I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.
Tl;dv: Over 180k meetings left wide open
51–60 of 231 posts
Re: Tl;dv: Over 180k meetings left wide open
#52Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.
Re: Tl;dv: Over 180k meetings left wide open
#53Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it. Wasn't a dating app exposed this year with same negligence or firebase security?
But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.
Re: Tl;dv: Over 180k meetings left wide open
#54Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.
Re: Tl;dv: Over 180k meetings left wide open
#55Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], p…
Re: Tl;dv: Over 180k meetings left wide open
#56I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
Re: Tl;dv: Over 180k meetings left wide open
#57Re: Tl;dv: Over 180k meetings left wide open
#58I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem. The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is…
But man is it ugly.
Re: Tl;dv: Over 180k meetings left wide open
#59Earlier quoted context omitted.
You need to read the article.
I read the entire article. Did you? There’s no reason in there to expose this company’s clients. Edit - Are you capable of answering my actual question or was that the best you could do?
Re: Tl;dv: Over 180k meetings left wide open
#60I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.