A developer-level explanation would be helpful here.
Was the mistake in the default Firebase configuration settings, or were common poor choices made by each of the app developers independently?
Was the mistake in the default Firebase configuration settings, or were common poor choices made by each of the app developers independently?
It's the most irresponsible default I have seen in practice.
Let's not forget that there is a security/permissions testing feature built right into Firebase. It would literally take 1 minute for a dev to ask and test: hey, can people read each other's data?
That's not what "safer" means. You cannot say that that's what would happen, either.