But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
They do have enterprise level controls that let admins turn this off. Unfortunately, it is on by default, and some of those basic security controls require a higher tier of service.
It is absolutely wild that these companies treat security like an afterthought. And I also realized SOC2 Compliant meant absolutely nothing.
They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period?
Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.
I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.
I let him and our manager know that he'd just violated eavesdropping laws across state lines (he's in D.C. and I'm in WA; RCW 9.73.030).
It's amazing how many people don't think that "AI Notetaker" is the same as "I secretly recorded this (as possibly violated the law)"
My own company is a sitting duck for hackers right now. I've begged them to implement basic 2FA for 6 months and all they do is brush concerns under the carpet. No one gives a shit, all the way to the very top.
oof
Why could he not speak to HIS ceo himself instead of asking Bob to
Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026
PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..
https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)
https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)
It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.
The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
Wasn't a dating app exposed this year with same negligence or firebase security?
Takes about 7 minutes for a 2 hour meeting on my 3080 GPU so well within useful timeframe.
I did it because i didn't want to pay £7 a month for a discord meeting notes taker, but seems generally useful. And ofc you could swap out for a local model if you have more compute than i do...
1785962536 | Tl;Dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open | https://bobdahacker.com/blog/tldv-hack | https://news.ycombinator.com/item?id=49188723
Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.
Pretty appropriate, given a vulnerability of this severity. Literal microservice spaghetti.
(Also, please, let's all move back to boring names for services and servers. Nobody likes trying to decode what all these silly names mean.)
EDIT:
omg, the disclosure communication is infuriating.
> We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO
This should have been a P1 that was fixed same day, and they strung him along for months. Absolute amateurs.
"Raphael Allstadt, co-founder of Germany’s fastest-growing startup, tl;dv, argues that European tech needs to be “bold but secure” to win the enterprise AI race."
"But Silicon Valley may have more engineering talent on paper; Europeans care far more about data, security, and privacy. That means our builders pay closer attention, build compliance in from the start, and are ultimately better suited to serve the enterprise market, especially here in Europe.”
As tl;dv scales, Allstadt’s mission remains twofold: to prove that a European startup can out-execute the US giants on product, while maintaining the privacy standards Europe demands.
The irony
oh man, imagine telling them "you don't want people like me breaking into your app! Just look at how I got into this call!"
Major consumer companies reply just like that.
It’s incompetence and I think to an extent also arrogance.
However that privacy policy raises also quite a few concerns. They say that "profile image URL" is based on contractual obligation which is quite weird, just why profile image is necessary to fulfill a contract? Additionally IP address and location are collected for "adapted pricing" and it's "legal and contractual obligation". I can somewhat understand that if it's used to calculate VAT, but "adapted pricing" sounds much wider thing. And even VAT calculation itself isn't really "adapted pricing", it's something that the company needs to handle. They are of course free to change the price based on that, but that price change goes more to legitimate interest rather than legal (or contractual) obligation.
They also claim that "Product analysis and improvement, marketing and attribution, incident management and in some of our logs" as well as "Analysis of products and navigation on the site and application" are also "legal and contractual obligation". I honestly want to hear what contract necessitates those or exactly what law requires them to do that.
then kick the can for 6 months?