conv.

All stories
SecurityRunning 2d

tl;dv AI Meeting Platform Leaves 181,874 Meetings Exposed for 6 Months

Researcher reports Firestore database vulnerability allowing unauthenticated access to government, corporate, and university calls; company disputes severity.

Conversation activity · last 4 days peak 3/hr

Peak 3 items in one hour at Aug 6, 12 PM; 41 items over 4 days Aug 6, 6 AM — 1 itemAug 6, 7 AM — 1 itemAug 6, 8 AM — no itemsAug 6, 9 AM — 3 itemsAug 6, 10 AM — 3 itemsAug 6, 11 AM — 2 itemsAug 6, 12 PM — 3 itemsAug 6, 1 PM — 1 itemAug 6, 2 PM — no itemsAug 6, 3 PM — 1 itemAug 6, 4 PM — no itemsAug 6, 5 PM — 2 itemsAug 6, 6 PM — no itemsAug 6, 7 PM — 2 itemsAug 6, 8 PM — no itemsAug 6, 9 PM — no itemsAug 6, 10 PM — no itemsAug 6, 11 PM — no itemsAug 7, 12 AM — no itemsAug 7, 1 AM — 1 itemAug 7, 2 AM — 2 itemsAug 7, 3 AM — 1 itemAug 7, 4 AM — 2 itemsAug 7, 5 AM — 1 itemAug 7, 6 AM — 2 itemsAug 7, 7 AM — 2 itemsAug 7, 8 AM — no itemsAug 7, 9 AM — no itemsAug 7, 10 AM — no itemsAug 7, 11 AM — 4 itemsAug 7, 12 PM — no itemsAug 7, 1 PM — no itemsAug 7, 2 PM — 1 itemAug 7, 3 PM — no itemsAug 7, 4 PM — 1 itemAug 7, 5 PM — no itemsAug 7, 6 PM — no itemsAug 7, 7 PM — no itemsAug 7, 8 PM — 1 itemAug 7, 9 PM — no itemsAug 7, 10 PM — no itemsAug 7, 11 PM — no itemsAug 8, 12 AM — no itemsAug 8, 1 AM — no itemsAug 8, 2 AM — no itemsAug 8, 3 AM — no itemsAug 8, 4 AM — no itemsAug 8, 5 AM — no itemsAug 8, 6 AM — no itemsAug 8, 7 AM — no itemsAug 8, 8 AM — no itemsAug 8, 9 AM — no itemsAug 8, 10 AM — no itemsAug 8, 11 AM — no itemsAug 8, 12 PM — no itemsAug 8, 1 PM — no itemsAug 8, 2 PM — 1 itemAug 8, 3 PM — no itemsAug 8, 4 PM — no itemsAug 8, 5 PM — no itemsAug 8, 6 PM — no itemsAug 8, 7 PM — no itemsAug 8, 8 PM — no itemsAug 8, 9 PM — no itemsAug 8, 10 PM — no itemsAug 8, 11 PM — no itemsAug 9, 12 AM — no itemsAug 9, 1 AM — 1 itemAug 9, 2 AM — 1 itemAug 9, 3 AM — 1 itemAug 9, 4 AM — no itemsAug 9, 5 AM — no itemsAug 9, 6 AM — no itemsAug 9, 7 AM — no itemsAug 9, 8 AM — no itemsAug 9, 9 AM — no itemsAug 9, 10 AM — no itemsAug 9, 11 AM — no itemsAug 9, 12 PM — no itemsAug 9, 1 PM — no itemsAug 9, 2 PM — no itemsAug 9, 3 PM — no itemsAug 9, 4 PM — no itemsAug 9, 5 PM — no itemsAug 9, 6 PM — no itemsAug 9, 7 PM — no itemsAug 9, 8 PM — no items 3 items · 12 PM
Aug 7Aug 8Aug 9

Summary, timeline and people extracted by Claude from 41 items across 1 source · 8h ago. Quotes are verbatim.

Security researcher BobDaHacker reported a critical vulnerability in tl;dv's Firebase configuration on January 28, 2026, allowing any authenticated user to access metadata for 181,874 meetings across 84,312 users and 35,003 domains, including government agencies from 23 countries and major universities. Six months later in July 2026, the vulnerability remained active. tl;dv's CTO disputed the severity, claiming the issue was resolved and that accessing the data required technical sophistication, contradicting the researcher's documentation of easily querying the Firestore database and joining live government and university calls uninvited.

  • tl;dv left 181,874 meetings exposed for six months after initial vulnerability report, with access to metadata from government agencies across 23 countries, major universities, and corporations.
  • Researcher successfully joined live government and university calls uninvited by querying the unprotected Firestore database, proving the vulnerability was easily exploitable without sophisticated attacks.
  • tl;dv's CTO ignored the initial report and later disputed severity claims, stating the issue was resolved and required technical sophistication—contradicted by documented evidence the vulnerability remained active and easily accessible.

