Skip to content

Around 16,000 Databases with Personal Data Exposed on the Open Internet: The Platform Favored by AI Apps Says Projects Are "Secure by Default"

1 min read
Share
Around 16,000 Databases with Personal Data Exposed on the Open Internet: The Platform Favored by AI Apps Says Projects Are "Secure by Default"

Around 16,000 databases hosted on the Supabase platform were showing people's personal data to anyone on the internet. That's the finding of new research by cybersecurity firm UpGuard. Names, addresses, phone numbers, and in a smaller number of cases passwords and authentication tokens - available to anyone who knew where to look.

Supabase lets website and app developers store and manage their databases. This year it reached a valuation of 10 billion dollars (about 8.8 billion euros), largely thanks to the boom in so-called "vibe coding" - apps written by artificial intelligence instead of a programmer, based on a person's description. The problem is that generated code often has security holes, or the app needs specific settings its author has no clue about. You click "publish," and the database door stays open.

The examples in the research read like a catalog of everything that must never leak. Private conversations with sex workers on an Indian adult streaming platform. Thousands of license plates from an American parking service. Contacts of people who used an immigration and relocation service. One of the databases belonged to an African government's consulate in France. Another was used by a virtual SIM farm to intercept one-time verification codes for online accounts, something typically used for scams and phishing attacks.

Most of the exposed databases are in the US, but UpGuard stresses the problem is global. The research builds on earlier findings of open Supabase databases, including databases belonging to Y Combinator startups. The history of such leaks is long: misconfigured servers and databases have already led to leaks of military emails, visa applications, classified government documents, hundreds of thousands of scanned driver's licenses and children's personal data. What's new is the wave - with AI, building an app is easy and fast, but security know-how doesn't come in the package.

Supabase's response is a classic. Chief information security officer Bill Harmer says the company hasn't seen the research, but that its projects are "secure by default." He describes security as a shared responsibility: "We provide secure defaults and tools, and customers control how their projects are configured." The company notifies affected customers when it discovers a problem, and "security at Supabase is never finished," Harmer adds. Translation: we sell the door locked, and if you leave it open, that's your problem. Except that the people whose addresses and conversations are hanging on the internet aren't Supabase customers. They just used somebody's app.

How many of the apps we use every day are put together the same way - and has anyone even checked where our data ends up?