customer passwords. Even with high turnover, some people don't understand why that is essential.
When simplicity fights security in a corporate setting, simplicity nearly always wins. The exception is when an executive is security savvy and isn't a push over to their peers.