跳到主内容
@wquguru
精选85Hacker News Best(web_list)行业动态

AI会议记录应用tl;dv泄露18万条录音,可实时闯入会议

Over 181,000 AI meeting recordings left wide open in note taking app

原文
发到 X
推荐理由

做AI会议/数据安全相关工作的同学必看,这是真实存在的租户隔离漏洞,暴露了AI应用数据保护的典型坑,建议立即检查自家Firestore/数据库的访问控制。

I reported this on January 28th, 2026. It is now July 2026. Six months later. The Firestore database is still wide open. The CTO never responded. I guess my emails were too long and they didn't view them.

我在2026年1月28日报告了此事。现在是2026年7月。六个月过去了。Firestore数据库仍然完全开放。CTO从未回应。我猜我的邮件太长了,他们没看。

What is tl;dv?

什么是tl;dv?

tl;dv (Too Long; Didn't View) is an AI meeting recording platform. It drops a bot into your Google Meet, Zoom, or Teams call, records everything, transcribes it, and generates summaries with AI. Over 2 million users. Backed by investors. Endorsed by half of LinkedIn's sales influencer community.

tl;dv(太长不看)是一个AI会议录制平台。它会在你的Google Meet、Zoom或Teams通话中放入一个机器人,录制所有内容,转录,并用AI生成摘要。拥有超过200万用户。有投资者支持。得到LinkedIn一半销售影响者社区的认可。

They store your sales calls, job interviews, performance reviews, internal strategy sessions. The kind of content where someone says "this call is being recorded" and everyone nervously laughs and then shares trade secrets for 45 minutes.

他们存储你的销售电话、求职面试、绩效评估、内部战略会议。那种内容,有人说“本次通话正在录音”,然后大家紧张地笑笑,接着分享45分钟的商业机密。

The Vulnerability

漏洞

When you sign up for tl;dv, the platform authenticates you with a JWT and exchanges it for a Firebase token via gw.tldv.io/v1/users/firebase/token. That token lets you query their Firestore database at projects/lmi-store/databases/(default).

当你注册tl;dv时,平台用JWT验证你,并通过gw.tldv.io/v1/users/firebase/token交换Firebase令牌。该令牌让你查询他们的Firestore数据库,位于projects/lmi-store/databases/(default)。

The meetings collection has no tenant isolation. Any authenticated tl;dv user can query every meeting across every account on the platform. Each meeting record hands you the creator's email address, the conference ID (which is a joinable Google Meet or Teams room), the provider, the recording status, and timestamps.

meetings集合没有租户隔离。任何经过身份验证的tl;dv用户都可以查询平台上所有账户的每个会议。每条会议记录都会给你创建者的电子邮件地址、会议ID(这是一个可加入的Google Meet或Teams房间)、提供商、录制状态和时间戳。

For meetings in recording status, that conference ID is a live, active call. You can watch the collection in real time, see a meeting start recording, grab the ID, and walk into someone's call uninvited. At any given time there are roughly 1,000 meetings with status: recording sitting in the collection. A thousand live calls with exposed conference IDs. An attacker with a bot could join all of them simultaneously.

对于处于录制状态的会议,该会议ID是一个实时的、活跃的通话。你可以实时观看集合,看到会议开始录制,抓取ID,然后不请自来地进入某人的通话。在任何给定时间,集合中大约有1000个状态为recording的会议。一千个实时通话,暴露了会议ID。一个拥有机器人的攻击者可以同时加入所有通话。

I Joined 2 Meetings

我加入了2个会议

I did it.

我做到了。

Grabbed a conference ID from Firestore and joined a live Google Meet belonging to the Malaysian Ministry of Education. A lady was presenting to over 157 participants. The tl;dv bot was already in the participant list. I was in the same call. Nobody invited me. The Firestore database did.

从Firestore抓取了一个会议ID,并加入了一个属于马来西亚教育部的实时Google Meet。一位女士正在向超过157名参与者演示。tl;dv机器人已经在参与者列表中。我在同一个通话中。没有人邀请我。是Firestore数据库邀请的。

I also joined a call where students from a major US university were building a startup app. 21 people in the call. They were screen-sharing their entire project, discussing prototypes, and, I kid you not, talking about how they needed to add client-side validation for .edu email addresses. They were also setting up Supabase live on screen, and all I could think was "please set up RLS policies" because most people don't, and then you end up like tl;dv.

我还参加了一个电话会议,会上美国一所主要大学的学生正在构建一个初创应用。电话会议中有21人。他们正在屏幕共享整个项目,讨论原型,而且,我没开玩笑,他们在讨论如何为.edu邮箱地址添加客户端验证。他们还在屏幕上实时设置Supabase,我满脑子想的都是“请设置RLS策略”,因为大多数人不这样做,然后你就会像tl;dv那样收场。

I wanted to say something so badly. "Hey, you might want server-side validation too." But this was a proof of concept, not a consultation.

