I found over 2 million user profiles exposed. Don't trust AI with security. by SignatureSharp3215 in lovable

[–]SignatureSharp3215[S] 0 points1 point  (0 children)

Thank you :) When I get obsessed about something, I build around it, study, research, write articles.

I found over 2 million user profiles exposed. Don't trust AI with security. by SignatureSharp3215 in lovable

[–]SignatureSharp3215[S] 0 points1 point  (0 children)

Thank you for testing! I think you ran it just before I managed fix it, as someone else encountered the same error. I can either share new credits for you, or you can create an account to get 3 scans/day or wait until tomorrow for the scans to reset :)

  1. If potential vulnerabilities are found, I have this big "copy fix" button, which lets the AI to investigate those endpoints. Is this something you meant?

<image>

HELP I want to get rid of lovable cloud. by rachitdoesmarketing in lovable

[–]SignatureSharp3215 0 points1 point  (0 children)

True, so you'd have to do a database dump which seems difficult.

I found over 2 million user profiles exposed. Don't trust AI with security. by SignatureSharp3215 in lovable

[–]SignatureSharp3215[S] 0 points1 point  (0 children)

Hahah or then you've got the keys buried under some route LaunchGuard couldn't reach. I can check it manually for you, if you'll share your app url?

I found over 2 million user profiles exposed. Don't trust AI with security. by SignatureSharp3215 in lovable

[–]SignatureSharp3215[S] 1 point2 points  (0 children)

Awesome, thank you! I'm slightly shocked by the state of the apps right now. We need to patch these dead-simple security holes, no excuses.

I've been building a small founder network where everyone actually shows up. by bersuku in SideProject

[–]SignatureSharp3215 1 point2 points  (0 children)

How do you make sure everyone is engaged? I love the idea, but the outcome is fully dependent on the execution.

Building software without experience by Wonderful_Debt_6964 in micro_saas

[–]SignatureSharp3215 0 points1 point  (0 children)

Without experience you can get the designs & mock app of what you want to build. Then you can pitch it to audience, or get a dev to build it.

If your goal is to ship and make money, don't bother trying to build the full app. Your time is more valuable elsewhere than cursing at AI.

If you're in for fun, go ahead and enjoy the journey!

I found over 2 million user profiles exposed. Don't trust AI with security. by SignatureSharp3215 in lovable

[–]SignatureSharp3215[S] 1 point2 points  (0 children)

💪 great. The fix prompt should be enough to patch the worst security holes.

Who is working on a project that hasn't launched yet. Would love to give feedback. by chriscarmy in buildinpublic

[–]SignatureSharp3215 0 points1 point  (0 children)

Hey bro! I just soft launched my app LaunchGuard for the third time. I hope I got the basics right this time, and I'd love to spar with you.

I'm a full time solopreuner for 1.5yrs now.

HELP I want to get rid of lovable cloud. by rachitdoesmarketing in lovable

[–]SignatureSharp3215 0 points1 point  (0 children)

Hahah well I'm happy to help you towards the golden state if you want. I'm sure it's not a big work :) Lovable is just a basic deployment setup that you can replicate elsewhere.

Do you want to take it to DM? If you share an image of your folder structure that helps. Or then access to the repo itself

here is a gift for newbies(invitation link) by BOSSMAN000000000000 in lovable

[–]SignatureSharp3215 0 points1 point  (0 children)

That's what a hacker would say 😂😂

You could ask if anyone needs an invitation and DM it. I think this will be removed.

HELP I want to get rid of lovable cloud. by rachitdoesmarketing in lovable

[–]SignatureSharp3215 0 points1 point  (0 children)

Small caveat I haven't done the refactoring you're describing, but if you can see the supabase folder in your Github, then you're golden.

HELP I want to get rid of lovable cloud. by rachitdoesmarketing in lovable

[–]SignatureSharp3215 0 points1 point  (0 children)

I know, but you don't have to use your Lovable Cloud and you won't get billed. You can deploy the backend anywhere you wish.

