Tl;dv: Over 180k meetings left wide open
bobdahacker.com
bobdahacker.com
But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
Just email the CTO about it ;)
They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period?
Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.
They do have enterprise level controls that let admins turn this off. Unfortunately, it is on by default, and some of those basic security controls require a higher tier of service.
It is absolutely wild that these companies treat security like an afterthought. And I also realized SOC2 Compliant meant absolutely nothing.
Using common, overbearing MDM or endpoint tools make providing evidence of adherence to policies easier, however.
I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.
> You should use a when the word that follows sounds like it begins with a consonant (‘a dog,’ ‘a balloon’). You should use an if the word that follows sounds like it begins with a vowel (‘an ant,’ ‘an elevator’). Remember that sometimes a word will begin with a vowel but it sounds like a consonant (‘a one-time deal’); in this case you should still use a, rather than an. And in some cases a word will start with a consonant but it sounds like a vowel (’an hour’); in this case you should still use an, rather than a. [1]
Maybe English is just broken. Words starting with a long “u” sound make me question the rule - different than other long vowels…
Does one play “a ukulele” or “an ukulele”?
We need an umpire to make the call (;->
Using a more familiar example might help illustrate this: we say “a user”, not “a user”; similarly, it’s “a European”, not “an European”.
Here’s a good article about it: https://phonicshero.com/when-is-a-consonant-a-vowel-and-why/
I let him and our manager know that he'd just violated eavesdropping laws across state lines (he's in D.C. and I'm in WA; RCW 9.73.030).
It's amazing how many people don't think that "AI Notetaker" is the same as "I secretly recorded this (as possibly violated the law)"
Btw, how do you understand the purpose of this law? Because I can't imagine it serving anyone other than abusers and liars that want to abuse a lie without leaving evidence.
Two party consent just means recordings are mostly useless because it lets the worst party control the availability, so unless they are very stupid, they just won't consent.
Kind of funny how that is the pitch for a lot of these products. AI to help you take notes in meetings. AI to help you pass an interview. AI to read and write for you. AI to let you be a lazy bastard, in other words.
Under the security part, they do seem to at least be compliant with your typical security standards (HIPAA, SOC 2 Type 1, etc.) and claim that all data is deleted within 12 hours of transcription. So it isn't like the contents of your meeting are being siphoned off to some fly-by-night service, at least.
So no, I don't think they're very reputable at all.
My own company is a sitting duck for hackers right now. I've begged them to implement basic 2FA for 6 months and all they do is brush concerns under the carpet. No one gives a shit, all the way to the very top.
oof
Why could he not speak to HIS ceo himself instead of asking Bob to
You can't expect a founder/CEO to spend 2 minutes relaying an email with critical security information to his own CTO, he's surely way too busy disrupting and pivoting and doubling down on product market fit.
* I know they're just saying the words a self aware person would say to give that impression, but it can be eerily convincing.
Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026
PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..
https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)
https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)
It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.
Leaked selfies? Do you mean ID photos?
Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.
And even if, a later "is this ready for release" will probably surface such obvious issues.
I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.
Asking the LLM for a review of the code would still have caught it
That is not a very good basis to start complaining about AI producing insecure code.
If you still want to do it, at least check if it actually is the case with reasonably intelligent current models.
The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
But man is it ugly.
I think clearly the _leader_ in the space is granola, but I'm just not going to use a cloud provider for this.
Drafts have anything like that?
It's a hard problem I've been working away on for a while now. It's far from perfect but every step brings it a bit closer.
Two more improvements, audio quality improvements which is currently in the works and close to release and a new document generation model. I'm currently using a custom fine tuned Phi-4 (released December 2024!) model, that's _so old_ in the grand scheme of LLMs, I just haven't had time to benchmark and properly test some new models whilst this currently does a good job as it is. There has to be some gains here, but who knows!
Ahh yea as for the models:
Speech to text - Nvidia Parakeet TDT 0.6b V3
Diarisation - Nvidia Marblenet for the speech detection, TitaNet-Large for the embeddings and then using NeMo multi-scale to do clustering around them
I might take another look into doing it in a different way that gradually builds up from successful calls, I just need to think of how to do this in a simple(ish) way for non-technical users and a way that still works well enough on low to mid tier laptops.
If you’re targeting data for people to use on the same call then requires more intense work, while if you’re targeting data for people to use after or on an ongoing basis (eg an established business meeting with staff/vendors/etc) then having a predefined one seems good. Same interface as a CRM: picture, some audio clips for users to choose from, and confidence scores on each section of the recording for cases where people sound similar or are talking over each other. Over time the diarization gets better as users accept/reject/tag samples and that work helps them feel more aligned with the tool.
Some great suggestions, appreciate you taking the time to write it out, it's given me some things to think about.
