字号 ·· | 护眼
techcrunch

一些Supabase客户正在公开将大量用户数据暴露在网络上Some Supabase customers are publicly exposing reams of people’s data to the web

点「原文对照」整页切到原文,或双击某段只看那段的原文。

由开发平台 Supabase 托管的数千个数据库正将人们的敏感信息暴露在公共互联网上,网络安全公司 UpGuard 最新的一项安全研究发现。

Thousands of databases hosted by development platform Supabase are exposing people’s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found.

UpGuard 向 TechCrunch 表示,他们发现了约1.6万个数据库,这些数据库在 Supabase 托管期间不同程度地暴露了个人数据。Supabase 允许网页和应用开发者存储并运行数据库。

UpGuard told TechCrunch that it found around 16,000 databases on which some degree of personal data was exposed while they were hosted by Supabase, which allows web and app developers to store and run their databases.

Supabase 今年早些时候估值达到100亿美元,原因之一是越来越多开发者将在该平台上采用“氛围编程”方式开发的应用托管于此。但该公司在处理用户安全的方式上受到批评。已有大量公开记录的案例显示,用户错误配置数据库,或在不知情的情况下将数据库暴露在更广泛的互联网中;其中一些数据库暴露的记录数多达数百万条。

Supabase earlier this year reached a $10 billion valuation, thanks to a rise in developers hosting their vibe-coded apps on the platform. But the company has faced criticism for how it handles user security. There are widely documented cases of users misconfiguring or unknowingly exposing their databases to the broader internet, in some instances to the tune of millions of records each.

这些发现凸显出,采用“氛围编程”方式构建的应用和网站,可能因基本配置错误和不当的安全措施而泄露或暴露敏感数据。虽然人工智能工具可以轻松用于构建网站和应用,但生成的代码往往包含安全缺陷,或者应用可能需要特定配置,而开发者对此并不知情。

The findings highlight how vibe-coded apps and websites can spill or expose sensitive data through basic misconfigurations and improper security. While AI tools can be used to easily build websites and apps, the generated code can often contain security flaws, or apps might require specific configuration that the developer may be ignorant of.

多年来,无数数据泄露事件都与配置不当的存储服务器、数据库和网站有关。此类事件曾导致敏感军事邮件、移民和签证申请、机密政府文件、数十万份驾驶证扫描件以及儿童个人信息泄露。

Over the years, countless data breaches have been linked to improperly configured storage servers, databases and websites. Such cases have resulted in the leaks of sensitive military emails, immigration and visa applications, classified government files, hundreds of thousands of driver’s license scans and children’s personal information.

如今,人工智能“氛围编程”的兴起正助推新一波数据泄露。随着人们日益使用 Supabase 存储数据,其中许多泄露事件如今都被指向该平台。

Now, the boom in AI vibe-coding is helping fuel a new wave of data breaches, many of which are now being linked to Supabase as people increasingly use it for storing their data.

UpGuard 表示,希望了解整个平台 exposed 数据的规模,并发现姓名、地址、电话号码和用户密码均可在公开网络上访问。该研究还发现了数量较少的密码和身份验证令牌。

UpGuard says it sought to understand the scale of exposed data across the platform, and found publicly accessible names, addresses, phone numbers and user passwords. The research surfaced a fewer number of passwords and authentication tokens.

该公司表示,这些数据库中存储了与多个项目相关的数据,例如:一个印度成人直播网站上与性工作者的私人对话记录;美国某代客停车服务公司的数千个车牌信息;以及使用移民和搬迁服务人员的联系方式。UpGuard指出,其中一个数据库属于非洲政府在法国设立的领事馆;另一个数据库则被用于虚拟SIM卡服务提供商拦截短信,这些短信用于发送一次性验证码,以验证在线账户(这些验证码通常被用于发起诈骗或网络钓鱼攻击)。

The firm said the databases contained data linked to various projects, such as private conversations with sex workers on an Indian adult streaming site; thousands of license plates of a U.S. valet service; and the contact information of people who used an immigration and relocation service. One of the databases belonged to an African government’s consulate in France, said UpGuard, while another was used to intercept text messages by a virtual SIM farm for sending one-time passcodes to verify online accounts, typically for launching scams and phishing attacks.

虽然这些被泄露的数据集大多位于美国,但UpGuard认为这实际上是一个全球性的问题。此发现基于之前的研究结果——此前也有研究发现,Supabase平台上托管着大量被泄露的数据库,其中包括由Y Combinator孵化的项目以及其他流行应用程序的数据。

While the majority of these exposed datasets appear to be located in the United States, UpGuard said this is a worldwide problem. The findings build on earlier research that also found a range of exposed databases hosted on Supabase, including those by Y Combinator startups and other popular apps.

多年来,Supabase对其平台进行了多次改进,加强了平台的安全性以及用户对数据库的访问控制。

Supabase has made changes to its platform over the years, including bolstering its platform and user access to databases.

当被问及此事时,Supabase的首席信息安全官Bil Harmer表示,虽然该公司尚未看到相关研究报告,但其所有项目在默认情况下都是安全的。他认为安全问题是公司与其客户共同的责任:“我们提供了安全的基础设置和工具,客户可以自行配置他们的项目;一旦发现安全问题,我们会立即通知受影响的客户。”

When reached for comment, Supabase’s Chief Information Security Officer Bil Harmer said that while the company has not seen the research, its projects are “secure by default.” He described security as a shared responsibility between the company and its customers. “We provide secure defaults and tooling, and customers control how their own projects are configured,” and the company notifies affected customers when security issues are discovered, he said.

Hamer进一步强调:“Supabase的安全工作永无止境。我们非常重视安全问题,并会不断努力,让每位开发者都能更轻松地开发出安全可靠的应用程序。”

“Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely,” said Harmer.

UpGuard的安全研究员Greg Pollock认为,该公司的研究对于提高人们对数据泄露问题的认识具有重要意义。

UpGuard security researcher Greg Pollock said the company’s research was important for raising awareness about the issue of data exposures.