67 comments

  • purplemoonx 30 minutes ago ago

    It's hilarious how these companies handle security breaches.

    I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.

    I had just started working there and found it in the first week.

    Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.

    Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).

    -----

    I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.

    • jjice 9 minutes ago ago

      I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal.

      I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.

      Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.

      • purplemoonx 3 minutes ago ago

        So bad.

        At these types of startups, developers will find themselves in some debate about the time complexity of a click handler (which is debounced anyway).

        Meanwhile Joe CEO is like "HAY GUYS" -drops db-

        "CAN U FIX IT BY MONDAY"

    • mschuster91 23 minutes ago ago

      > I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.

      The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time.

      In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.

      • purplemoonx 17 minutes ago ago

        Idk licensing and regulation sounds like involving more institutional arrogance.

        We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).

        The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doing.

        Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing. People who have done it a thousand times should get that job, not some dumb kid who just got out of school.

        • QuadmasterXLII 8 minutes ago ago

          this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.

  • yellow_lead an hour ago ago

    Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art...

    But they try to play it off as though this were public data:

    > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.

    Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.

    [1] https://tldv.io/features/security-commitment/

    • cyberge99 32 minutes ago ago

      Is there an entity that can validate they are not SOC2 compliant outside of their claim?

      • maebert 9 minutes ago ago

        Yes, SOC2 require an audit by an independent auditor, and in principle you can request their audit report from them.

        Just email the CTO about it ;)

  • palmotea 2 hours ago ago

    Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.

    • HPsquared an hour ago ago

      Also add the word "secure" a lot.

    • markboo an hour ago ago

      AI agent: sorry for that, I'll build the next version will be the most secured one

    • DrammBA 19 minutes ago ago

      Actually they are taking one from Anthropic's playbook and saying it's the user's fault for misunderstanding what "sharing" means.

  • slp3r 5 minutes ago ago

    Turns out building https://github.com/sleep3r/crispy was a pretty good idea

  • wkirby an hour ago ago

    I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem.

    The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.

    • properbrew 17 minutes ago ago

      I'm definitely biased as the developer, but maybe try https://whistle-enterprise.com and see how it works for you.

      It's a hard problem I've been working away on for a while now. It's far from perfect but every step brings it a bit closer.

      • wkirby 7 minutes ago ago

        Literally starting my monday weekly standup now, I'll run it and see what's up. Thanks!

    • cyberge99 29 minutes ago ago

      Drafts.app is hideous but it has great routing capability and a dictation feature. I use it to capture what my thoughts and route based on content. I have a button that routes to an internal voice agent named KiKo. Ideas get routed to Things or todoist. Issues get routed to github, etc. It’s one universal surface for note capture.

      But man is it ugly.

      • wkirby 21 minutes ago ago

        My ideal use case is to pipe audio from both my microphone and capture system audio so things like our weekly team standup or my 1:1s with my devs can all have reliable, decent notes without taking me out of the flow of the conversation.

        I think clearly the _leader_ in the space is granola, but I'm just not going to use a cloud provider for this.

        Drafts have anything like that?

  • cube00 26 minutes ago ago

    I saw an YouTuber the other day sharing their "day in the life" as an Amazon Software Engineer while promoting (as part of a paid sponsorship) the AI note taking feature of the SoundCore headphones, claiming how great it was they now record their meetings and receive an AI summary at the end.

    I wonder how many companies realise their meetings are being funnelled to all these note taking AI companies.

    • newsoftheday 14 minutes ago ago

      Not trying to be rude or mean here but it should be, "a YouTuber" since YouTuber starts with a consonant sound.

      • Ylpertnodi 10 minutes ago ago

        I knew a girl called Anne Yoo.

  • fsuts 19 minutes ago ago

    > He responded within minutes: "thank you! can you report it to our CTO and we will look at it immediately?"

    Why could he not speak to HIS ceo himself instead of asking Bob to

  • Ekaros 2 hours ago ago

    I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.

    • pc86 2 hours ago ago

      Sturgeon's Law is proved correct time and again. Most things are crap. Most people produce some crap in their lives. Some people only produce crap. Those people still need to eat but unfortunately some of them (somehow) find their way into tech and actually convince people to pay money for crap.

      Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.

      • noir_lord 2 hours ago ago

        Fortunately we have LLM's to not produce that crap... wait, those LLM's were trained on the existing crap and produce the same crap... oh no.

        • user43928 an hour ago ago

          I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it.

          And even if, a later "is this ready for release" will probably surface such obvious issues.

          I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.

          • wongarsu an hour ago ago

            However if you start current SOTA models out on a bad codebase they will happily write more bad code to fit in with the "conventions" of the existing code. Including authentication and isolation. If you start out your app on the wrong foot (for example because you lack the vocabulary to express what you need) you can end up with nicely polished turds

            Asking the LLM for a review of the code would still have caught it

          • skydhash an hour ago ago

            Still the six month wait time when everything should be good? /s

        • bonoboTP an hour ago ago

          They were RL trained on verifiable rewards. It's not purely learning to predict the next token of a human produced stream.

