메뉴
BL
TechCrunch AI • 15시간 전

수파베이스 고객 수천 개 DB, 개인정보 노출 실태

IMP
7/10
핵심 요약

사이버보안 업체 UpGuard의 조사에 따르면 개발 플랫폼 Supabase에서 호스팅되는 약 1만 6천 개의 데이터베이스가 이름, 주소, 전화번호, 비밀번호 등 개인정보를 공개 웹에 노출하고 있습니다. 바이브 코딩(vibe coding) 열풍으로 AI 도구가 생성한 코드의 보안 결함과 개발자의 잘못된 설정이 대규모 데이터 유출 사고로 이어지는 사례가 늘고 있어, AI 개발 도구 활용 시 기본 보안 설정 점검의 중요성이 부각됩니다.

번역된 본문

사이버보안 업체 UpGuard의 새로운 보안 연구에 따르면, 개발 플랫폼 Supabase에서 호스팅되는 수천 개의 데이터베이스가 사람들의 민감한 정보를 공개 웹에 노출하고 있는 것으로 밝혀졌습니다. UpGuard는 테크크런치(TechCrunch)에, 웹·앱 개발자들이 데이터베이스를 저장하고 운영할 수 있게 해주는 Supabase에서 호스팅되는 약 1만 6천 개의 데이터베이스에서 어느 정도 수준의 개인 데이터가 노출되었다고 밝혔습니다. Supabase는 올해 초 개발자들이 '바이브 코딩(vibe coding)'으로 만든 앱을 플랫폼에 호스팅하는 것이 늘면서 100억 달러의 기업 가치를 달성했습니다. 그러나 이 회사는 사용자 보안 처리 방식에 대해 비판을 받아왔습니다. 사용자가 데이터베이스를 잘못 설정하거나 모르는 사이에 인터넷 전체에 노출한 사례가 널리 문서화되어 있으며, 일부 경우 수백만 건의 기록이 노출되기도 했습니다.

이번 조사 결과는 바이브 코딩으로 만든 앱과 웹사이트가 기본적인 설정 오류와 부적절한 보안으로 인해 민감한 데이터를 유출하거나 노출할 수 있음을 보여줍니다. AI 도구를 사용하면 웹사이트와 앱을 쉽게 만들 수 있지만, 생성된 코드에는 종종 보안 결함이 포함되어 있거나, 개발자가 알지 못하는 특정 설정이 앱에 필요할 수 있습니다. 수년에 걸쳐 수많은 데이터 유출 사고가 잘못 구성된 스토리지 서버, 데이터베이스, 웹사이트와 연관되어 왔습니다. 이러한 사고로 민감한 군사 이메일, 이민·비자 신청서, 기밀 정부 문서, 수십만 건의 운전면허증 스캔본, 아동 개인정보 등이 유출된 바 있습니다. 이제 AI 바이브 코딩 붐이 새로운 데이터 유출 물결을 부추기고 있으며, 사람들이 점점 더 Supabase를 데이터 저장에 사용하면서 많은 사고가 Supabase와 연관되고 있습니다.

UpGuard는 플랫폼 전반의 노출 데이터 규모를 파악하고자 조사를 진행했으며, 공개적으로 접근 가능한 이름, 주소, 전화번호, 사용자 비밀번호를 발견했습니다. 연구에서는 비교적 소수의 비밀번호와 인증 토큰도 확인되었습니다. 이 회사에 따르면 해당 데이터베이스에는 다양한 프로젝트와 관련된 데이터가 담겨 있었는데, 예를 들어 인도 성인 스트리밍 사이트에서 성매매 종사자와 나눈 비공개 대화, 미국 발렛(주차 대행) 서비스의 수천 건 차량 번호판, 이민·이주 서비스를 이용한 사람들의 연락처 정보 등이 포함되어 있었습니다. UpGuard에 따르면 데이터베이스 중 하나는 프랑스에 있는 아프리카 정부 영사관 소유였으며, 또 다른 하나는 온라인 계정 인증을 위한 일회성 비밀번호를 발송하는 가상 SIM 팜(SIM farm)이 문자 메시지를 가로채는 데 사용된 것으로, 이는 일반적으로 사기 및 피싱 공격에 활용됩니다. 노출된 데이터셋 대부분은 미국에 있는 것으로 보이지만, UpGuard는 이것이 전 세계적 문제라고 밝혔습니다.

