Firebase Database default settings make the entire database world-readable and world-writable by all "authenticated users". But once you have enabled authentication, then that means anyone who signs into your app with a Google account. Restricting users to only access their own data requires understanding and writing "security rules".
It's the most irresponsible default I have seen in practice.