Tl;dv: Over 180k meetings left wide open
Points and comments are a snapshot, not live.
A security researcher found tl;dv's Firestore database exposed 181,874 meetings to any authenticated user.
The tl;dv AI meeting recording platform left its Firestore `meetings` collection without tenant isolation. Any authenticated user could query all meetings across every account, including live calls. The researcher joined a Malaysian Ministry of Education meeting and a university startup call. Over 181,874 meeting records belonging to 84,312 users across 35,003 email domains were accessible, including government meetings from 23 countries. The CTO never responded to disclosures over six months. The researcher also found tl;dv's internal World Cup prediction app, `worldcup.tldv.io`, had no authentication, leaking employee names and emails.
The company claims SOC2 and GDPR compliance.
What commenters are saying
Commenters were stunned that the vulnerability remained open for six months despite the CEO being aware of it. Several noted this is a common pattern with Firebase, blaming its "easy to start" marketing for leading to insecure defaults. Some defended the blog's decision to name clients, arguing the company's negligence made the risk public already. A voice phishing company commented that this exact type of leak provides attackers with audio samples for deepfake attacks. One commenter questioned the ethics of exposing clients' names in the write-up.