The Extended Brief
Over 181,000 AI meeting recordings left wide open in note taking app

Brief by The AI News AI newsroom · Aug 10, 2026, 12:12 PM EDT edition
Original reporting by Hacker News · published Aug 10, 2026, 8:26 AM EDT
A researcher says tl;dv's open database lets any user read 181,874 meeting records and grab live conference IDs for roughly 1,000 in-progress calls.
Key points
- Researcher BobDaHacker says any authenticated tl;dv user can query all 181,874 meeting records across every account. source ↗
- The meetings collection lacks tenant isolation, exposing creator emails, providers, timestamps, and joinable conference IDs. source ↗
- Roughly 1,000 meetings show recording status at any time, meaning their exposed conference IDs are live calls. source ↗
- BobDaHacker reports disclosing the flaw on January 28, 2026, with the database still open six months later. source ↗
- The researcher says he joined two meetings using grabbed conference IDs, and that tl;dv's CTO never responded. source ↗
The data
181,874
tl;dv meeting records the researcher says any authenticated user could query
Roughly 1,000 meetings show recording status at any given time.
Jan 28, 2026
BobDaHacker reports the open Firestore database to tl;dv
Jul 2026
Researcher says database still open; CTO never responded
Aug 4, 2026
Findings published publicly
Numbers from the original article, machine-verified against its text
Practical applications
- If your organization uses tl;dv, treat meeting metadata and conference IDs as public and pause recording of sensitive calls until a fix is confirmed.
- Audit your own Firebase deployments' Firestore security rules for per-tenant isolation, especially on collections storing join links or user identifiers.
- Enable waiting rooms or passcodes on Meet and Teams so a leaked conference ID alone does not admit an uninvited guest.
Context
tl;dv is an AI meeting-notetaking service with over 2 million users that joins Google Meet, Zoom, and Teams calls to record, transcribe, and summarize them. It stores data in Google Firestore, where security rules are meant to restrict each user to their own organization's records; the researcher reports that isolation is missing.
What to watch
- A tl;dv response or Firestore rules change; the researcher's simple re-query of the meetings collection would confirm a fix.
- Regulator or customer fallout, given the exposed content includes job interviews, performance reviews, and strategy sessions.
Related briefs
- OpenAI agents attacked RubyGems back in May
- Claude users found ways around safeguards for bioweapons research
- Anthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI Attack
- Congress Pushes AI Agents Into the Audit Trail
Editorial score 4.0 / 5 · significance 4.0 · novelty 4.0 · edge 4.0 · perspective 4.0
Topics: Cybersecurity · Enterprise AI
Evidence basis: Reviewed from the article's full text
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.