frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

11% of vibe-coded apps are leaking Supabase keys

https://supaexplorer.com/cybersecurity-insight-report-january-2026
5•xyborg•1h ago

Comments

xyborg•1h ago
Something remarkable happened in 2024-2025: building a full-stack app became easy. Tools like Supabase, combined with AI coding assistants and no-code builders, let solo founders ship production apps in days, not months.

But speed comes at a cost. As we started using SupaExplorer to audit projects, we noticed a pattern: many apps were misconfiguring their Supabase setup. The anon key in client-side code is fine; it's designed to be public. But we found apps exposing the service_role key (which bypasses RLS), or using the anon key with tables that had no RLS policies at all.

We decided to quantify the problem. Over the past month, we collected launch URLs from five major indie product directories and systematically scanned each one.

- 20,052 URLs Scanned - 2,217 Domains Exposed - 11.04% Exposure Rate - 2,325 Critical Exposures

What's Being Leaked

Not all exposures are equal. Finding a Supabase project URL and anon key in client code is expected, as both are designed to be public. The anon key provides low-privilege access that respects your Row Level Security policies.

The danger is when apps expose the service_role key (or the new sb_secret_... format), the elevated-privilege key meant only for server-side use. Of the 2,960 files flagged, we found credentials that could bypass RLS in a significant portion. We also verified which exposed databases had tables without RLS protection.

I would love to hear your thoughts on this, and how can we generating awareness about this topic.

How to be a good conference talk audience member (2022)

https://www.mooreds.com/wordpress/archives/3522
1•mooreds•7m ago•0 comments

Who Gets to Inherit the Stars?

https://techcrunch.com/2026/01/17/who-gets-to-inherit-the-stars-a-space-ethicist-on-what-were-not...
1•zansara•8m ago•0 comments

A Hit Movie Set Deep Inside an AI Lab

https://www.wsj.com/tech/ai/google-deepmind-documentary-youtube-thinking-game-732bfa06
1•bookofjoe•10m ago•1 comments

My Personal Financial Strategy (2020)

https://www.rdegges.com/2020/my-personal-financial-strategy/
1•mooreds•10m ago•0 comments

The Suicide Pact: what happens the moment we invade Greenland

https://substack.com/inbox/post/184398789
3•Eric_WVGG•13m ago•3 comments

DetLLM – Deterministic Inference Checks

https://github.com/tommasocerruti/detllm
1•cerru905•15m ago•1 comments

Musk wants up to $134B in OpenAI lawsuit, despite $700B fortune

https://techcrunch.com/2026/01/17/musk-wants-up-to-134b-in-openai-lawsuit-despite-700b-fortune/
2•SilverElfin•19m ago•2 comments

Camden County Police in New Jersey expands drone program

https://www.cbsnews.com/philadelphia/news/camden-nj-homicides-drone-program/
1•pilingual•20m ago•0 comments

Ask HN: Duterte EJK, 2025-09, US extrajudicial killing in the Caribbean?

1•stopbulying•20m ago•1 comments

Authenticating Digital Evidence in US Courts [pdf]

https://law.baylor.edu/sites/g/files/ecbvkj1546/files/2023-11/7_grimm_capra_joseph.pdf
1•colonCapitalDee•21m ago•0 comments

EU Set to Halt US Trade Deal over Trump's New Tariff Threat

https://www.bloomberg.com/news/articles/2026-01-17/eu-set-to-halt-us-trade-deal-over-trump-s-late...
7•ekjhgkejhgk•22m ago•2 comments

Ask HN: Why is the $0 hijacking of intellectual labor so normalized in OSS?

1•fumi2026•25m ago•6 comments

My Rube Goldberg RSS Pipeline

https://taoofmac.com/space/blog/2026/01/17/2130
1•rcarmo•26m ago•0 comments

Global trust crisis deepfakes AI

https://techfusiondaily.com/global-trust-crisis-deepfakes-ai/
1•nelkazzu•27m ago•0 comments

Ask HN: How AliExpress gets its recommendation as priority in Gmail?

2•RicoElectrico•28m ago•1 comments

Weight-loss drugs could save U.S. airlines more than $500M this year

https://www.latimes.com/business/story/2026-01-15/weight-loss-drugs-help-airlines
2•cwwc•28m ago•0 comments

A.I. and Burnout

https://petersobot.com/blog/on-ai-and-burnout/index.html
3•psobot•29m ago•0 comments

"This is the way" parody Bluesky posts

https://bsky.app/profile/shengokai.blacksky.app/post/3mcndjl5hw22w/quotes
1•mooreds•30m ago•3 comments

Texas A&M university is banning Plato, citing his "gender ideology"

https://lithub.com/texas-am-is-banning-plato-citing-his-gender-ideology/
5•Geekette•32m ago•1 comments

Has AI removed the appeal of vertical SaaS?

https://www.elliotcsmith.com/has-ai-removed-the-appeal-of-vertical-saas/
1•smitec•35m ago•0 comments

Pittsburgh researchers developing lifesaving robot "dogs"

https://www.cbsnews.com/news/pittsburgh-researchers-carnegie-mellon-life-saving-robot-dogs/
1•rolph•36m ago•0 comments

Show HN: Potatoverse, Platform for Apps

https://github.com/blue-monads/potatoverse
5•born-jre•37m ago•1 comments

The Engineering Management Myths Star Trek Teaches (2022)

https://philipotoole.com/star-trek-made-me-a-bad-engineering-manager/
4•otoolep•40m ago•1 comments

Partial reprogramming as a strategy for aging and disease

https://www.sciencedirect.com/science/article/pii/S1568163726000012
2•jjoe•41m ago•0 comments

DIY Potato Aerogel: Free Cooling from Your Kitchen? [video]

https://www.youtube.com/watch?v=J87Qyxzm_fQ
1•znpy•42m ago•0 comments

The EU, spurred by Trump, to sign mega free-trade deal with South America

https://www.washingtonpost.com/world/2026/01/17/eu-trade-deal-mercosur-south-america/
6•stopbulying•44m ago•4 comments

Auto start Next.js dev server when you open the project in VSCode

https://marketplace.visualstudio.com/items?itemName=bullptr.nextjs-code
1•bukharim96•45m ago•0 comments

Show HN: School/ಶಾಲೆ – Agentic Voice Tutor for Students

1•gaganyatri•51m ago•0 comments

Apache Arrow for the Database

https://dataengineeringcentral.substack.com/p/apache-arrow-for-the-database
2•tanelpoder•52m ago•0 comments

New fintech company claims Bitcoin will reach 100M by 2050

https://www.distributedledgertechnologies.com/
1•winnertakeall•53m ago•2 comments