I love Firebase but these kind of security holes make me hesitant to use it for anything serious. Is it even possible to prevent without adding an extra server layer?
well, you are exposing the database at the javascript level. If it is javascript then you can mess with it in your browser via the developer console. So if you are using firebase via javascript your application is fundamentally insecure. You cannot even put serverside sanity checks like "this person should not ask for this value" or "nobody should have a string for a score" because of firebase's limitations.
Aha! My only use of firebase was writing a chat application for fun back at their launch marketing push. This is good to see, and I think I might go play with it more.
I still don't see how setting security rules would prevent cheating. I would love to know how to fix this issue as I'm making a similar MMO game with Firebase.
You have obviously never tried Firebase.
So how would you prevent people from just setting whatever score they want in this game?