It's hilarious how these companies handle security breaches.
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal.
I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.
Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.
At a few companies I've worked at, they squelch this kind of bug/security breach reporting by immediately making it the discoverer's job to fix the problem and champion it through the system to production, taking on all responsibility if something breaks of course. You only have to go through that once to get the message.
More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.
If a civil engineer made a negligent mistake that bad which "made it to production", rather than being caught before the structure collapsed, he would spend a decade in prison for negligent homicide.
The entire reason the company was funded is the US government started enforcing FCRA compliance on 1099 Uber drivers.
So the government did get involved and regulated Uber and the entire gig economy, and the private sector is so powerful they just made their own background check company with hundreds of millions of dollars in VC and hype, gave them Uber as their flagship customer and wiped their hands.
No doubt in my mind these people were "just happy to be here" at best, criminals at worst, and have no business working with PII and background checks. Founders and everyone there.
But I still think the company should be found liable, not an individual engineer. They would be a lot more incentivized to hire based on merit, and not incentivized to literally be corrupt like they are now.
With your idea of punishing the engineer... these VCs would love that. Shift even more blame onto the worker, why not, we've taken it for everything else
Software lost that status in the vibe coding era. It's an art form now, not necessarily something worse or easier, just different than engineering. But probably not the career path anymore for those who prefered math over philosophy in college.
It was this way well before vibe coding. Over a decade of zero interest rates combined with talent wars and other anticompetitive behaviors by large tech companies did the industry in.
Software never had that status. I was disgusted by the decline I could see in the 90s even, and I was a teenager, I had no clue and still don't. I cannot imagine how it must be for people who do have a clue. They're probably all drinking.
> I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time.
In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.
Idk licensing and regulation sounds like involving more institutional arrogance.
We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doing.
Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing. People who have done it a thousand times should get that job, not some dumb kid who just got out of school.
this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.
As a cybersecurity practitioner, regulation and oversight is the only incentive that moves the needle in my experience. If there are no costs or negative outcomes for not caring about security, security will not be prioritized. Big fan of SEC Breach Reporting via Form 8-K, as well as state reporting requirements.
> Idk licensing and regulation sounds like involving more institutional arrogance.
Well it works. Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on a modern ship is a pretty rare thing to happen (either as employee or passenger) if you contrast it with the situation just five decades or so ago.
> We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
Degree mills aren't the kind of gatekeeping I'm talking about. If you screw up, you still can go to another company and continue screwing up there, which also means there is barely any incentive to hold education institutions accountable to deliver good education. In the regulated trades however? Screw up enough and you're out for good.
> Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing.
Commercial aviation involves other people's lives in real-time. I put that more like being a lifeguard or EMT.
Recreational aviation has a lot less regulation. I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
Shouldn't need a license to make React components, sorry.
But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
On a personal note, I recognize that I should have kept the researcher updated after his initial outreach earlier this year, and I take full responsibility for that communication gap.
They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period?
Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.
I saw an YouTuber the other day sharing their "day in the life" as an Amazon Software Engineer while promoting (as part of a paid sponsorship) the AI note taking feature of SoundCore headphones, claiming they now record their meetings and receive an AI summary at the end.
I wonder how many companies realise these new devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then security.
Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.
I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem.
The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
Thank you, great question! Hard one to answer, thought about it a lot and it's going to be the diarisation of more than 5+ speakers per audio stream (your microphone + system audio for a max of 10). I actually spent a lot of time that went completely nowhere trying to fine tune my own diarisation model, it was fun to a degree but painful to see my output end up worse than what I currently had after days of work. Having a bot join the call would be such an easy way of diarising, the call software has already done it for you, but feels like a bit of a cop out.
Two more improvements, audio quality improvements which is currently in the works and close to release and a new document generation model. I'm currently using a custom fine tuned Phi-4 (released December 2024!) model, that's _so old_ in the grand scheme of LLMs, I just haven't had time to benchmark and properly test some new models whilst this currently does a good job as it is. There has to be some gains here, but who knows!
Drafts.app is hideous but it has great routing capability and a dictation feature.
I use it to capture what my thoughts and route based on content.
I have a button that routes to an internal voice agent named KiKo.
Ideas get routed to Things or todoist.
Issues get routed to github, etc.
