Live data from Hacker News

Tl;dv: Over 180k meetings left wide open

bobdahacker.com

51–60 of 231 posts

Re: Tl;dv: Over 180k meetings left wide open

#52
I think this is one of the few times public disclosure wasn’t a good idea. Some of these are government meetings and could put lives in danger.

Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.

Re: Tl;dv: Over 180k meetings left wide open

#53
post #14

Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it. Wasn't a dating app exposed this year with same negligence or firebase security?

It's almost like people need knowledge and experience to work with tools securely. The problem with Firebase (I think) is that its marketing is "it's easy to use" and I'm confident most problems - like storing this info - is easy to figure out and finish, then move on to the next thing.

But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.

Re: Tl;dv: Over 180k meetings left wide open

#55

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], p…

Is there an entity that can validate they are not SOC2 compliant outside of their claim?

Re: Tl;dv: Over 180k meetings left wide open

#56
It's hilarious how these companies handle security breaches.

I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.

I had just started working there and found it in the first week.

Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.

Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).

-----

I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.

Re: Tl;dv: Over 180k meetings left wide open

#58
post #38

I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem. The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is…

Drafts.app is hideous but it has great routing capability and a dictation feature. I use it to capture what my thoughts and route based on content. I have a button that routes to an internal voice agent named KiKo. Ideas get routed to Things or todoist. Issues get routed to github, etc. It’s one universal surface for note capture.

But man is it ugly.

Re: Tl;dv: Over 180k meetings left wide open

#59
post #25

Earlier quoted context omitted.

You need to read the article.

I read the entire article. Did you? There’s no reason in there to expose this company’s clients. Edit - Are you capable of answering my actual question or was that the best you could do?

I think it is fine, the person hasn't really leaked any critical information. He named a few clients that are mostly government departments, and it would be a public interest concern if said issue is ignored for 6 months anyway

Re: Tl;dv: Over 180k meetings left wide open

#60
I saw an YouTuber the other day sharing their "day in the life" as an Amazon Software Engineer while promoting (as part of a paid sponsorship) the AI note taking feature of SoundCore headphones, claiming they now record their meetings and receive an AI summary at the end.

I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.

Post reply on HN