Tools
AI Minute Newsroom
2026-08-10
The AI notetaker in your meetings had no lock on the door: 181,874 meetings from 84,312 users were readable by anyone with an account
A security researcher published a disclosure on Monday showing that tl;dv, an AI meeting recorder with more than two million users, left its database open to every signed-in customer. The flaw was a missing Firestore security rule: when you logged in, tl;dv handed you a Firebase token that let you list the entire 'meetings' collection, with no separation between one company's data and another's. The researcher counted 181,874 meeting records covering 84,312 unique users across 35,003 email domains, including government meetings from 23 countries and a large number of schools and universities. Most of what leaked was metadata — creator email addresses, timestamps, recording status — but it also included conference IDs, which for roughly a thousand calls that were live at the time meant an outsider could simply join. Over a thousand meetings had fully public video and transcripts. A separate internal World Cup prediction app had no authentication at all and exposed 43 players, 19 of them named employees. The timeline is the worst part: the researcher reported it to tl;dv's chief executive and CTO on 28 January 2026, followed up repeatedly through March, and six months later the hole was still open. The company's CTO never replied.
Why it mattersMeeting recorders are the AI product that spread fastest without anyone deciding to adopt them. One participant installs a bot, and it sits in every call after that — hiring interviews, patient conversations, disciplinary meetings, parent-teacher calls, board discussions — recording people who never agreed to anything and often never noticed the join. That makes these tools a concentration of exactly the material an organisation would never put in a public folder, held by a startup whose security is nobody's procurement checkbox. Here the failure was not exotic. It was one missing database rule, the kind of mistake that takes an afternoon to fix, and it stayed unfixed for six months while the researcher kept emailing. The practical lesson is narrow and worth acting on today: whoever runs your accounts should check which notetakers have been authorised to join calls, and remove the ones nobody chose deliberately. The wider lesson is that a recording that exists somewhere is a recording someone else can eventually read.
✓ Verified · 3 sources
Read in the app — free, in 9 languages
Related stories
TikTok put a shopping chatbot inside the video you are watching.
2026-10-06Meta's assistant keeps an hourly file on everyone in your life.
2026-10-05One command restores the Apple Intelligence off switch Apple deleted.
2026-10-05OpenAI will ship a Codex upgrade daily for 28 days or reset limits.
2026-10-05Meta open-sourced the firmware for building your own Muse gadget.
2026-10-04