logoalt Hacker News

Tl;dv: Over 180k meetings left wide open

585 pointsby colesantiagoyesterday at 12:26 PM192 commentsview on HN

Comments

yellow_leadyesterday at 2:12 PM

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art...

But they try to play it off as though this were public data:

> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.

Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.

[1] https://tldv.io/features/security-commitment/

show 8 replies
cube00yesterday at 2:35 PM

I saw an YouTuber the other day sharing their "day in the life" as an Amazon Software Engineer while promoting (as part of a paid sponsorship) the AI note taking feature of SoundCore headphones, claiming they now record their meetings and receive an AI summary at the end.

I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.

show 6 replies
xvxvxyesterday at 7:23 PM

This should be the kiss of death for any company. The exposure of sensitive data like that, and for that long? There's a serious disconnect between security best practices and law, and how many companies actually operate.

My own company is a sitting duck for hackers right now. I've begged them to implement basic 2FA for 6 months and all they do is brush concerns under the carpet. No one gives a shit, all the way to the very top.

palmoteayesterday at 1:15 PM

Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.

show 3 replies
Aeroiyesterday at 1:42 PM

"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "

oof

show 1 reply
fsutsyesterday at 2:42 PM

> He responded within minutes: "thank you! can you report it to our CTO and we will look at it immediately?"

Why could he not speak to HIS ceo himself instead of asking Bob to

show 2 replies
Ekarosyesterday at 1:06 PM

I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.

show 2 replies
wkirbyyesterday at 2:01 PM

I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem.

The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.

show 4 replies
purplemoonxyesterday at 2:31 PM

It's hilarious how these companies handle security breaches.

I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.

I had just started working there and found it in the first week.

Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.

Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).

-----

I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.

show 6 replies
msyeayesterday at 6:41 PM

My biggest worry is the small talk that you casually have in meetings. Comments about your pattern of life, family, locations, friends and health. Slurping all that up over 100s of meetings is concerning. Stored raw transcripts of meetings is a huge liability. Should redact small talk and only store useful extracts.

show 1 reply
sktbyesterday at 12:49 PM

Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.

show 1 reply
Orasyesterday at 1:23 PM

Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it.

Wasn't a dating app exposed this year with same negligence or firebase security?

show 2 replies
gppkyesterday at 8:06 PM

Heh, interesting. I literally just vibe-coded an app tonight that takes a meeting recording, runs it through whisper to generate the text, then through your local codex gives you a summary and creates actions that are pushable to either github (technical) or PM tool (project level)

Takes about 7 minutes for a 2 hour meeting on my 3080 GPU so well within useful timeframe.

I did it because i didn't want to pay £7 a month for a discord meeting notes taker, but seems generally useful. And ofc you could swap out for a local model if you have more compute than i do...

show 1 reply
ubervisoryesterday at 8:37 PM

These companies take anything but responsibility. The fact that they’re trying to downplay it in their own blog post with “but look at the others, they’ve had security issues too,” as if that makes it any better, says it all. I would never trust that company with anything ever again.

show 1 reply
_superposition_today at 10:00 AM

How is this even a product? Call me cynical and maybe slightly jealous but I increasingly believe the difference between successful and unsuccessful startup businesses is suckering investors out of a check and faking it til you make it. Influencer trash vibes.

nashashmiyesterday at 3:39 PM

This breach will help with tl;dv's awareness. More people will suddenly become aware of it. The downside is that less private conversations will be hooked up to tl;dv, and more public seminars will be fed instead. This is a win-win overall. And it is a PSA to all other companies to secure their servers a little bit better.

sensanatyyesterday at 3:05 PM

The worst part of these AI meeting notes and recordings is that I have literally never seen anybody, in any situation, go back to them. The (very) few times I ever bothered to check the transcripts and especially the summaries immediately after a meeting, without fail they'd have something in them that is the complete opposite of what someone said in the meeting, or they'd miss extremely important clarifications or context. Literally worse than useless, actively detrimental, but you bet your ass whichever moron forced these to be on for every meeting is putting it on their resume - "Increased long-term organizational cohesiveness via comprehensive automated meeting notes" or whatever type of bullshittery.

show 1 reply
SpaceL10nyesterday at 1:12 PM

Hmm, does Ukraine know that Russia is watching the Ministry of Digital Transformation's meetings?

gvvyesterday at 4:06 PM

Funny, my first thought was that this has to be related to Firebase...

jwrallieyesterday at 10:33 PM

The worst thing is that there is nothing technical preventing this kind of service from running fully local. All the audio is already being routed to any participant and transcription models are lightweight enough and can run in virtually any computer.

slp3ryesterday at 2:56 PM

Turns out building https://github.com/sleep3r/crispy was a pretty good idea

SpyCoder77yesterday at 10:45 PM

I love the fact that, if the emails listed in the post are correct, bob didn't even try to be professional with formatting or capitalization or anything. That shows how much power this man had in this situation lol

usamaasfaryesterday at 2:12 PM

I'm starting to believe Firebase is cursed at this point.

show 2 replies
chrysopraceyesterday at 10:08 PM

We use a similar tool at work and it's automatically invited to every meeting. It records, transcribes, and lets you search for something somebody said and when. It is incredibly unsettling.

hashstringyesterday at 7:31 PM

The disclosure section is gold. It’s such an accurate description.