Unfortunately it’s mostly not up to you. It’s a weakest-link problem. It doesn’t matter if you don’t use a note taker AI, if even one person on the call uses one. Their tool doesn’t notify you and usually the person doesn’t either.
It also has the reverse impact to the person using the note taker, where people say less around them. Same as if I'm talking to someone with Meta glasses.
I wonder if the people who use these tools know the people they meet with speak less during their meetings, and then all of the participants have a post-meeting call without them to say what they really thought.
Yeah, but I'm unwilling to be that person.
Yep, diarization just hasn't been well solved yet. As soon as it has, the quality in note-takers, meeting transcripts, etc, will sky-rocket across the board.
I also agree that diarization and speaker identification are probably one of the hardest parts to get right if the speakers aren’t separated correctly, even a great summary won’t fix it.
We’re looking into more privacy preserving approaches for MindNote (a multimodal AI Notetaker), including local/on-device processing, so this is really useful feedback. Thanks for sharing your experience!
Wasn't a dating app exposed this year with same negligence or firebase security?
But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.
Takes about 7 minutes for a 2 hour meeting on my 3080 GPU so well within useful timeframe.
I did it because i didn't want to pay £7 a month for a discord meeting notes taker, but seems generally useful. And ofc you could swap out for a local model if you have more compute than i do...
It's not about the meeting, its about the work after the meeting.
This tool creates a list of reviewable actions, and has API access to github and project management tools so i can tag the owners and submit them direct.
It also creates comprehensive, well versed minutes, in a historically logged list.
How many of your meetings you pay attention to do you actually get all that output, that you can share and push back to your team?
AI notes are a godsend, because instead of forcing one person to keep careful notes throughout, the meeting's host can quickly review, edit, and send out the minutes - a job that otherwise would literally take more time than the meeting, because one person spent the meeting just taking notes. The AI notes require careful review, and contain a lot of repetitive fluff, but all notes require review before distribution.
So, now you are aware that this is a normal thing in other companies.
Perhaps we can all agree that usage is very bimodal, between the people who refer to auto-notes constantly vs never?
1785962536 | Tl;Dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open | https://bobdahacker.com/blog/tldv-hack | https://news.ycombinator.com/item?id=49188723
Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.
Pretty appropriate, given a vulnerability of this severity. Literal microservice spaghetti.
(Also, please, let's all move back to boring names for services and servers. Nobody likes trying to decode what all these silly names mean.)
EDIT:
omg, the disclosure communication is infuriating.
> We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO
This should have been a P1 that was fixed same day, and they strung him along for months. Absolute amateurs.
"Raphael Allstadt, co-founder of Germany’s fastest-growing startup, tl;dv, argues that European tech needs to be “bold but secure” to win the enterprise AI race."
"But Silicon Valley may have more engineering talent on paper; Europeans care far more about data, security, and privacy. That means our builders pay closer attention, build compliance in from the start, and are ultimately better suited to serve the enterprise market, especially here in Europe.”
As tl;dv scales, Allstadt’s mission remains twofold: to prove that a European startup can out-execute the US giants on product, while maintaining the privacy standards Europe demands.
The irony
oh man, imagine telling them "you don't want people like me breaking into your app! Just look at how I got into this call!"
> The irony is al dente.
Major consumer companies reply just like that.
It’s incompetence and I think to an extent also arrogance.
However that privacy policy raises also quite a few concerns. They say that "profile image URL" is based on contractual obligation which is quite weird, just why profile image is necessary to fulfill a contract? Additionally IP address and location are collected for "adapted pricing" and it's "legal and contractual obligation". I can somewhat understand that if it's used to calculate VAT, but "adapted pricing" sounds much wider thing. And even VAT calculation itself isn't really "adapted pricing", it's something that the company needs to handle. They are of course free to change the price based on that, but that price change goes more to legitimate interest rather than legal (or contractual) obligation.
They also claim that "Product analysis and improvement, marketing and attribution, incident management and in some of our logs" as well as "Analysis of products and navigation on the site and application" are also "legal and contractual obligation". I honestly want to hear what contract necessitates those or exactly what law requires them to do that.
Distributing it might count as copyright piracy, but merely downloading public data?
Your defense would have to be that you were authorized to access the data, or that you did not know that you weren't authorized to access the data. Not merely that the data was easily accessible.
then kick the can for 6 months?
We might be able to check the meeting minutes and get the answer?
Thank god the root cause was definitively identified! /s
> [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]
This is near the disclosure schedule
Edit - Are you capable of answering my actual question or was that the best you could do?
And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.
That is a Boeing and Volkswagen type of excuse. The engineers did it!
And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”
If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.
I’m so sorry for tl;dv ‘s insurance company.