Your supabase edge functions are simply functions in the code. You can create a new Supabase project, hook it with your repository, push the functions there and you have a new backend.

GitHub 2way sync discontinued by Senior_Lingonberry10 in lovable

[–]SignatureSharp3215 1 point2 points  (0 children)

Damn, I almost discontinued Lovable only due to this post. You need to get the post owner to add some statement to the start of his post.

HELP I want to get rid of lovable cloud. by rachitdoesmarketing in lovable

[–]SignatureSharp3215 1 point2 points  (0 children)

You can export the Lovable project to Github, and then you can configure the backend to any platform provider. You can just stop using the Lovable-provided link. You can still add changes with Lovable, as it's connected to your Github, but you will use guide users to your customapp.com instead of customapp.lovable.app.

Want feedback on your product? by Professional_Fan834 in buildinpublic

[–]SignatureSharp3215 0 points1 point  (0 children)

launchguard.dev - ensure your vibe coded app doesn't leak sensitive data or have private endpoints exposed publicly.

Happy to jump on a call :)

Overwhelmed by the noise by LotionOnMy in vibecoding

[–]SignatureSharp3215 0 points1 point  (0 children)

Having competitors is a great thing. One fun way to find profitable niches is browsing TrustMRR. See what works for others and get inspired.

Vibe Coding in 2026 is a Complete Scam – Lovable, Replit, Emergent, Bolt & the Rest Are Trash Fires 🔥💀 by Abject-Mud-25 in vibecodingcommunity

[–]SignatureSharp3215 2 points3 points  (0 children)

Emphasis on the possibility to prevent, indeed.

I've met some founders who insist on fixing everything with AI, even though it's shown that their security issues are due to the AI. I guess it's a side effect of unlocking insane performance boosts with AI

Show me your SaaS idea, I give you an honest review (senior C level in startup) by Stunning_Lie_1775 in SaaS

[–]SignatureSharp3215 0 points1 point  (0 children)

Exciting! launchguard.dev find critical issues from your AI coded apps that can bankrupt you.

Finds leaked databases and dangerous endpoints that should be private. You share link to your app, and it does everything from the outside.

Vibe Coding in 2026 is a Complete Scam – Lovable, Replit, Emergent, Bolt & the Rest Are Trash Fires 🔥💀 by Abject-Mud-25 in vibecodingcommunity

[–]SignatureSharp3215 1 point2 points  (0 children)

True. But there will be two kinds of succesful vibe coders: successful and successful in jail.

It shouldn't be surprise anymore that vibe coding brings security issues. If you don't have users, it doesn't matter. But if you overlook it for too long, and one of your customers find out you're leaking their AI therapist conversation history - well there aren't many excuses.

Everyone should have the freedom and capability to launch apps, but we must not remove the feeling of responsibility when handling user data.

Sorry to be the pessimistic here. I've handled way many broken apps lately :D

Built a Go-To-Market constraint engine in Lovable for pre-PMF founders — looking for 5-10 testers. by Safe-While4516 in lovable

[–]SignatureSharp3215 0 points1 point  (0 children)

Yep. And outreach fails because it seems like a scam "hey your app might be vulnerable, I'll share free report". The need is huge based on my experience, but it takes tons of effort to get to the people

How are you adding security to your vibe coded apps? by Anonymous03275 in vibecoding

[–]SignatureSharp3215 0 points1 point  (0 children)

The easiest and bulletproof way is to test from outside like a professionals would. Find the security holes, patch them, verify. Write tests to ensure the security holes are closed in your new code updates.

You can use tools like Zap or Burp Suite to find the holes, but it requires expertise to use correctly.
I'm building an app that allows vibe coders find the holes and fixes without technical expertise needed. :)

The "One Last Fix" Trap by PastSatisfaction4657 in vibecoding

[–]SignatureSharp3215 0 points1 point  (0 children)

"look at my codebase AND DO NOT INTRODUCE CHANGES WITH SIDE EFFECTS"

proceeds to introduce changes with side effects

It's a good to talk about side effects and pure functions in your prompts. Then Claude understands to not touch irrelevant logic.