我非常想说点什么。“嘿,你可能也需要服务器端验证。”但这只是一个概念验证,不是咨询。

The Scale

规模

I queried the Firestore meetings collection and saw there were 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains.

我查询了Firestore的meetings集合,发现有181,874条会议记录,属于84,312个唯一用户,分布在35,003个邮箱域名中。

Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. All .gov domains. Government employees recording calls on a platform that lets any free-tier user enumerate the whole thing.

来自23个国家的政府会议:巴西、哥伦比亚、秘鲁、乌克兰、萨尔瓦多、菲律宾、智利、印度尼西亚、墨西哥、美国、卡塔尔、马来西亚、乌兹别克斯坦、斯里兰卡、海地、南非、牙买加、洪都拉斯、阿根廷、泰国、日本、以色列和伯利兹。全部是.gov域名。政府员工在一个允许任何免费用户枚举整个数据库的平台上录制通话。

University meetings from Berkeley, the University of Tokyo, De La Salle, Universidad Nacional de Colombia. Dozens of .edu and .ac domains.

来自伯克利、东京大学、德拉萨大学、哥伦比亚国立大学等大学的会议。数十个.edu和.ac域名。

Corporate meetings from all 35,000 remaining domains. Mitsui-Soko (484 meetings across four regional offices), Mitsui Fudosan, HubSpot, Confluent, Mekari, AnyMind Group. Every company that ever used tl;dv had their meeting metadata in the same unprotected collection.

来自其余35,000个域名的企业会议。三井仓库(四个地区办事处共484次会议)、三井不动产、HubSpot、Confluent、Mekari、AnyMind集团。每个曾经使用过tl;dv的公司,他们的会议元数据都在同一个未受保护的集合中。

Peak month was July 2025 with 43,209 meetings. Busiest time slot: Wednesday at 2pm UTC, 7,804 meetings. Hump-day standup hour.

峰值月份是2025年7月,有43,209次会议。最繁忙的时间段:周三下午2点UTC,7,804次会议。周三的站立会议时间。

But Wait, There's More

但是等等,还有更多

I wanted to know how much actual content was accessible too, by default meetings are private (Meaning you cant watch the video or see the transcript), so I scraped 27,334 meeting IDs and checked which ones were public. Over 1,000 were. 715 invitee emails exposed across 228 domains.

我还想知道有多少实际内容可以访问,默认情况下会议是私有的(这意味着你不能观看视频或查看文字记录),所以我抓取了27,334个会议ID,并检查了哪些是公开的。超过1,000个是公开的。715个受邀者邮箱在228个域名中暴露。

Highlights: a Brazilian government conservation meeting (PACTO Mata Atlântica) with participants from WWF, The Nature Conservancy, Conservation International, WRI, and the São Paulo state government. Meetings from Ukraine's Ministry of Digital Transformation. A HubSpot sales call. Sessions involving Universidad Nacional de Colombia and Chile's Cámara Verde.

亮点:巴西政府保护会议(PACTO Mata Atlântica),参与者包括WWF、大自然保护协会、保护国际、世界资源研究所和圣保罗州政府。乌克兰数字化转型部的会议。HubSpot销售电话。涉及哥伦比亚国立大学和智利Cámara Verde的会议。

The Pasta Infrastructure

意大利面基础设施

tl;dv names their microservices after pasta. A subdomain scan reveals cappellini, carbonara, fusilli, pasta, penne, puttanesca-v0, and ravioli, all under tldv.io. An entire Italian restaurant worth of Express servers.

tl;dv 用意大利面名称来命名他们的微服务。子域名扫描发现 cappellini、carbonara、fusilli、pasta、penne、puttanesca-v0 和 ravioli,全部位于 tldv.io 下。一整个意大利餐厅的 Express 服务器。

Too Long; Didn't Score

太长不看;没得分

While exploring their subdomains I found https://worldcup.tldv.io. A FIFA World Cup 2026 vibecoded prediction game built on Base44 for tl;dv employees. It's called "World Cup Pick'em" and their internal squad is named "Too Long; Didn't Score." Cute.

在探索他们的子域名时,我发现了 https://worldcup.tldv.io。这是一个基于 Base44 为 tl;dv 员工构建的 2026 年 FIFA 世界杯预测游戏,名为“World Cup Pick'em”,他们的内部团队名为“Too Long; Didn't Score”。挺可爱的。

The Player entity API has zero authentication. GET /api/entities/Player returns every player record without a session cookie. 43 players. 19 @tldv.io employees with full names and corporate emails.