How it unfolded

  1. Reaction tl;dv downplays vulnerability by industry normalization

    Company compares incident to similar issues at Anthropic, Zoom, and Lovable, framing as a UX problem rather than a security failure.

  2. Analysis Community analysis: gaslighting and false remediation claims

    Lobsters commenter notes tl;dv's claim of resolution contradicts the documented fact that the exploit worked six months after the initial report and immediate fix claim.

  3. Reaction Lobsters discussion: tl;dv company response questioned

    Commenters point to tl;dv's Dark Reading response claiming the issue was 'resolved shortly after' reporting, contradicting evidence the vulnerability remained active after six months.

  4. Report Full vulnerability report published on Lobsters

    BobDaHacker publishes detailed technical post documenting the exposure, including meetings from government agencies across 23 countries, universities, and major corporations.

  5. 5 weeks quiet
  6. Event Vulnerability confirmed still active six months later

    BobDaHacker verifies the Firestore database remains unpatched, discovers 181,874 meeting records across 84,312 users from 35,003 domains, and successfully joins two live calls without invitation.

  7. 22 weeks quiet
  8. Event BobDaHacker reports vulnerability to tl;dv

    Security researcher reports that tl;dv's Firestore database lacks tenant isolation, allowing any authenticated user to enumerate all meetings across the platform.

What people are saying verbatim

“I reported this on January 28th, 2026. It is now July 2026. Six months later. The Firestore database is still wide open. The CTO never responded.”

BobDaHacker · bobdahacker.com blog / Lobsters

“Grabbed a conference ID from Firestore and joined a live Google Meet belonging to the Malaysian Ministry of Education. A lady was presenting to over 157 participants.”

BobDaHacker · bobdahacker.com blog / Lobsters

“The issue was resolved shortly after. As part of our immediate fix, we have fully secured this access point to ensure meeting URLs can no longer be obtained this way.”

tl;dv CTO · tl;dv blog (cited on Lobsters)

“The exploit works 6 months later but it was 'resolved' shortly after being reported?”

stephenr, Lobsters commenter · Lobsters

“reaching it required specific programmatic actions by an technically versed hacker.”

tl;dv · Dark Reading article (cited on Lobsters)

Voices from the web unedited

  • As a note, BobDaHacker uses [she/they pronouns](https://bobdahacker.com/), and is being consistently misgendered by tl;dv (though the [darkreading.com article](https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls) correctly uses they/them). Hopefully lobste.rs can be an exception and use her correct…

    novedevoprivacy,security3d ago72▲view on Lobsters ↗
  • Remember when companies had dedicated ops/infra teams that were specifically in charge of things like managing access to services, and developers would complain that it's too slow to wait for another team to provision a database for them? Pepperidge farm remembers.

    stephenrprivacy,security3d ago58▲view on Lobsters ↗
  • > reaching it required specific programmatic actions by an technically versed hacker. It’s a variant of Ye Olde claim of a “super sophisticated attack” when the attacker was simply adjusting URLs by incrementing numbers.

    sjamaanprivacy,security3d ago45▲view on Lobsters ↗
  • > which one would you pick? let's see >Even for those affected public meetings, content was not surfaced through tl;dv’s normal browsing or search: reaching it required specific programmatic actions by an technically versed hacker. it's B and C.

    kwasprivacy,security3d ago39▲view on Lobsters ↗
  • https://tldv.io/blog/our-thoughts-on-the-darkreading-com-article/ <- company response options: - The hacker guy is inventing things - This CTO is gaslighting his customers - Something in between (did they not understand the report?) which one would you pick?

    yoelcaboprivacy,security3d ago34▲view on Lobsters ↗
  • I'd imagine B is doing the heavy lifting here. They acknowledge that the report happened, they don't *directly* dispute anything he claimed, and the wording used around their *response* to the breach (whether from the pen tester in question or this mysterious other organisation that's never named) sounds quite bizarre to me. > The issue was…

    stephenrprivacy,security3d ago28▲view on Lobsters ↗
  • > The vulnerable data was strictly limited to metadata: meeting identifiers, conference IDs (the links used to join Google Meet or Microsoft Teams calls) and participant email addresses and domains. > > … the exposed data did not include highly sensitive personal data lol

    altanoprivacy,security3d ago27▲view on Lobsters ↗
  • > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Lovable and Zoom have both worked through cases where user-configured public settings produced broader visibility than users had anticipated. It…

    cflewisprivacy,security3d ago26▲view on Lobsters ↗
  • Sentences like "Over 2 million users. Backed by investors. Endorsed by half of LinkedIn's sales influencer community." do it for me, I can't finish reading the article even if it really was human-written.

    janiczekprivacy,security3d ago22▲view on Lobsters ↗
  • What immediately sends me into a white-hot rage is the way the general public and the media simply accepts blaming of every such incident on "hackers" as a universal excuse. Hacking is viewed as a force of nature that nobody can do anything about, not as sheer incompetence of businesses taking upon themselves the task of keeping user data. And no…

    isagalaevprivacy,security3d ago19▲view on Lobsters ↗