메뉴
HN
Hacker News • 46일 전

AI 회의 녹화 앱에서 18만 건 이상의 회의 기록이 노출

IMP
9/10
핵심 요약

인기 AI 회의 녹화 플랫폼인 tl;dv에서 심각한 데이터베이스 접근 통제 결함이 발견되었습니다. 이 취약점으로 인해 모든 사용자가 다른 사용자들의 비공개 회의 메타데이터와 진행 중인 회의실 ID를 무단으로 조회할 수 있었습니다. 전 세계 정부 기관, 주요 대학, 글로벌 기업의 민감한 회의 정보 18만 건 이상이 완전히 노출된 심각한 보안 사고입니다.

번역된 본문

나는 이 문제를 2026년 1월 28일에 처음 보고했다. 이제 2026년 7월이다. 6개월이 지났다. 하지만 Firestore 데이터베이스는 여전히 활짝 열려 있다. CTO는 단 한 번도 답장하지 않았다. 내가 보낸 이메일이 너무 길어서 읽지 않은 모양이다.

tl;dv는 무엇인가? tl;dv(Too Long; Didn't View)는 AI 회의 녹화 플랫폼이다. 구글 미트(Google Meet), 줌(Zoom), 팀즈(Teams) 통화에 봇을 투입해 모든 것을 녹화하고, 텍스트로 변환한 뒤 AI로 요약본을 생성한다. 사용자는 200만 명이 넘는다. 투자자들의 지원을 받았으며, 링크드인 영업 인플루언서 커뮤니티 절반의 추천을 받았다. 이들은 당신의 영업 통화, 취업 면접, 인사 평가, 내부 전략 회의를 저장한다. 바로 누군가 "이 통화는 녹음되고 있습니다"라고 말하면 모두가 불안하게 웃으면서 45분 동안 영업 비밀을 공유하는 바로 그런 콘텐츠 말이다.

취약점 tl;dv에 가입하면 플랫폼은 JWT로 사용자를 인증하고 gw.tldv.io/v1/users/firebase/token을 통해 Firebase 토큰으로 교환한다. 해당 토큰을 통해 projects/lmi-store/databases/(default)의 Firestore 데이터베이스를 쿼리할 수 있다. 문제는 meetings 컬렉션에 테넌트 격리(tenant isolation)가 전혀 없다는 것이다. 인증된 tl;dv 사용자라면 누구나 플랫폼 전체의 모든 계정에 걸친 모든 회의를 쿼리할 수 있다. 각 회의 기록에는 생성자의 이메일 주소, 회의 ID(참여 가능한 구글 미트 또는 팀즈 룸), 제공자, 녹화 상태 및 타임스탬프가 그대로 노출된다. 현재 녹화 중인 상태의 회의라면, 그 회의 ID는 실시간으로 진행 중인 통화를 의미한다. 실시간으로 컬렉션을 지켜보다가 회의가 녹화를 시작하면 ID를 가로채서 초대받지 않은 채 다른 사람의 통화에 들어갈 수 있다. 언제든지 이 컬렉션에는 상태가 'recording'인 회의가 대략 1,000개 정도 존재한다. 노출된 회의 ID를 가진 실시간 통화 1,000개다. 봇을 보유한 공격자는 이 모든 통화에 동시에 참여할 수 있다.

내가 직접 2개의 회의에 참여해봤다 나는 실제로 해보았다. Firestore에서 회의 ID를 가로채 말레이시아 교육부 소속의 실시간 구글 미트에 들어갔다. 한 여성이 157명 이상의 참가자에게 프레젠테이션을 하고 있었다. 참가자 명단에는 이미 tl;dv 봇이 있었다. 나 역시 같은 통화에 있었다. 아무도 나를 초대하지 않았다. Firestore 데이터베이스가 나를 초대한 것이다. 또한 미국의 한 명문 대학 학생들이 스타트업 앱을 개발하는 회의에도 참여했다. 21명이 통화에 있었다. 이들은 화면을 공유해 전체 프로젝트를 보여주며 프로토타입을 논의하고 있었고, 농담이 아니라 .edu 이메일 주소에 대한 클라이언트 측 검증(client-side validation)을 추가해야 한다고 이야기하고 있었다. 게다가 화면에서 실시간으로 Supabase를 세팅하고 있었는데, 내 머릿속에 떠오른 생각은 오직 '제발 RLS 정책을 설정해라'였다. 왜냐하면 대부분의 사람들이 그렇게 하지 않아 결국 tl;dv처럼 되기 때문이다. 나는 '혹시 서버 측 검증도 필요할 겁니다'라고 말하고 싶어 미칠 지경이었다. 하지만 이는 컨설팅이 아니라 취약점 개념 증명(Proof of Concept)일 뿐이었다.