  • Aeroi an hour ago ago

    "Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "

    oof

  • Oras 2 hours ago ago

    Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it.

    Wasn't a dating app exposed this year with same negligence or firebase security?

    • asdf88990 6 minutes ago ago

      If something happens again and again, it is by choice. Firebase chooses to make it “easy” to get started rather than “secure by default”.

    • Cthulhu_ 34 minutes ago ago

      It's almost like people need knowledge and experience to work with tools securely. The problem with Firebase (I think) is that its marketing is "it's easy to use" and I'm confident most problems - like storing this info - is easy to figure out and finish, then move on to the next thing.

      But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.

  • sktb 2 hours ago ago

    Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.

    • Cthulhu_ 34 minutes ago ago

      In this case the CEO was aware of it and... did nothing.

  • SpaceL10n 2 hours ago ago

    Hmm, does Ukraine know that Russia is watching the Ministry of Digital Transformation's meetings?

  • usamaasfar an hour ago ago

    I'm starting to believe Firebase is cursed at this point.

  • nope1000 21 minutes ago ago

    To forget tenant isolation on one endpoint is bad enough but to ignore it for 6 months is madness. I am at a SaaS company and our customers have such strict security requirements for us and that is for less confidential data.

  • iJohnDoe 39 minutes ago ago

    I think this is one of the few times public disclosure wasn’t a good idea. Some of these are government meetings and could put lives in danger.

    Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.

  • brohee 13 minutes ago ago

    Now let's see if European users get their GDPR article 33 notification of the breach...

  • idiotsecant 2 hours ago ago

    Is this still active? I wouldn't mind spying on some meeting notes. Sounds fun.

    • mdrzn 2 hours ago ago

      If they haven't fixed it in 6 months, I'd say it's fair game to scrape as much as you can.

      • bpodgursky an hour ago ago

        I know this is a joke but it's still a felony, for your own sake don't do this.

    • blitzar 2 hours ago ago

      "Lets circle back and touch base to tease out any low hanging synergies we can capitalise on" - repeated 181,000 times

  • gyanchawdhary 2 hours ago ago

    This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.

    Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026

    PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..

    https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)

    https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)

    It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.

    • lostlogin an hour ago ago

      > 4TB/40,000 contractors voice + government ID + selfie leaked

      Leaked selfies? Do you mean ID photos?

      • zeroxfe an hour ago ago

        Selfies are used during live ID verification. (All of this is supposed to be encrypted, and destroyed within certain regulatory bounds.)

  • Aeroi 2 hours ago ago

    holy crap. how do you respond as CEO to this and not escalate to like priority #1?

    then kick the can for 6 months?

    • lostlogin an hour ago ago

      > how do you respond as CEO to this and not escalate to like priority #1? then kick the can for 6 months?

      We might be able to check the meeting minutes and get the answer?

    • root-parent an hour ago ago

      A post on LinkedIn where this CEO seems very active should solve that.

  • hluska 2 hours ago ago

    I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?

    • gossamer an hour ago ago

      As I see it he is not the one exposing clients to risk. He is frustrated that no one is fixing it. The company that left themselves open like this are the ones that are exposing their clients.

      If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.

    • Ekaros an hour ago ago

      Sometimes shame is only option to get things fixed. Sadly we do not have any reliable government institutions that could mandate immediate shut down of services. Before that only way to get things fixed is public shame.

    • root-parent an hour ago ago

      You need to read the article.

      • hluska an hour ago ago

        I read the entire article. Did you? There’s no reason in there to expose this company’s clients.

        Edit - Are you capable of answering my actual question or was that the best you could do?

        • charlieyu1 27 minutes ago ago

          I think it is fine, the person hasn't really leaked any critical information. He named a few clients that are mostly government departments, and it would be a public interest concern if said issue is ignored for 6 months anyway

        • mikestew an hour ago ago

          Read the article again, then. Anyone that has could get the list with a trivial amount of work. Security through obscurity isn’t going to hide that client list.

          And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”

        • root-parent an hour ago ago

          He has been emailing the CEO for six months with no replies. This is has also been posted here before with not a single pip or comment ... :-)

          And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.

          • Oras an hour ago ago

            Technical due diligence do not including pep test!

          • dpark an hour ago ago

            > And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.

            That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.

            • root-parent an hour ago ago

              >> They trusted a company that made a promise and that company let them down.

              That is a Boeing and Volkswagen type of excuse. The engineers did it!

    • masfuerte an hour ago ago

      What's the alternative? Seriously. He's spent six months trying to get them to fix it. The risk is already there.

  • seb1204 an hour ago ago

    So did he email privacy@tldv.io? Why not? Maybe someone who understands it would read it.

    • ncr100 an hour ago ago

      It's unclear. Only stating the existence of the privacy email.

      > [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]

      This is near the disclosure schedule

    • intended an hour ago ago

      From the article - he reached out to the CEO directly, who acknowledged and said it was being worked on by the CTO. He did this repeatedly over 6 months.