Player 实体 API 完全没有认证。GET /api/entities/Player 无需会话 cookie 即可返回所有玩家记录。43 名玩家,其中 19 名是 @tldv.io 员工,包含全名和公司邮箱。

Raphael Allstadt, my disclosure contact who gave vague reassurances and then went quiet, came in 2nd place with 298 points. His personal Gmail was also in the API response. Player #5 on the global leaderboard is "Super Duper CEO." I'll let you guess who that is.

Raphael Allstadt,我的披露联系人,他给了模糊的保证然后沉默了,以 298 分排名第二。他的个人 Gmail 也在 API 响应中。全球排行榜上的第 5 名是“Super Duper CEO”。你猜是谁。

The Prediction and Fixture entities are also wide open. A company that records millions of people's meetings vibecoded an internal fun app that leaks their own employee directory. The irony is al dente.

Prediction 和 Fixture 实体也完全开放。一家记录数百万人会议的公司,用 vibe coding 搞了个内部娱乐应用,却泄露了自己的员工目录。这讽刺意味十足。

Disclosure

披露

On January 28th I messaged Raphael Allstadt on LinkedIn and told him I'd found a huge vulnerability that leaks user data. He responded within minutes: "thank you! can you report it to our CTO and we will look at it immediately?" I sent the email. He said "thank you!" I asked about a reward. "My CTO will come back to you," he said.

1 月 28 日,我在 LinkedIn 上给 Raphael Allstadt 发消息,告诉他我发现了一个泄露用户数据的巨大漏洞。他几分钟内回复:“谢谢!你能向我们的 CTO 报告吗?我们会立即处理。”我发了邮件。他说“谢谢!”我问是否有奖励。他说:“我的 CTO 会联系你。”

The CTO never came back to me.

CTO 从未联系我。

January 29th: "your cto hasnt reached out yet btw and its not fixed." January 30th, Raphael: "I am sure the team is reviewing it very very soon ❤️" February 14th: "havent got an email and the vulnerability stilll works." Raphael: "He'll come back ☺️" I told him to maybe fix the vulnerability and not leave customers exposed. February 19th: "We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO."

1 月 29 日:“顺便说一句,你的 CTO 还没联系我,而且漏洞还没修复。”1 月 30 日,Raphael:“我相信团队很快就会审查的 ❤️”2 月 14 日:“没收到邮件,漏洞仍然有效。”Raphael:“他会来的 ☺️”我告诉他也许应该修复漏洞,不要让客户暴露在风险中。2 月 19 日:“我们正在处理。需要一些时间,但请放心,我们会跟进。如需进一步沟通,我建议联系我们的 CTO。”

The CTO who never responded. That CTO.

那个从未回应的 CTO。就是那个 CTO。

March 6th: "still not fixed." Seen by Raphael at 5:42 PM. No reply.

3 月 6 日:“仍未修复。”Raphael 在下午 5:42 已读。没有回复。

July 22nd: "still not fixed..." No reply.

7 月 22 日:“仍未修复……”没有回复。

Their security page is a trophy case. SOC2 compliant. GDPR compliant. EU AI Act compliant. Hosted in the EU. AES-256 encryption. A founder commitment video. Six compliance badges lined up in a row. Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at [email protected]. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. Their Firestore database has better uptime than their inbox.

他们的安全页面是一个奖杯陈列柜。SOC2 合规。GDPR 合规。欧盟 AI 法案合规。托管在欧盟。AES-256 加密。创始人承诺视频。六个合规徽章排成一排。埋在底部,有一行字:“如果您发现了我们应该解决的隐私或安全问题,请随时通过 [email protected] 告知我们。我们的安全团队将在 24 小时内回复。”我直接给 CTO 发了邮件。六个月。没有回复。他们的 Firestore 数据库的可用性都比他们的收件箱高。

DateWhat
Late January 2026Discovered Firestore tenant isolation bypass
January 28, 2026Reached out to Raphael Allstadt (LinkedIn) and emailed CTO + Raphael
January 29, 2026Raphael gives vague reassurance
February - March 2026Multiple follow-ups. CTO never responds.
July 2026Still not fixed. Still no response. Buon appetito.
日期事件
2026年1月下旬发现 Firestore 租户隔离绕过
2026年1月28日通过 LinkedIn 联系 Raphael Allstadt,并给 CTO 和 Raphael 发邮件
2026年1月29日Raphael 给出模糊的保证
2026年2月至3月多次跟进。CTO 从未回复。
2026年7月仍未修复。仍无回复。祝你好胃口。

To tl;dv

致 tl;dv

Your platform records people's most sensitive conversations. Job interviews. Sales negotiations. Government briefings. Your users trusted you with content they explicitly consented to record.

你们的平台记录人们最敏感的对话。求职面试。销售谈判。政府简报。你们的用户信任你们,把明确同意录制的内容托付给你们。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

关联信息,但可能不是同一事件