I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
Tl;dv: Over 180k meetings left wide open
31–40 of 231 posts
Re: Tl;dv: Over 180k meetings left wide open
#32Earlier quoted context omitted.
Fortunately we have LLM's to not produce that crap... wait, those LLM's were trained on the existing crap and produce the same crap... oh no.
I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it. And even if, a later "is this ready for release" will probably surface such obvious issues. I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.
Re: Tl;dv: Over 180k meetings left wide open
#33Earlier quoted context omitted.
You need to read the article.
I read the entire article. Did you? There’s no reason in there to expose this company’s clients. Edit - Are you capable of answering my actual question or was that the best you could do?
And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”
Re: Tl;dv: Over 180k meetings left wide open
#34This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk. Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/m…
> 4TB/40,000 contractors voice + government ID + selfie leaked Leaked selfies? Do you mean ID photos?
Re: Tl;dv: Over 180k meetings left wide open
#35Re: Tl;dv: Over 180k meetings left wide open
#36So did he email privacy@tldv.io? Why not? Maybe someone who understands it would read it.
Re: Tl;dv: Over 180k meetings left wide open
#37Earlier quoted context omitted.
I read the entire article. Did you? There’s no reason in there to expose this company’s clients. Edit - Are you capable of answering my actual question or was that the best you could do?
He has been emailing the CEO for six months with no replies. This is has also been posted here before with not a single pip or comment ... :-) And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.
Re: Tl;dv: Over 180k meetings left wide open
#38The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
Re: Tl;dv: Over 180k meetings left wide open
#39Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.
Re: Tl;dv: Over 180k meetings left wide open
#40Earlier quoted context omitted.
Fortunately we have LLM's to not produce that crap... wait, those LLM's were trained on the existing crap and produce the same crap... oh no.
I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it. And even if, a later "is this ready for release" will probably surface such obvious issues. I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.
Asking the LLM for a review of the code would still have caught it