Hubs AI and Technology Post
Join TrustHub to participate — every member is ID-verified
Sign Up Free
0

Too Long; Didn't View Just Became Too Lazy; Didn't Verify

A security researcher renamed a company last week. The company calls itself tl;dv, short for "too long; didn't view." The researcher's title for his disclosure: "Too Lazy; Didn't Validate."

When you read what actually happened, the rename lands. And honestly, it lands on both parties.

What happened, in the short version

tl;dv is one of those AI notetakers that joins your Google Meet, Zoom, or Teams calls to record, transcribe, and summarize everything. Millions of users, including government workers in 23 countries, universities like Berkeley, and companies like HubSpot.

A researcher found that the database holding all of their meeting records had no lock on it. Anyone with a free account could look up every meeting on the platform: who organized it, when, and a live link to whatever call was recording right now. At any moment, that meant about 1,000 live calls you could just walk into. He proved it by walking into a Malaysian Ministry of Education meeting with over 157 people in it. Nobody invited him. The database did.

One correction to the scary headline, because it matters: 181,874 meeting records were exposed, not 181,874 recordings. The recordings and transcripts stayed locked down. What leaked was the meeting info plus live links, and that turned out to be plenty.

He reported it on January 28. The CTO never responded once. Six months later it was still open. The fix is a few lines of code.

It was literally just a switch

Here's the part I can't get over. This was not a sophisticated hack. A researcher signed up for a free account and looked around. That was the whole attack.

And tl;dv knew how to do security. Every other part of their database was locked. Chats, transcripts, recordings, all of it. Someone on that team knew how to lock things down and did it everywhere, then somehow skipped the one place holding live links to every call on the platform.

It was literally just a switch. Do we let people in here or not? They just didn't flip it.

And yes, I think it's stupid and funny that the company's name fits this better than their product ever did. Too Long; Didn't View turned out to be Too Lazy; Didn't Verify.

The meeting hosts were lazy too

I want to be fair here, because I'm pro-AI: this is not only the bot company's fault.

An uninvited guest sat in a 157-person government meeting and nobody questioned it. The tl;dv bot was already sitting in the participant list, and everyone just accepted it. Impersonating an AI notetaker got the researcher into about 80 percent of private calls. People have been trained to see a bot on the roster and move on.

Video platforms already have tools for this. Waiting rooms. Lockable meetings. And there is no reason you can't have AI check every account trying to join a sensitive call. The host side of this failure was laziness too, just a different flavor.

Users are lazy. That's what the money is for.

Here's where I land on the blame math.

End users are always going to be lazy. That's not an insult. That's why they pay the software company. A government employee who installs a free notetaker is not going to audit how it stores data, and we shouldn't expect them to. Security is the thing you're buying when you pay for software that records your meetings, and it's the thing tl;dv was selling. Their security page has a row of compliance badges and a promise that their security team would respond within 24 hours.

So when I split the blame, I land at 80 percent on the bot company and 20 percent on the end client. The client got lazy about who they let into the room. The company got lazy about the one thing it was being paid to do. Those are not the same failure, and they shouldn't carry the same weight.

And for anyone asking whether AI could have prevented this: yes, on both sides. This is a basic mistake, and automated security checks would have caught it. I use near-frontier models every day, and this is exactly the kind of thing they're good at. If you build with AI, you also verify with AI. That's the deal.

The corporate case is the scary one

Government meetings are often public record anyway, so the stakes there are real but limited. The corporate case is where this gets genuinely ugly. Sales negotiations, job interviews, performance reviews, strategy sessions. The kind of call where someone says "this call is being recorded," everyone laughs nervously, and then trade secrets get shared for 45 minutes.

Now imagine an attacker doesn't need to breach your company at all. They just join the call your notetaker already joined, using the link your notetaker leaked. That's an IP theft pipeline running through a third party nobody bothered to check.

Badges are claims, and claims are cheap. The only kind of trust that survives a story like this is the kind you can verify.

0 Comments

Log in to join this hub and comment.

No comments yet. Be the first to reply!