tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Exposed Without Protection
Key point
A Firestore misconfiguration on tl;dv exposed meeting metadata and some calls.
Details
Investigation revealed that the Firestore database of the AI meeting recording and transcription platform tl;dv lacked tenant isolation, allowing any authenticated user to view meeting information belonging to other accounts.
The exposed meeting records included the following information:
- Email addresses of meeting creators
- Google Meet and Teams meeting IDs
- Meeting provider and recording status
- Creation and recording timestamps
Meeting IDs with a status: recording could be collected in real time, and the author stated that they used this to join a Malaysia Ministry of Education meeting and startup meetings of US university students without invitation. The author claimed that approximately 1,000 ongoing meetings were exposed at the time.
In the meetings collection in Firestore, a total of 181,874 meeting records, 84,312 users, and 35,003 email domains were confirmed. Government domains were found in 23 countries, and the data also included meeting metadata from universities such as Berkeley and the University of Tokyo, as well as companies like Mitsui-Soko, HubSpot, and Confluent.
Upon further verification of 27,334 meeting IDs, the author found that over 1,000 of the normally private meetings were public, and 715 inviter emails belonging to 228 domains were also exposed.
The author reported the issue on January 28, 2026, but stated that six months later, at the time of writing, the Firestore database was still public and they had not received a response from the CTO.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.