WEBVTT

1
00:00:03.200 --> 00:00:08.080
This is Decrypted. Tuesday, the twenty-ninth of September.

2
00:00:08.080 --> 00:00:13.440
Supabase's secure default skips the way most apps are built now.

3
00:00:13.440 --> 00:00:18.240
Sixteen thousand, three hundred and twenty six leaking databases.

4
00:00:18.240 --> 00:00:21.680
It sounds like a story about careless developers.

5
00:00:21.680 --> 00:00:25.760
It's really a story about a lock that only fits one door.

6
00:00:25.760 --> 00:00:34.333
Researchers at UpGuard scanned roughly 300,000 domains built on Supabase, the database platform behind a larg

7
00:00:34.333 --> 00:00:37.120
e share of today's AI-assisted app building.

8
00:00:37.120 --> 00:00:45.807
They found that many of the exposed tables were leaking real personal data: names, tokens, and in a Canadian

9
00:00:45.807 --> 00:00:50.800
immigration service's case, 884 plaintext passwords.

10
00:00:50.800 --> 00:00:54.880
The telling detail isn't that developers made mistakes.

11
00:00:54.880 --> 00:01:01.760
It's that Supabase's own security default only switches on if you build a table one particular way.

12
00:01:01.760 --> 00:01:05.600
And the way most people now build tables is the other one.

13
00:01:05.600 --> 00:01:11.040
Next.

The lock that only fits one door.

14
00:01:11.040 --> 00:01:18.480
Supabase controls access through something called Row Level Security, or R L S.

15
00:01:18.480 --> 00:01:23.360
It's a policy layer that decides which rows a given key is allowed to see.

16
00:01:23.360 --> 00:01:32.853
Since 2025, Supabase has switched R L S on by default for any table created through its Table Editor, the poi

17
00:01:32.853 --> 00:01:40.773
nt-and-click web console. But tables created programmatically, through the A P I, don't get R L S switched on

18
00:01:40.773 --> 00:01:49.840
by default.

That second route is exactly how AI coding agents such as Lovable, Replit and Bolt build an app's

19
00:01:49.840 --> 00:01:55.520
database. Someone types "build me a booking system" into a chat window.

20
00:01:55.520 --> 00:02:02.600
The agent calls the A P I, the table appears, and the safety switch that would exist if a human had clicked t

21
00:02:02.600 --> 00:02:04.800
hrough the console is simply absent.

22
00:02:04.800 --> 00:02:12.560
Now add the habit of pasting a "public" anonymous key into client-side code as though it were a secret one.

23
00:02:12.560 --> 00:02:19.520
Any table without R L S is then readable by anyone who finds that key sitting in the page source.

24
00:02:19.520 --> 00:02:22.881
That's most of them.

And also.

25
00:02:22.881 --> 00:02:25.040
Whose default is it, anyway.

26
00:02:25.040 --> 00:02:31.280
Vendors are right to say a default can't cover every configuration choice a developer might make.

27
00:02:31.280 --> 00:02:39.280
But this default fails on the single most common path in 2026: code that a person never directly wrote.

28
00:02:39.280 --> 00:02:43.600
UpGuard's own framing is the sharpest part of its report.

29
00:02:43.600 --> 00:02:51.770
It argues it's "time to rebalance the equation", the way Amazon did with S3, which flipped to private-by-defa

30
00:02:51.770 --> 00:02:56.800
ult buckets after a decade of leaks, and the way GitHub did with new repositories.

31
00:02:56.800 --> 00:03:03.280
A secure default that quietly exempts the fastest-growing way of using a product isn't a default.

32
00:03:03.280 --> 00:03:06.160
It's a footnote.

And finally.

33
00:03:06.160 --> 00:03:09.200
What UK organisations should take from this.

34
00:03:09.200 --> 00:03:17.813
Plenty of UK fintechs, agencies and startups are prototyping on Supabase, often through exactly the AI tooli

35
00:03:17.813 --> 00:03:24.400
ng this report describes. And they're moving those prototypes into production faster than anyone reviews them.

36
00:03:24.400 --> 00:03:32.160
A misconfigured database holding customer P I I is a personal data breach under UK G D P R.

37
00:03:32.160 --> 00:03:36.400
It doesn't matter whether it was built by a contractor or a chatbot.

38
00:03:36.400 --> 00:03:44.040
"The AI did it" is not a defence the I C O has ever accepted, and there's no reason to expect it to start.

39
00:03:44.040 --> 00:03:46.640
The practical fix costs little.

40
00:03:46.640 --> 00:03:53.120
Before anything built this way goes live, someone should run Supabase's own security advisor.

41
00:03:53.120 --> 00:03:57.200
They should confirm R L S is enabled on every table.

42
00:03:57.200 --> 00:04:03.920
And they should treat an anonymous key found in client-side code as a red flag, not normal practice.

43
00:04:03.920 --> 00:04:08.560
Secure by Design was written for humans writing code by hand.

44
00:04:08.560 --> 00:04:11.440
It has to survive the case where nobody did.

45
00:04:11.440 --> 00:04:16.960
That was Decrypted. The written version and every source are linked in the show notes.

46
00:04:16.960 --> 00:04:18.400
Thanks for listening.