규모 나는 Firestore의 meetings 컬렉션을 쿼리하여 35,003개의 이메일 도메인에 걸쳐 84,312명의 고유 사용자에게 속한 181,874개의 회의 기록이 있는 것을 확인했다.

  • 23개국 정부 회의: 브라질, 콜롬비아, 페루, 우크라이나, 엘살바도르, 필리핀, 칠레, 인도네시아, 멕시코, 미국, 카타르, 말레이시아, 우즈베키스탄, 스리랑카, 아이티, 남아프리카 공화국, 자메이카, 온두라스, 아르헨티나, 태국, 일본, 이스라엘, 벨리즈. 모두 .gov 정부 도메인이다. 정부 직원들이 무료 사용자조차 모든 것을 조회할 수 있는 플랫폼에서 통화를 녹화한 것이다.
  • 버클리, 도쿄대, 라 살, 콜롬비아 국립대 등 주요 대학 회의. 수십 개의 .edu 및 .ac 도메인.
  • 나머지 35,000개의 모든 도메인에서 온 기업 회의. 미쓰이-소코(4개 지역 사무소의 회의 484건), 미쓰이 부도산, 허브스팟(HubSpot), 컨플루언트(Confluent), 메카리(Mekari), 애니마인드(AnyMind Group). tl;dv를 사용한 적이 있는 모든 기업의 회의 메타데이터가 보호 조치 없이 동일한 컬렉션에 방치되어 있었다. 가장 활발했던 달은 2025년 7월로 43,209건의 회의가 있었다. 가장 붐비는 시간대는 협정 세계시(UTC) 기준 수요일 오후 2시로, 7,804개의 회의가 진행되었다. 한주의 정점을 찍는 수요일 스탠드업 미팅 시간대였다.

그러나 끝이 아니다 실제로 얼마나 많은 콘텐츠에 접근할 수 있는지 알고 싶었다. 기본적으로 회의는 비공개로 설정되어 있다(즉, 동영상을 시청하거나 텍스트를 볼 수 없다는 의미). 그래서 나는 27,334개의 회의 ID를 스크래핑하여 어떤 회의가 [접근 가능한지 확인했다.]

