Tl;dv: Over 180k meetings left wide open
- Security
- AI
- Privacy
- Developer Tools
- Regulation
The post alleges tl;dv, a startup that records and summarizes meetings with AI, exposed over 180,000 meeting artifacts because one backend endpoint lacked tenant isolation. In plain terms, users could retrieve recordings, transcripts, and metadata from other customers. The writeup says the data included internal corporate calls and government meetings across many countries. The researcher also published a long disclosure timeline showing the CEO acknowledged the issue early, routed it to the CTO, and then let it sit for roughly six months before the company fixed it and published a response.
If you use AI meeting tools, assume the default risk is far higher than the marketing suggests and review where recordings, transcripts, and sharing links actually live. For buyers, this pushes security review away from badges like SOC 2 and toward hard questions about tenant isolation, retention, local processing, and breach response time.
-
bobdahacker.com
- Discuss on HN