Live data from Hacker News

Tl;dv: Over 180k meetings left wide open

bobdahacker.com

21–30 of 231 posts

Re: Tl;dv: Over 180k meetings left wide open

#22
post #12

holy crap. how do you respond as CEO to this and not escalate to like priority #1? then kick the can for 6 months?

> how do you respond as CEO to this and not escalate to like priority #1? then kick the can for 6 months?

We might be able to check the meeting minutes and get the answer?

Re: Tl;dv: Over 180k meetings left wide open

#23
post #6

Earlier quoted context omitted.

Sturgeon's Law is proved correct time and again. Most things are crap. Most people produce some crap in their lives. Some people only produce crap. Those people still need to eat but unfortunately some of them (somehow) find their way into tech and actually convince people to pay money for crap. Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high…

Fortunately we have LLM's to not produce that crap... wait, those LLM's were trained on the existing crap and produce the same crap... oh no.

I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it.

And even if, a later "is this ready for release" will probably surface such obvious issues.

I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.

Re: Tl;dv: Over 180k meetings left wide open

#24
post #19

So did he email privacy@tldv.io? Why not? Maybe someone who understands it would read it.

It's unclear. Only stating the existence of the privacy email.

> [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]

This is near the disclosure schedule

Re: Tl;dv: Over 180k meetings left wide open

#25
post #15

I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?

You need to read the article.

I read the entire article. Did you? There’s no reason in there to expose this company’s clients.

Edit - Are you capable of answering my actual question or was that the best you could do?

Re: Tl;dv: Over 180k meetings left wide open

#26
"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "

oof

Re: Tl;dv: Over 180k meetings left wide open

#27
post #15

I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?

As I see it he is not the one exposing clients to risk. He is frustrated that no one is fixing it. The company that left themselves open like this are the ones that are exposing their clients.

If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.

Re: Tl;dv: Over 180k meetings left wide open

#28
post #25

Earlier quoted context omitted.

You need to read the article.

I read the entire article. Did you? There’s no reason in there to expose this company’s clients. Edit - Are you capable of answering my actual question or was that the best you could do?

He has been emailing the CEO for six months with no replies. This is has also been posted here before with not a single pip or comment ... :-)

And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.

Post reply on HN