zlacker

[parent] [thread] 2 comments
1. quesom+(OP)[view] [source] 2026-01-18 19:57:31
Finally somebody built this, the problem is that the people who don't know won't think of using this tool.

A friend recently came across a project with no RLS and described it as "a once in a lifetime fuckup, a career defining moment, you could shitcan them but they wont learn how to fix it, either way they need adult oversight".

And once you find some dumb low-hanging fruit like that, you usually discover that the vibe-coded ignorance is fractal, especially with TypeScript projects where people assume that you define something in an interface with a given type that the user will always supply that - and your user will always be the app you wrote - and duck-typing doesn't exist.

Maybe worth scanning the various Android app stores? It's incredibly depressing.

replies(1): >>xyborg+Pt
2. xyborg+Pt[view] [source] 2026-01-18 23:46:16
>>quesom+(OP)
Yes, sometimes is hard, and also kinda frustrating when they don't seem to care about their users' data privacy.

For Android/iOS, I know those are even worse, but it's tricky to get the data, might be easier to get and decompile the APKs though.

replies(1): >>xyborg+a9c
◧◩
3. xyborg+a9c[view] [source] [discussion] 2026-01-22 12:12:40
>>xyborg+Pt
I have been playing around iOS apps now, I found many with exposed Firebase instances as well :/
[go to top]