Eden Stroet
Eden Stroet is a security researcher and SOC analyst at Hadrian Security in Amsterdam, where they focus on vulnerability research, automated scanning, and pentesting. They are a volunteer with the Dutch Institute for Vulnerability Disclosure (DIVD) and an active bug bounty hunter on HackerOne and Intigriti. Eden runs two online cyber security communities called Digital Overdose and Hard Way Hacking and Coding. When they're not hacking, they're on an aerial hoop or playing videogames with friends.
Session
In one week, Eden pentested two completely separate applications built on Supabase, and both had Row-Level Security disabled. This talk walks through both engagements, the surprising ways developers misunderstand Supabase's security model, and why this vulnerability class keeps appearing even when the documentation warns you plainly. If you've ever shipped a Supabase app and didn't think twice about RLS, this one's for you.