Live data from Hacker News

Tl;dv: Over 180k meetings left wide open

bobdahacker.com

151–160 of 231 posts

Re: Tl;dv: Over 180k meetings left wide open

#151

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], p…

I used to work for a company seeking SOC2 compliance. They told me that I had to install corporate malware because of the compliance. I didn't want to install it on my personal computer, which I had been using for work. They sent me a company computer. I installed the corporate malware on that one. I set the company computer aside and continued working on my personal computer. No SOC2 compliance was harmed in the process.

Re: Tl;dv: Over 180k meetings left wide open

#152

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], p…

Once again proof that SOC2 is nothing but a marketing tactic, and busywork

VC runway afterburners, engage!!!

Re: Tl;dv: Over 180k meetings left wide open

#153

Earlier quoted context omitted.

More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.

I studied physics, did a PhD and postdoc, the whole science shebang. When I got into software development a few years ago, I was put into a well functioning pizza sized team that developed an internal app for another company. The crew was as software-dev as it gets,: - one architect who was there from the apps inception yen years prior, who knows all the ins and outs of the application - one project lead, who was wit…

Heh, that idea resonates with me. I’ve been contemplating some projects that will require pulling permits, and as part of that process have been trying to understand how an engineer reviewing my submitted plans would think.

While you could absolutely generate a list of compliance checks to execute like a formula, at the end of the day you need to have absorbed enough experience that, when presented a physical or imagined project, your brain is immediately able to make connections between what it sees and the general principles of how you build something correctly.

Since I don’t have that experience, I know I need to stick to the well-trod path. No clean-sheet deck construction methods for me. :)

Re: Tl;dv: Over 180k meetings left wide open

#154

Earlier quoted context omitted.

I know this is a joke but it's still a felony, for your own sake don't do this.

Serious question: how is it a felony? Distributing it might count as copyright piracy, but merely downloading public data?

The federal government outlaws "knowingly accessing a computer without authorization or exceeding authorized access" to obtain information from any "protected computer" (which, in this context, means any computer involved in interstate commerce - which, in practice, has been ruled such that it certainly includes any Internet-connected server of a corporation).

Your defense would have to be that you were authorized to access the data, or that you did not know that you weren't authorized to access the data. Not merely that the data was easily accessible.

Re: Tl;dv: Over 180k meetings left wide open

#155
post #38

I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem. The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is…

> I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem Unfortunately it’s mostly not up to you. It’s a weakest-link problem. It doesn’t matter if you don’t use a note taker AI, if even one person on the call uses one. Their tool doesn’t notify you and usually the person doesn’t either. It also has the reverse impact to the person using the note taker, whe…

> It doesn’t matter if you don’t use a note taker AI, if even one person on the call uses one

Yeah, but I'm unwilling to be that person.

Re: Tl;dv: Over 180k meetings left wide open

#156
post #130

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], p…

I used a product with SOC2 certification, which uploads all your chatbot conversations to a server they control (mandatory), potentially including source code and other proprietary data, which can be made visible to public with a single click. Doesn't matter if you are an individual or enterprise user. They do have enterprise level controls that let admins turn this off. Unfortunately, it is on by default, and some o…

SOC2 requires a company to write policies in a large number of areas, and to demonstrate that they're complying with the policies they wrote. AFAIK SOC2 does not require anything meaningful about the actual contents of the policies, nor does it require the policies to remain constant.

Re: Tl;dv: Over 180k meetings left wide open

#157
This should be the kiss of death for any company. The exposure of sensitive data like that, and for that long? There's a serious disconnect between security best practices and law, and how many companies actually operate.

My own company is a sitting duck for hackers right now. I've begged them to implement basic 2FA for 6 months and all they do is brush concerns under the carpet. No one gives a shit, all the way to the very top.

Re: Tl;dv: Over 180k meetings left wide open

#158
post #38

I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem. The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is…

> The breakdown in the pipeline seems to be reliable local diarization

Yep, diarization just hasn't been well solved yet. As soon as it has, the quality in note-takers, meeting transcripts, etc, will sky-rocket across the board.

Re: Tl;dv: Over 180k meetings left wide open

#160
post #26

"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. " oof

Hegseth loves this app!
Post reply on HN