Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m not familiar with Firebase, but is it unusual for end users to have direct access to a database at all? Why isn’t there a web front end there?



Firebase has a "rules" feature where you set up security/authorization rules on your database:

https://firebase.google.com/docs/database/security#section-a...

There's a "development" mode you can enable on your database that simply ignores all of the rules. The college app either 1) has no/unsafe rules set up, or 2) left their Firebase database in development mode.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: