144 pointsby colesantiago2 hours ago20 comments
  • yellow_lead16 minutes ago
    Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art...

    But they try to play it off as though this were public data:

    > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.

    Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.

    [1] https://tldv.io/features/security-commitment/

  • palmoteaan hour ago
    Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.
    • HPsquared39 minutes ago
      Also add the word "secure" a lot.
    • markboo24 minutes ago
      AI agent: sorry for that, I'll build the next version will be the most secured one
  • wkirby26 minutes ago
    I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem.

    The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.

  • Ekarosan hour ago
    I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.
    • pc86an hour ago
      Sturgeon's Law is proved correct time and again. Most things are crap. Most people produce some crap in their lives. Some people only produce crap. Those people still need to eat but unfortunately some of them (somehow) find their way into tech and actually convince people to pay money for crap.

      Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.

      • noir_lordan hour ago
        Fortunately we have LLM's to not produce that crap... wait, those LLM's were trained on the existing crap and produce the same crap... oh no.
        • user43928an hour ago
          I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it.

          And even if, a later "is this ready for release" will probably surface such obvious issues.

          I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.

          • wongarsu22 minutes ago
            However if you start current SOTA models out on a bad codebase they will happily write more bad code to fit in with the "conventions" of the existing code. Including authentication and isolation. If you start out your app on the wrong foot (for example because you lack the vocabulary to express what you need) you can end up with nicely polished turds

            Asking the LLM for a review of the code would still have caught it

          • skydhash35 minutes ago
            Still the six month wait time when everything should be good? /s
        • bonoboTP15 minutes ago
          They were RL trained on verifiable rewards. It's not purely learning to predict the next token of a human produced stream.
    • owen-hill7 minutes ago
      [flagged]
  • 18 minutes ago
    undefined
  • Aeroian hour ago
    "Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "

    oof

  • Orasan hour ago
    Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it.

    Wasn't a dating app exposed this year with same negligence or firebase security?

  • usamaasfar16 minutes ago
    I'm starting to believe Firebase is cursed at this point.
  • iJohnDoe6 minutes ago
    I think this is one of the few times public disclosure wasn’t a good idea. Some of these are government meetings and could put lives in danger.

    Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.

  • sktb2 hours ago
    Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.
  • SpaceL10nan hour ago
    Hmm, does Ukraine know that Russia is watching the Ministry of Digital Transformation's meetings?
  • gyanchawdharyan hour ago
    This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.

    Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026

    PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..

    https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)

    https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)

    It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.

    • lostloginan hour ago
      > 4TB/40,000 contractors voice + government ID + selfie leaked

      Leaked selfies? Do you mean ID photos?

      • zeroxfe30 minutes ago
        Selfies are used during live ID verification. (All of this is supposed to be encrypted, and destroyed within certain regulatory bounds.)
  • idiotsecantan hour ago
    Is this still active? I wouldn't mind spying on some meeting notes. Sounds fun.
    • mdrznan hour ago
      If they haven't fixed it in 6 months, I'd say it's fair game to scrape as much as you can.
      • bpodgursky13 minutes ago
        I know this is a joke but it's still a felony, for your own sake don't do this.
    • blitzaran hour ago
      "Lets circle back and touch base to tease out any low hanging synergies we can capitalise on" - repeated 181,000 times
    • an hour ago
      undefined
  • Aeroian hour ago
    holy crap. how do you respond as CEO to this and not escalate to like priority #1?

    then kick the can for 6 months?

    • lostloginan hour ago
      > how do you respond as CEO to this and not escalate to like priority #1? then kick the can for 6 months?

      We might be able to check the meeting minutes and get the answer?

    • root-parentan hour ago
      A post on LinkedIn where this CEO seems very active should solve that.
  • ayang300030 minutes ago
    [flagged]
  • redsocksfan45an hour ago
    [dead]
  • alkh39 minutes ago
    [flagged]
  • new_account_900an hour ago
    [dead]
  • hluskaan hour ago
    I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
    • gossamer40 minutes ago
      As I see it he is not the one exposing clients to risk. He is frustrated that no one is fixing it. The company that left themselves open like this are the ones that are exposing their clients.

      If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.

    • Ekaros22 minutes ago
      Sometimes shame is only option to get things fixed. Sadly we do not have any reliable government institutions that could mandate immediate shut down of services. Before that only way to get things fixed is public shame.
    • root-parentan hour ago
      You need to read the article.
      • hluskaan hour ago
        I read the entire article. Did you? There’s no reason in there to expose this company’s clients.

        Edit - Are you capable of answering my actual question or was that the best you could do?

        • mikestew33 minutes ago
          Read the article again, then. Anyone that has could get the list with a trivial amount of work. Security through obscurity isn’t going to hide that client list.

          And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”

        • root-parent39 minutes ago
          He has been emailing the CEO for six months with no replies. This is has also been posted here before with not a single pip or comment ... :-)

          And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.

          • Oras21 minutes ago
            Technical due diligence do not including pep test!
          • dpark29 minutes ago
            > And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.

            That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.

            • root-parent20 minutes ago
              >> They trusted a company that made a promise and that company let them down.

              That is a Boeing and Volkswagen type of excuse. The engineers did it!

    • masfuerte36 minutes ago
      What's the alternative? Seriously. He's spent six months trying to get them to fix it. The risk is already there.
  • seb1204an hour ago
    So did he email privacy@tldv.io? Why not? Maybe someone who understands it would read it.
    • ncr100an hour ago
      It's unclear. Only stating the existence of the privacy email.

      > [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]

      This is near the disclosure schedule

    • intended30 minutes ago
      From the article - he reached out to the CEO directly, who acknowledged and said it was being worked on by the CTO. He did this repeatedly over 6 months.