zlacker

[return to "11% of vibe-coded apps are leaking Supabase keys"]
1. quesom+9p2[view] [source] 2026-01-18 19:57:31
>>xyborg+(OP)
Finally somebody built this, the problem is that the people who don't know won't think of using this tool.

A friend recently came across a project with no RLS and described it as "a once in a lifetime fuckup, a career defining moment, you could shitcan them but they wont learn how to fix it, either way they need adult oversight".

And once you find some dumb low-hanging fruit like that, you usually discover that the vibe-coded ignorance is fractal, especially with TypeScript projects where people assume that you define something in an interface with a given type that the user will always supply that - and your user will always be the app you wrote - and duck-typing doesn't exist.

Maybe worth scanning the various Android app stores? It's incredibly depressing.

◧◩
2. xyborg+YS2[view] [source] 2026-01-18 23:46:16
>>quesom+9p2
Yes, sometimes is hard, and also kinda frustrating when they don't seem to care about their users' data privacy.

For Android/iOS, I know those are even worse, but it's tricky to get the data, might be easier to get and decompile the APKs though.

◧◩◪
3. xyborg+jye[view] [source] 2026-01-22 12:12:40
>>xyborg+YS2
I have been playing around iOS apps now, I found many with exposed Firebase instances as well :/
[go to top]