Ask HN: What in the world is going on at Supabase?
No synthesized answer yet. Check the discussion below.
Emails to support@, info@ etc multiple TLDs, all ignored for months...
1. someone created an website using supabase with email logins (and possibly edited the template / opt-out link)
2. someone signed you up to that service - you received an email from that app
3. you sent us an email (to support@supabase.io or similar) to report abuse
4. we emailed a few months later with the generic email you posted
First, I'm sorry you had a bad experience. we have been historically very on-top of our support emails, but this year the tickets have grown ~10x while our team can only grow ~2x. We have had to make short-term trade-offs (automations) which are sub-par so that we can catch up with the growth and primarily focus on the paying customersI'm be the first to acknowledge that this is something we want to improve. Unfortunately that will take time and iterations - you are experiencing our support (i hope) at it's worst. We sent an email to the backlog of unanswered free-plan emails just to acknowledge and redirect them somewhere we can offer more support
For security/fraud, we have a slightly different process: https://supabase.com/.well-known/security.txt
This process is to ensure that we _don't_ miss emails, like we did with yours.
You post here is helpful for us to figure out the areas that we need to improve. Again, I'm sorry that we didn't give you a good impression the first time - all we can do is iterate based on feedback like yours. If you want to share more my email is in my profile
I still don't even know if that does what I think it does (it sounds like marketing list opt-out).
/ /
How is a user, who has been signed up for your services without their knowledge, meant to "opt out" of the trial, or account, after the point of receiving the email,
if they never even initiated the account on your end?
While this sucks, your best bet is to vote with your wallet, find a way to act as though they don't exist, and leave them to their own devices.
I'm not a client, no relationship with them.
@kiwicopple - given you have keyword notifications set up on here [0], between this and your current AWS situation, this is not a good look
> your current AWS situation
I think the assessment here is accurate:
https://x.com/theo/status/1979271205279666586
> Looked into this a bit. I don’t think “downtime” is a fair way to report on this. No existing databases are affected. Amazon is literally out of boxes in eu-west-2, so Supabase can’t provision NEW DBs in that one specific region
I want to own the fact that we can be multi-cloud, and that we can work with AWS on their capacity planning (note: this is not a typical request for an increase on a soft limit). We are working through both of these options. That said, the Reddit poster classifying this as days of downtime is not entirely fair, and it makes it harder to for us to over communicate with our community. Throughout this period we had days where there was free of capacity on AWS and we chose to leave the status up until we have finalized our conversations with AWS.
I also want to acknowledge that there is a broader AWS issue today in us-east-1 which affects us (and most other companies today) that is unrelated
They claim that? Where?
1. your company owns example.com
2. someone signs up to supabase with alice@example.com
3. you receive the confirmation email somehow (which probably isn't important)
a. either the email address is valid,
b. it is delivered some catch-all mailbox
4. you email supabase support notifying them that someone is signing up with an address that your company controls
Is that right? If so, I don't think this is some kind of vital security event. The confirmation email won't be delivered to the purported bad actor, so the account won't verify.(I have no way to know what's possible, or what the spoof accounts are doing - I've never registered with them! Just trying to give a courtesy heads up so they can take a look at bad actors on their platform...)
"You've successfully signed up. Please check your email to confirm your account before signing in to the Supabase dashboard. The confirmation link expires in 10 minutes."
If you attempt to sign in before verifying, you'll see:
"Account has not been verified, please check the link sent to your email"
So nothing is going to happen. This is probably a bot probing for accounts. The system is operating as intended. No cause for concern.
----
One more bit: when you receive the initial account email, you'll find a note at the bottom confirming the intention:
"If you didn't request for this, you can safely ignore this email."
The Opt out of these emails link was the end of their email.
Unless they’ve changed this since this ordeal began for me on July 12th, this is still a problem.
They're active on discord, so maybe bring it up there: https://discord.com/invite/AYybku5cUz
I got my DB paused a few times despite it being active (the irony is that I have an inactive DB that was not affected).