Live data from Hacker News

Tl;dv: Over 180k meetings left wide open

bobdahacker.com

71–80 of 231 posts

Re: Tl;dv: Over 180k meetings left wide open

#71

It's hilarious how these companies handle security breaches. I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault . I had just started working there and found it in the first week. Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years ev…

I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal.

I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.

Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.

Re: Tl;dv: Over 180k meetings left wide open

#72

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], p…

Is there an entity that can validate they are not SOC2 compliant outside of their claim?

Yes, SOC2 require an audit by an independent auditor, and in principle you can request their audit report from them.

Just email the CTO about it ;)

Re: Tl;dv: Over 180k meetings left wide open

#73

Earlier quoted context omitted.

> I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it. The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of…

Idk licensing and regulation sounds like involving more institutional arrogance. We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed). The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doi…

this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.

Re: Tl;dv: Over 180k meetings left wide open

#74
post #38

I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem. The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is…

I'm definitely biased as the developer, but maybe try https://whistle-enterprise.com and see how it works for you. It's a hard problem I've been working away on for a while now. It's far from perfect but every step brings it a bit closer.

Literally starting my monday weekly standup now, I'll run it and see what's up. Thanks!

Re: Tl;dv: Over 180k meetings left wide open

#75
post #14

Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it. Wasn't a dating app exposed this year with same negligence or firebase security?

If something happens again and again, it is by choice. Firebase chooses to make it “easy” to get started rather than “secure by default”.

Re: Tl;dv: Over 180k meetings left wide open

#77
post #71

It's hilarious how these companies handle security breaches. I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault . I had just started working there and found it in the first week. Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years ev…

I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal. I explained to him how the EC2 instances would assume the role that already had the permission an…

So bad.

At these types of startups, developers will find themselves in some debate about the time complexity of a click handler (which is debounced anyway).

Meanwhile Joe CEO is like "HAY GUYS" -drops db-

"CAN U FIX IT BY MONDAY"

Re: Tl;dv: Over 180k meetings left wide open

#78

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], p…

On a personal note, I recognize that I should have kept the researcher updated after his initial outreach earlier this year, and I take full responsibility for that communication gap.

They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period?

Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.

Re: Tl;dv: Over 180k meetings left wide open

#79

It's hilarious how these companies handle security breaches. I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault . I had just started working there and found it in the first week. Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years ev…

More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.

Re: Tl;dv: Over 180k meetings left wide open

#80
post #38

I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem. The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is…

I'm definitely biased as the developer, but maybe try https://whistle-enterprise.com and see how it works for you. It's a hard problem I've been working away on for a while now. It's far from perfect but every step brings it a bit closer.

Seems interesting. What would you say are the biggest missing points currently or things you want to get working/improved but couldn't yet?
Post reply on HN