원문 보기
원문 보기 (영어)
I reported this on January 28th, 2026. It is now July 2026. Six months later. The Firestore database is still wide open. The CTO never responded. I guess my emails were too long and they didn't view them. What is tl;dv? tl;dv (Too Long; Didn't View) is an AI meeting recording platform. It drops a bot into your Google Meet, Zoom, or Teams call, records everything, transcribes it, and generates summaries with AI. Over 2 million users. Backed by investors. Endorsed by half of LinkedIn's sales influencer community. They store your sales calls, job interviews, performance reviews, internal strategy sessions. The kind of content where someone says "this call is being recorded" and everyone nervously laughs and then shares trade secrets for 45 minutes. The Vulnerability When you sign up for tl;dv, the platform authenticates you with a JWT and exchanges it for a Firebase token via gw.tldv.io/v1/users/firebase/token . That token lets you query their Firestore database at projects/lmi-store/databases/(default) . The meetings collection has no tenant isolation. Any authenticated tl;dv user can query every meeting across every account on the platform. Each meeting record hands you the creator's email address, the conference ID (which is a joinable Google Meet or Teams room), the provider, the recording status, and timestamps. For meetings in recording status, that conference ID is a live, active call. You can watch the collection in real time, see a meeting start recording, grab the ID, and walk into someone's call uninvited. At any given time there are roughly 1,000 meetings with status: recording sitting in the collection. A thousand live calls with exposed conference IDs. An attacker with a bot could join all of them simultaneously. I Joined 2 Meetings I did it. Grabbed a conference ID from Firestore and joined a live Google Meet belonging to the Malaysian Ministry of Education . A lady was presenting to over 157 participants. The tl;dv bot was already in the participant list. I was in the same call. Nobody invited me. The Firestore database did. I also joined a call where students from a major US university were building a startup app. 21 people in the call. They were screen-sharing their entire project, discussing prototypes, and, I kid you not, talking about how they needed to add client-side validation for .edu email addresses. They were also setting up Supabase live on screen, and all I could think was "please set up RLS policies" because most people don't, and then you end up like tl;dv. I wanted to say something so badly. "Hey, you might want server-side validation too." But this was a proof of concept, not a consultation. The Scale I queried the Firestore meetings collection and saw there were 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains . Government meetings from 23 countries : Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. All .gov domains. Government employees recording calls on a platform that lets any free-tier user enumerate the whole thing. University meetings from Berkeley, the University of Tokyo, De La Salle, Universidad Nacional de Colombia. Dozens of .edu and .ac domains. Corporate meetings from all 35,000 remaining domains. Mitsui-Soko (484 meetings across four regional offices), Mitsui Fudosan, HubSpot, Confluent, Mekari, AnyMind Group. Every company that ever used tl;dv had their meeting metadata in the same unprotected collection. Peak month was July 2025 with 43,209 meetings . Busiest time slot: Wednesday at 2pm UTC , 7,804 meetings. Hump-day standup hour. But Wait, There's More I wanted to know how much actual content was accessible too, by default meetings are private (Meaning you cant watch the video or see the transcript), so I scraped 27,334 meeting IDs and checked which ones were public. Over 1,000 were. 715 invitee emails exposed across 228 domains . Highlights: a Brazilian government conservation meeting (PACTO Mata Atlântica) with participants from WWF, The Nature Conservancy, Conservation International, WRI, and the São Paulo state government. Meetings from Ukraine's Ministry of Digital Transformation. A HubSpot sales call. Sessions involving Universidad Nacional de Colombia and Chile's Cámara Verde. The Pasta Infrastructure tl;dv names their microservices after pasta. A subdomain scan reveals cappellini , carbonara , fusilli , pasta , penne , puttanesca-v0 , and ravioli , all under tldv.io. An entire Italian restaurant worth of Express servers. Too Long; Didn't Score While exploring their subdomains I found https://worldcup.tldv.io . A FIFA World Cup 2026 vibecoded prediction game built on Base44 for tl;dv employees. It's called "World Cup Pick'em" and their internal squad is named "Too Long; Didn't Score." Cute. The Player entity API has zero authentication. GET /api/entities/Player returns every player record without a session cookie. 43 players. 19 @tldv.io employees with full names and corporate emails. Raphael Allstadt, my disclosure contact who gave vague reassurances and then went quiet, came in 2nd place with 298 points. His personal Gmail was also in the API response. Player #5 on the global leaderboard is "Super Duper CEO." I'll let you guess who that is. The Prediction and Fixture entities are also wide open. A company that records millions of people's meetings vibecoded an internal fun app that leaks their own employee directory. The irony is al dente. Disclosure On January 28th I messaged Raphael Allstadt on LinkedIn and told him I'd found a huge vulnerability that leaks user data. He responded within minutes: "thank you! can you report it to our CTO and we will look at it immediately?" I sent the email. He said "thank you!" I asked about a reward. "My CTO will come back to you," he said. The CTO never came back to me. January 29th: "your cto hasnt reached out yet btw and its not fixed." January 30th, Raphael: "I am sure the team is reviewing it very very soon ❤️" February 14th: "havent got an email and the vulnerability stilll works." Raphael: "He'll come back ☺️" I told him to maybe fix the vulnerability and not leave customers exposed. February 19th: "We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO." The CTO who never responded. That CTO. March 6th: "still not fixed." Seen by Raphael at 5:42 PM. No reply. July 22nd: "still not fixed..." No reply. Their security page is a trophy case. SOC2 compliant. GDPR compliant. EU AI Act compliant. Hosted in the EU. AES-256 encryption. A founder commitment video. Six compliance badges lined up in a row. Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at [email protected] . Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. Their Firestore database has better uptime than their inbox. Date What Late January 2026 Discovered Firestore tenant isolation bypass January 28, 2026 Reached out to Raphael Allstadt (LinkedIn) and emailed CTO + Raphael January 29, 2026 Raphael gives vague reassurance February - March 2026 Multiple follow-ups. CTO never responds. July 2026 Still not fixed. Still no response. Buon appetito. To tl;dv Your platform records people's most sensitive conversations. Job interviews. Sales negotiations. Government briefings. Your users trusted you with content they explicitly consented to record. Fix the Firestore tenant isolation. Firestore security rules exist for this. You already do it correctly for every other collection (users, chats, transcripts, clips, recordings, videos, notes, teams, organizations all return 403). You just forgot meetings. Put auth on the World Cup app or take it down. Your