# Firebase: be careful to properly secure your data!

**URL:** <https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655>\
**Category:** Questions about Thunkable X\
**Created:** [June 29, 2018, 8:49pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655 "2018-06-29T20:49:51Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rob\_Schoemaker](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/rob_schoemaker/32/21023_2.png) [@Rob\_Schoemaker](https://community.thunkable.com/u/Rob_Schoemaker)\
**Post date:** [June 29, 2018, 8:49pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/1 "2018-06-29T20:49:51Z")

</div>

We all love firebase, and for a lot of applications the data stored in firebase will not be that critical. However, if you plan to store personal or confidential data in firebase, please think about your users and make sure to pay a lot of attention to properly securing your data, to avoid ending up in reports like this:

[Report on firebase breaches](https://info.appthority.com/hubfs/Appthority%20Q2-2018%20MTR%20Firebase%20Vulnerability.pdf?t=1529028419687&utm_campaign=Mobile%20Threat%20Reports&utm_source=hs_automation&utm_medium=email&utm_content=63775252&_hsenc=p2ANqtz-87dYv0h3BCKTEJJWXOUqitWgr16Ms1r5WQbn9zEPVFRJA_bNxYivBvEOQKWYXkWtMCzIMB6jDfnenz2Jh6lSuIKt_yaw&_hsmi=63775252)

regards Rob

---

<div class="post-metadata">

**Author:** ![albert](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/albert/32/4077_2.png) [@albert](https://community.thunkable.com/u/albert)\
**Post date:** [July 3, 2018, 6:19pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/2 "2018-07-03T18:19:39Z")

</div>

Thanks for this reminder @Rob_Schoemaker!

---

<div class="post-metadata">

**Author:** ![Zhou\_Sicong](https://avatars.discourse-cdn.com/v4/letter/z/df788c/32.png) [@Zhou\_Sicong](https://community.thunkable.com/u/Zhou_Sicong)\
**Post date:** [August 28, 2018, 9:30am UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/3 "2018-08-28T09:30:34Z")

</div>

How do we properly secure the firebase data if the app is to allow read and write by all users of the app? What are the firebase rules we need to set and how do we authenticate users and allow them access to their own nodes only?

---

<div class="post-metadata">

**Author:** ![Rob\_Schoemaker](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/rob_schoemaker/32/21023_2.png) [@Rob\_Schoemaker](https://community.thunkable.com/u/Rob_Schoemaker)\
**Post date:** [September 3, 2018, 6:17pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/4 "2018-09-03T18:17:36Z")

</div>

General:

[https://firebase.google.com/docs/database/security/](https://firebase.google.com/docs/database/security/)

Only allowing users to access their own nodes:  
[https://firebase.google.com/docs/database/security/user-security](https://firebase.google.com/docs/database/security/user-security)

---

<div class="post-metadata">

**Author:** ![maxb](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/maxb/32/35200_2.png) [@maxb](https://community.thunkable.com/u/maxb)\
**Post date:** [May 1, 2019, 2:58pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/5 "2019-05-01T14:58:19Z")

</div>

The link is labeled as dangerous for the pc, isn’t it ironic?

---

<div class="post-metadata">

**Author:** ![maxb](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/maxb/32/35200_2.png) [@maxb](https://community.thunkable.com/u/maxb)\
**Post date:** [May 1, 2019, 3:01pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/6 "2019-05-01T15:01:56Z")

</div>

I’d like to have in my app a cellphone number only authentication, I can have the SMS verification trough an external service, but I don’t know if I can have the firebase data security if the user doesn’t register to firebase with the email, any suggestion or explanation about it?

Thx

---

<div class="post-metadata">

**Author:** ![collingwoodkarate](https://avatars.discourse-cdn.com/v4/letter/c/b2d939/32.png) [@collingwoodkarate](https://community.thunkable.com/u/collingwoodkarate)\
**Post date:** [July 27, 2020, 2:59pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/7 "2020-07-27T14:59:43Z")

</div>

Hey Rob, Really having trouble getting the firebase rules to work. If I set read write to true, the app below works. But if I change the firebase rules to the suggested read/write access, I can’t get it to work. If you have any advice, it would be really really appreciated. I’ve watched, and read so many tutorials. Thank you so much if you have any suggestions. John  
[https://x.thunkable.com/copy/d402369a4eb5e9a929f719e08410115a](https://x.thunkable.com/copy/d402369a4eb5e9a929f719e08410115a)

rules in firebase:  
{  
“rules”: {  
“users”: {  
“$uid”: {  
“.read”: “auth != null && auth.uid == $uid”,  
“.write”: “auth != null && auth.uid == $uid”  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![maxb](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/maxb/32/35200_2.png) [@maxb](https://community.thunkable.com/u/maxb)\
**Post date:** [July 29, 2020, 4:24pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/8 "2020-07-29T16:24:50Z")

</div>

Check this post:

> [@WOW I can't believe I finally made it with Firebase security rules!](http://community.thunkable.com/t/wow-i-cant-believe-i-finally-made-it-with-firebase-security-rules/196252):
>
> Ok so, I know rules-fu. I’ve been studying and fighting with firebase for a while now, it’s NOT been easy for me, but I think I can say that I nailed it. So if you need help with firebase security, I’llgladly helpfellow thunkers to saveyou tons of time.

Firebase security rules can be very, very hard to understand.Read a lot and the keep reading.

---

<div class="post-metadata">

**Author:** ![ioannis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ioannis/32/146956_2.png) [@ioannis](https://community.thunkable.com/u/ioannis)\
**Post date:** [November 8, 2024, 12:00pm UTC](https://community.thunkable.com/t/firebase-be-careful-to-properly-secure-your-data/33655/9 "2024-11-08T12:00:26Z")

</div>


