aiminute. ← All AI news
Tools 2026-08-10

The AI notetaker in your meetings had no lock on the door: 181,874 meetings from 84,312 users were readable by anyone with an account

The AI notetaker in your meetings had no lock on the door: 181,874 meetings from 84,312 users were readable by anyone with an account

A security researcher published a disclosure on Monday showing that tl;dv, an AI meeting recorder with more than two million users, left its database open to every signed-in customer. The flaw was a missing Firestore security rule: when you logged in, tl;dv handed you a Firebase token that let you list the entire 'meetings' collection, with no separation between one company's data and another's. The researcher counted 181,874 meeting records covering 84,312 unique users across 35,003 email domains, including government meetings from 23 countries and a large number of schools and universities. Most of what leaked was metadata — creator email addresses, timestamps, recording status — but it also included conference IDs, which for roughly a thousand calls that were live at the time meant an outsider could simply join. Over a thousand meetings had fully public video and transcripts. A separate internal World Cup prediction app had no authentication at all and exposed 43 players, 19 of them named employees. The timeline is the worst part: the researcher reported it to tl;dv's chief executive and CTO on 28 January 2026, followed up repeatedly through March, and six months later the hole was still open. The company's CTO never replied.

Why it mattersMeeting recorders are the AI product that spread fastest without anyone deciding to adopt them. One participant installs a bot, and it sits in every call after that — hiring interviews, patient conversations, disciplinary meetings, parent-teacher calls, board discussions — recording people who never agreed to anything and often never noticed the join. That makes these tools a concentration of exactly the material an organisation would never put in a public folder, held by a startup whose security is nobody's procurement checkbox. Here the failure was not exotic. It was one missing database rule, the kind of mistake that takes an afternoon to fix, and it stayed unfixed for six months while the researcher kept emailing. The practical lesson is narrow and worth acting on today: whoever runs your accounts should check which notetakers have been authorised to join calls, and remove the ones nobody chose deliberately. The wider lesson is that a recording that exists somewhere is a recording someone else can eventually read.

✓ Verified · 3 sources

WhatsApp X Telegram
Read in the app — free, in 9 languages

Related stories

Apple Music will tell you when a song was made by a machine — but the uploader decides whether to say so
2026-08-21
Stripe has just paid $7.5 billion for a model router. Days later Ramp built one and is giving it away until January.
2026-08-21
Meta's assistant is now a Mac app that reads your screen and types into any window — and what it sees can train the model
2026-08-21
One click on a news site now tells Google to show you more of it — and you stay on the page you were reading
2026-08-21
Adobe will now generate the music, the voiceover and the door slam — and it says the licence covers you
2026-08-21