3,340 karma · joined October 3, 2010
- Helped start + Board @ CharmIndustrial.com
- Co-Founder @ Kradle.ai
Past: - Co-Founder/CEO at Firebase (YC S11)
- Co-Founder @ CovidActNow.org
- Partner @ HF0
- Built the product team @ ChainlinkWe'll be aiming to do this with future tutorials on security.
I'll add one now.
You’re right, some folks don’t fully setup their security rules. We remind our developers to do this, but can -- and clearly need -- to do more. Your suggestion about requiring security rules is a good one. We’ll be going through our customers and providing more personalized feedback on their security rules in the coming days. Also, we are working on additional tutorials and examples to teach our devs how to use our security rules in an interactive way.
Thanks for pointing out some of the areas we can improve our examples. They’re intended to illustrate design patterns, not be robust production apps. Again, we can do better here, and the code we use as an example should be bullet proof.
Like any application, Firebase-powered apps are only as secure as the developers make them. If you do not control access with security rules, your app could be vulnerable. XSS attacks can affect Firebase apps like any other application.
Finally, we would have really liked you to provide responsible disclosure on the specific Firebases you found issue with and given us enough time to speak with those customers before taking this public.
We’ll reach out to you via email now.
To answer your questions:
1. We put our code in escrow for very large customers. We are thinking about the best way to address the concerns of everyone else. Stay tuned.
2. This is coming. It'll be a little while.
Thanks again for your comments. Criticism helps us figure out where we need to improve.
If you're worried about lock-in, I'd first try Firebase along with our AngularJS[1] or Backbone[2] bindings. You don't have to change the way you write your app and can switch Firebase our for another backend easily. We recognize that we're only going to win a developer's trust by building a reliable service with the best tools and fair pricing -- so this is what we're going to do
I'd love to dispel any concerns, please feel free to email me anytime (james at firebase)
The quality was great too, you can easily get multiple iterations and give feedback easily.
Sorry for any confusion. I'll add some explicit language in the README on GitHub.
Thanks for checking out the code.
Regarding pricing, you can find it here: https://www.firebase.com/pricing.html
Pricing is difficult and we're trying to get it right. Your feedback would be great.
If you're successful you'll be working for far longer than that. Even if you're not successful good teams will continue to iterate or change ideas, which will often take far longer than 24 months.
Saurik - We're glad that there are people like you searching for holes in services like Firebase. Hopefully it'll keep making all of us better. Please keep doing it.
As ivolo noted, we do have a security feature set we're testing. It has taken a little while to build something that is both functional and usable. We're pretty confident we've got something that our users will love.
Excited to show you soon!
We're definitely working on security full speed. We have some basic security but it's not ready yet. If you'd like to beta test it, please email us: beta@firebase.com
You can check out our FAQ for more info: http://www.firebase.com/faq.html
We both think that application development is going to radically change in the future and we're both building products that promote a new way of developing apps. We're stoked about Meteor and see our products as very complementary.
We know the Meteor guys well and are really excited about what they're building. It's very complementary.
We're both advocating a new paradigm in software development and the faster it comes the better.
It was always intended to be a marketing gimmick. The critical mass required to sustain good conversation only lasted for the time the story was on the front page.
Getting a website owner to install a chat system, (rather than just having an overlay) combined with integrating with site credentials will make an on-site chat system significantly more viable.
I like the Rotten Tomatoes integration. Nice work.
Love the idea and congrats on knocking it out in a weekend.
- Flood control is already baked in. 4 messages every 10 seconds is the limit.
- Pasting images gets ugly (eg porn). We'll think of a good way to do this soon.
- JS editor is a sweet idea!
- Personal ban list / spam reporting are on their way.
Thanks again.