Major consumer companies reply just like that.

It’s incompetence and I think to an extent also arrogance.

buzeryesterday at 8:45 PM

My first thought was "huh, I wonder if they follow GDPR, that starts sound to like Article 32 violation" (related to security of processing). I checked the privacy policy and yes, they are based in Germany so GDPR likely applies to all of their processing.

However that privacy policy raises also quite a few concerns. They say that "profile image URL" is based on contractual obligation which is quite weird, just why profile image is necessary to fulfill a contract? Additionally IP address and location are collected for "adapted pricing" and it's "legal and contractual obligation". I can somewhat understand that if it's used to calculate VAT, but "adapted pricing" sounds much wider thing. And even VAT calculation itself isn't really "adapted pricing", it's something that the company needs to handle. They are of course free to change the price based on that, but that price change goes more to legitimate interest rather than legal (or contractual) obligation.

They also claim that "Product analysis and improvement, marketing and attribution, incident management and in some of our logs" as well as "Analysis of products and navigation on the site and application" are also "legal and contractual obligation". I honestly want to hear what contract necessitates those or exactly what law requires them to do that.

toreador44yesterday at 7:47 PM

From an online article about the CEO:

"Raphael Allstadt, co-founder of Germany’s fastest-growing startup, tl;dv, argues that European tech needs to be “bold but secure” to win the enterprise AI race."

"But Silicon Valley may have more engineering talent on paper; Europeans care far more about data, security, and privacy. That means our builders pay closer attention, build compliance in from the start, and are ultimately better suited to serve the enterprise market, especially here in Europe.”

As tl;dv scales, Allstadt’s mission remains twofold: to prove that a European startup can out-execute the US giants on product, while maintaining the privacy standards Europe demands.

The irony

gyanchawdharyyesterday at 1:22 PM

This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.

Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026

PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..

https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)

https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)

It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.

show 1 reply
headzyesterday at 3:18 PM

OK, the issue sucks. That said, the post was written by an LLM and It's not pleasant to read. If I didn’t work with Claude every day, I might feel differently, but because I do, this reads like slop.

show 2 replies
iJohnDoeyesterday at 2:21 PM

I think this is one of the few times public disclosure wasn’t a good idea. Some of these are government meetings and could put lives in danger.

Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.

LoganDarkyesterday at 11:32 PM

> I wanted to say something so badly. "Hey, you might want server-side validation too." But this was a proof of concept, not a consultation.

oh man, imagine telling them "you don't want people like me breaking into your app! Just look at how I got into this call!"

odo1242yesterday at 9:01 PM

This is essentially the #1 Firebase footgun. Having client-accessible databases with optional rule-base security has always seemed a bit dumb to me.

Aeroiyesterday at 1:22 PM

holy crap. how do you respond as CEO to this and not escalate to like priority #1?

then kick the can for 6 months?

show 2 replies
nope1000yesterday at 2:39 PM

To forget tenant isolation on one endpoint is bad enough but to ignore it for 6 months is madness. I am at a SaaS company and our customers have such strict security requirements for us and that is for less confidential data.

homeonthemtnyesterday at 3:28 PM

Wow.

idiotsecantyesterday at 1:02 PM

Is this still active? I wouldn't mind spying on some meeting notes. Sounds fun.

show 3 replies
Trasmattayesterday at 3:28 PM

> tl;dv names their microservices after pasta. A subdomain scan reveals cappellini, carbonara, fusilli, pasta, penne, puttanesca-v0, and ravioli, all under tldv.io. An entire Italian restaurant worth of Express servers.

Pretty appropriate, given a vulnerability of this severity. Literal microservice spaghetti.

(Also, please, let's all move back to boring names for services and servers. Nobody likes trying to decode what all these silly names mean.)

EDIT:

omg, the disclosure communication is infuriating.

> We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO

This should have been a P1 that was fixed same day, and they strung him along for months. Absolute amateurs.

broheeyesterday at 2:47 PM

Now let's see if European users get their GDPR article 33 notification of the breach...

saadyousfiyesterday at 3:44 PM

[dead]

ayang3000yesterday at 1:57 PM

[flagged]

redsocksfan45yesterday at 1:35 PM

[dead]

plantainyesterday at 3:27 PM

"Because the common denominator between both of these distinct incidents was Firebase, we are taking the additional step of immediately removing it from our tech stack altogether to definitively eliminate the risk of similar vulnerabilities in the future." - from their post-mortem.

Thank god the root cause was definitively identified! /s

new_account_900yesterday at 1:18 PM

[dead]

alkhyesterday at 1:49 PM

[flagged]

throwaway613746yesterday at 4:46 PM

[dead]

CurbStomperyesterday at 5:18 PM

[dead]

roystingyesterday at 6:47 PM

[dead]

hluskayesterday at 1:25 PM

I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?

show 4 replies

🔗 View 2 more comments