tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
122 points by yoelcabo
122 points by yoelcabo
Remember when companies had dedicated ops/infra teams that were specifically in charge of things like managing access to services, and developers would complain that it's too slow to wait for another team to provision a database for them?
Pepperidge farm remembers.
Not sure how you would reasonably expect an ops/infra team to fix a C-suite level cultural problem that this company clearly has, even the best ops team would flounder in that sort of environment. The best ops/infra teams are ultimately about accountability, the tech they build is just a downstream effect of that and if your CTO doesn't give a shit about accountability good luck.
https://tldv.io/blog/our-thoughts-on-the-darkreading-com-article/ <- company response
options:
which one would you pick?
which one would you pick?
let's see
Even for those affected public meetings, content was not surfaced through tl;dv’s normal browsing or search: reaching it required specific programmatic actions by an technically versed hacker.
it's B and C.
I'd imagine B is doing the heavy lifting here.
They acknowledge that the report happened, they don't directly dispute anything he claimed, and the wording used around their response to the breach (whether from the pen tester in question or this mysterious other organisation that's never named) sounds quite bizarre to me.
The issue was resolved shortly after.
As part of our immediate fix, we have fully secured this access point to ensure meeting URLs can no longer be obtained this way.
The exploit works 6 months later but it was "resolved" shortly after being reported?
"Immediate fix" sounds suspiciously like "hot fix to plug whatever aspects we can because we can't or won't fix the core issue for $REASONS".
reaching it required specific programmatic actions by an technically versed hacker.
It’s a variant of Ye Olde claim of a “super sophisticated attack” when the attacker was simply adjusting URLs by incrementing numbers.
The vulnerable data was strictly limited to metadata: meeting identifiers, conference IDs (the links used to join Google Meet or Microsoft Teams calls) and participant email addresses and domains.
… the exposed data did not include highly sensitive personal data
lol
Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Lovable and Zoom have both worked through cases where user-configured public settings produced broader visibility than users had anticipated. It is a category of UX problem the industry is collectively getting sharper about.
Imma go for gaslighting here: "everyone has this problem, even companies way smarter than us! Don't look at those naughty hacker people who want to confuse you. The problem is the users not understanding what public means, not that we leaked the whole list of every meeting."
Whether it's gaslighting or not
The common thread: “public” can mean different things to different users, and the UX around opting into public visibility needs to make the consequences unambiguous. We are taking a fresh look at how we surface those choices in our own product even better, and expect to ship changes soon.
I do have to agree with this 100%
Because the common denominator between both of these distinct incidents was Firebase, we are taking the additional step of immediately removing it from our tech stack altogether to definitively eliminate the risk of similar vulnerabilities in the future.
Correct me if i’m wrong, but was their response really “We had two (or one, depending on who’s story you take) misconfigurations that leaked data, so therefore we’re going to use a different tool”? (which could also be misconfigured, I’m not aware of ways to host data online for a service like this where that is not possible.) It is true that some tools are easier to secure than others, but this seems like a weird response to me.
The irony is al dente.
I LOLed
As a note, BobDaHacker uses she/they pronouns, and is being consistently misgendered by tl;dv (though the darkreading.com article correctly uses they/them). Hopefully lobste.rs can be an exception and use her correct pronouns :)
ah, firebase config at it once again...
Edit: eva's blog has a couple of great articles about security issues of companies using firebase (previously mentionned on lobsters)
They took "parse, don't validate" way too seriously /hj
Nothing in the news on this.
No indication on the company website that there is anything of concern anywhere ever.
Still bragging about their end-to-end security.
Psychotic.
It’s always firebase.
What immediately sends me into a white-hot rage is the way the general public and the media simply accepts blaming of every such incident on "hackers" as a universal excuse. Hacking is viewed as a force of nature that nobody can do anything about, not as sheer incompetence of businesses taking upon themselves the task of keeping user data.
And no, I don't expect a doctor or a salesperson to understand the difference between hacking and querying a wide open database. But I'd really love some technical industry-wide regulation requiring some basic, common-sense level of security, which, if the company doesn't meet it, would result in actual civil or criminal sentences for C-level execs.
Tangent: is the language the Author’s normal writing style or was this AI assisted writing?
It might be just me but I feel there is a specific dry punchy humor style that I no longer enjoy because it’s there everywhere and it feels like AI even if it isn’t (which is sad)
it doesn't look like AI to me. AI is not so dry. But 100% I feel you
What does 'dry' have to do with anything? Every paragraph and almost every sentence in this article is structured exactly the way Claude structures them everywhere for everything. It is the most recognizable of the AIs, and in this article is barely edited. https://www.pangram.com/history/2775edcd-dee3-4518-94d4-61ceeb10a212?ucc=XrbTEdPOPhj
Felt AI assisted to me. Definitely not the lowest slop, though, but it feels like there was at least some AI pass somewhere.
Sentences like "Over 2 million users. Backed by investors. Endorsed by half of LinkedIn's sales influencer community." do it for me, I can't finish reading the article even if it really was human-written.