It’s one universal surface for note capture.
My ideal use case is to pipe audio from both my microphone and capture system audio so things like our weekly team standup or my 1:1s with my devs can all have reliable, decent notes without taking me out of the flow of the conversation.
I think clearly the _leader_ in the space is granola, but I'm just not going to use a cloud provider for this.
"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "
This breach will help with tl;dv's awareness. More people will suddenly become aware of it. The downside is that less private conversations will be hooked up to tl;dv, and more public seminars will be fed instead. This is a win-win overall. And it is a PSA to all other companies to secure their servers a little bit better.
I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.
Sturgeon's Law is proved correct time and again. Most things are crap. Most people produce some crap in their lives. Some people only produce crap. Those people still need to eat but unfortunately some of them (somehow) find their way into tech and actually convince people to pay money for crap.
Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.
However if you start current SOTA models out on a bad codebase they will happily write more bad code to fit in with the "conventions" of the existing code. Including authentication and isolation. If you start out your app on the wrong foot (for example because you lack the vocabulary to express what you need) you can end up with nicely polished turds
Asking the LLM for a review of the code would still have caught it
I love the never-ending "SOTA" treadmill used to defend anything and everything these LLM tools shit up. Doesn't matter what happens, it wasn't one of the "SOTA" models (which changes every 7 seconds) ergo it's irrelevant, how very convenient for the AI pushers!
Can someone give me exact time when SOTA stop being good? Is it a day, week or a month? As such can I consider anything older than that time period to automatically be crap?
It's almost like people need knowledge and experience to work with tools securely. The problem with Firebase (I think) is that its marketing is "it's easy to use" and I'm confident most problems - like storing this info - is easy to figure out and finish, then move on to the next thing.
But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.
Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.
The worst part of these AI meeting notes and recordings is that I have literally never seen anybody, in any situation, go back to them. The (very) few times I ever bothered to check the transcripts and especially the summaries immediately after a meeting, without fail they'd have something in them that is the complete opposite of what someone said in the meeting, or they'd miss extremely important clarifications or context. Literally worse than useless, actively detrimental, but you bet your ass whichever moron forced these to be on for every meeting is putting it on their resume - "Increased long-term organizational cohesiveness via comprehensive automated meeting notes" or whatever type of bullshittery.
OK, the issue sucks. That said, the post was written by an LLM and It's not pleasant to read. If I didn’t work with Claude every day, I might feel differently, but because I do, this reads like slop.
To forget tenant isolation on one endpoint is bad enough but to ignore it for 6 months is madness. I am at a SaaS company and our customers have such strict security requirements for us and that is for less confidential data.
This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.
PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..
> tl;dv names their microservices after pasta. A subdomain scan reveals cappellini, carbonara, fusilli, pasta, penne, puttanesca-v0, and ravioli, all under tldv.io. An entire Italian restaurant worth of Express servers.
Pretty appropriate, given a vulnerability of this severity. Literal microservice spaghetti.
(Also, please, let's all move back to boring names for services and servers. Nobody likes trying to decode what all these silly names mean.)
EDIT:
omg, the disclosure communication is infuriating.
> We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO
This should have been a P1 that was fixed same day, and they strung him along for months. Absolute amateurs.
"Because the common denominator between both of these distinct incidents was Firebase, we are taking the additional step of immediately removing it from our tech stack altogether to definitively eliminate the risk of similar vulnerabilities in the future." - from their post-mortem.
Thank god the root cause was definitively identified! /s
I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
As I see it he is not the one exposing clients to risk. He is frustrated that no one is fixing it. The company that left themselves open like this are the ones that are exposing their clients.
If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.
Read the article again, then. Anyone that has could get the list with a trivial amount of work. Security through obscurity isn’t going to hide that client list.
And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”
I think it is fine, the person hasn't really leaked any critical information. He named a few clients that are mostly government departments, and it would be a public interest concern if said issue is ignored for 6 months anyway
He has been emailing the CEO for six months with no replies. This is has also been posted here before with not a single pip or comment ... :-)
And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
> And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.
Sometimes shame is only option to get things fixed. Sadly we do not have any reliable government institutions that could mandate immediate shut down of services. Before that only way to get things fixed is public shame.