이번 조사 결과는 Y 컴비네이터(Y Combinator) 스타트업과 기타 인기 앱을 포함해 Supabase에서 호스팅되는 다양한 노출 데이터베이스를 발견한 이전 연구를 발전시킨 것입니다. Supabase는 수년에 걸쳐 플랫폼 강화 및 사용자의 데이터베이스 접근 관리 개선 등 변화를 시도해 왔습니다. 코멘트 요청에 대해 Supabase의 빌 하머(Bil Harmer) 최고정보보안책임자(CISO)는 회사가 해당 연구를 접하지는 못했지만 자사 프로젝트는 "기본적으로 안전하다(secure by default)"고 말했습니다. 그는 보안을 회사와 고객 간의 공동 책임이라고 설명했습니다. "우리는 안전한 기본 설정과 도구를 제공하며, 고객이 자신의 프로젝트를 어떻게 구성할지 통제합니다"라고 그는 말하며, 보안 문제가 발견되면 회사가 영향을 받은 고객에게 통지한다고 덧붙였습니다. 하머 CISO는 "Supabase의 보안은 완성되지 않았습니다. 우리는 이를 올바르게 하는 것을 깊이 중요하게 생각하며, 모든 개발자가 안전하게 배포할 수 있도록 계속 노력할 것"이라고 밝혔습니다. UpGuard의 보안 연구원 그렉 폴락(Greg Pollock)은 이번 연구가 데이터 노출 문제에 대한 인식을 높이는 데 중요하다고 말했습니다.

원문 보기
원문 보기 (영어)
Thousands of databases hosted by development platform Supabase are exposing people's sensitive information to the public web, new security research by cybersecurity firm UpGuard has found. UpGuard told TechCrunch that it found around 16,000 databases on which some degree of personal data was exposed while they were hosted by Supabase, which allows web and app developers to store and run their databases. Supabase earlier this year reached a $10 billion valuation , thanks to a rise in developers hosting their vibe-coded apps on the platform. But the company has faced criticism for how it handles user security. There are widely documented cases of users misconfiguring or unknowingly exposing their databases to the broader internet, in some instances to the tune of millions of records each . The findings highlight how vibe-coded apps and websites can spill or expose sensitive data through basic misconfigurations and improper security. While AI tools can be used to easily build websites and apps, the generated code can often contain security flaws, or apps might require specific configuration that the developer may be ignorant of. Over the years, countless data breaches have been linked to improperly configured storage servers, databases and websites. Such cases have resulted in the leaks of sensitive military emails , immigration and visa applications , classified government files , hundreds of thousands of driver's license scans and children's personal information . Now, the boom in AI vibe-coding is helping fuel a new wave of data breaches, many of which are now being linked to Supabase as people increasingly use it for storing their data. UpGuard says it sought to understand the scale of exposed data across the platform, and found publicly accessible names, addresses, phone numbers and user passwords. The research surfaced a fewer number of passwords and authentication tokens. The firm said the databases contained data linked to various projects, such as private conversations with sex workers on an Indian adult streaming site; thousands of license plates of a U.S. valet service; and the contact information of people who used an immigration and relocation service. One of the databases belonged to an African government's consulate in France, said UpGuard, while another was used to intercept text messages by a virtual SIM farm for sending one-time passcodes to verify online accounts, typically for launching scams and phishing attacks. While the majority of these exposed datasets appear to be located in the United States, UpGuard said this is a worldwide problem. The findings build on earlier research that also found a range of exposed databases hosted on Supabase, including those by Y Combinator startups and other popular apps . Supabase has made changes to its platform over the years, including bolstering its platform and user access to databases. When reached for comment, Supabase's Chief Information Security Officer Bil Harmer said that while the company has not seen the research, its projects are "secure by default." He described security as a shared responsibility between the company and its customers. "We provide secure defaults and tooling, and customers control how their own projects are configured," and the company notifies affected customers when security issues are discovered, he said. "Security at Supabase is never finished. We care deeply about getting it right, and we'll keep making it easier for every developer to ship securely," said Harmer. UpGuard security researcher Greg Pollock said the company's research was important for raising awareness about the issue of data exposures. Topics AI , cybersecurity , data exposure , Security , Supabase , vibe coding When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Zack Whittaker Security Editor Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security . He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com . View Bio October 13 - 15 San Francisco Your next big connection is at Disrupt. Connect with 10,000+ founders, VCs, operators, and tech leaders. Explore tomorrow’s breakthroughs, hear what’s shaping tech today, and save up to $200 by Sept. 25 at 11:59 p.m. PT. BOOK NOW Most Popular Everything new coming to Meta's AI agent Muse Kirsten Korosec Lucas Ropek Meta made a Tamagotchi-like wearable for its Muse AI agent Lucas Ropek Anthropic says its biology lab has already found something big Julie Bort PitPro's first tire-changing robot goes live in Canada Sean O'Kane Anthropic releases Opus 5.5 with lower prices and Fable-level performance Russell Brandom OpenAI forms math advisory group as its AI resolves more than 100 open problems Aditya Mehta Meta's Muse is outpacing ChatGPT’s early mobile launch Sarah Perez