It's unclear. Only stating the existence of the privacy email.
> [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]
From the article - he reached out to the CEO directly, who acknowledged and said it was being worked on by the CTO. He did this repeatedly over 6 months.
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.
Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.
At these types of startups, developers will find themselves in some debate about the time complexity of a click handler (which is debounced anyway).
Meanwhile Joe CEO is like "HAY GUYS" -drops db-
"CAN U FIX IT BY MONDAY"
https://www.constructiondive.com/news/contractors-sentenced-...
https://www.reddit.com/r/AskEngineers/comments/cjpva1/is_it_...
https://www.monitor.co.ug/uganda/oped/commentary/it-s-a12-ye...
So the government did get involved and regulated Uber and the entire gig economy, and the private sector is so powerful they just made their own background check company with hundreds of millions of dollars in VC and hype, gave them Uber as their flagship customer and wiped their hands.
No doubt in my mind these people were "just happy to be here" at best, criminals at worst, and have no business working with PII and background checks. Founders and everyone there.
But I still think the company should be found liable, not an individual engineer. They would be a lot more incentivized to hire based on merit, and not incentivized to literally be corrupt like they are now.
With your idea of punishing the engineer... these VCs would love that. Shift even more blame onto the worker, why not, we've taken it for everything else
The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time.
In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.
We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doing.
Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing. People who have done it a thousand times should get that job, not some dumb kid who just got out of school.
How could there be?
Evolution can’t disprove the existence of God.
Otherwise, you can't prove that you don't still owe me $10 million from that time we went to the pink elephant show in outer space.
Bro you can't prove it wasn't a great show and that you didn't have a great time.
Lmk if you need my Venmo
https://www.sec.gov/newsroom/speeches-statements/gerding-cyb...
https://www.ncsl.org/technology-and-communication/security-b...
Well it works. Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on a modern ship is a pretty rare thing to happen (either as employee or passenger) if you contrast it with the situation just five decades or so ago.
> We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
Degree mills aren't the kind of gatekeeping I'm talking about. If you screw up, you still can go to another company and continue screwing up there, which also means there is barely any incentive to hold education institutions accountable to deliver good education. In the regulated trades however? Screw up enough and you're out for good.
> Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing.
Trades licensing is merit based.
Recreational aviation has a lot less regulation. I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
Shouldn't need a license to make React components, sorry.
Only on the bottom end. People with zero merit get forced out - eventually in most cases. However a lot of people who have merit are not allowed in.
But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
[1] https://tldv.io/features/security-commitment/
Just email the CTO about it ;)
They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period?
Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.
I wonder how many companies realise these new devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then security.
The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
It's a hard problem I've been working away on for a while now. It's far from perfect but every step brings it a bit closer.
Two more improvements, audio quality improvements which is currently in the works and close to release and a new document generation model. I'm currently using a custom fine tuned Phi-4 (released December 2024!) model, that's _so old_ in the grand scheme of LLMs, I just haven't had time to benchmark and properly test some new models whilst this currently does a good job as it is. There has to be some gains here, but who knows!
But man is it ugly.
I think clearly the _leader_ in the space is granola, but I'm just not going to use a cloud provider for this.
Drafts have anything like that?
oof
Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.
And even if, a later "is this ready for release" will probably surface such obvious issues.
I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.
Asking the LLM for a review of the code would still have caught it
Why could he not speak to HIS ceo himself instead of asking Bob to
Wasn't a dating app exposed this year with same negligence or firebase security?
But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.
Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.
Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026
PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..
https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)
https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)
It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.
Leaked selfies? Do you mean ID photos?
Pretty appropriate, given a vulnerability of this severity. Literal microservice spaghetti.
(Also, please, let's all move back to boring names for services and servers. Nobody likes trying to decode what all these silly names mean.)
EDIT:
omg, the disclosure communication is infuriating.
> We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO
This should have been a P1 that was fixed same day, and they strung him along for months. Absolute amateurs.
then kick the can for 6 months?
We might be able to check the meeting minutes and get the answer?
Thank god the root cause was definitively identified! /s
If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.
Edit - Are you capable of answering my actual question or was that the best you could do?
And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”
And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.
That is a Boeing and Volkswagen type of excuse. The engineers did it!
> [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]
This is near the disclosure schedule