tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv (Too Lazy; Didn’t Validate): 181,874 Meetings Left Wide Open
tl;dv (Too Lazy; Didn’t Validate):181,874 场会议完全暴露
I reported this on January 28th, 2026. It is now July 2026. Six months later. The Firestore database is still wide open. The CTO never responded. I guess my emails were too long and they didn’t view them. What is tl;dv? tl;dv (Too Long; Didn’t View) is an AI meeting recording platform. It drops a bot into your Google Meet, Zoom, or Teams call, records everything, transcribes it, and generates summaries with AI. Over 2 million users. Backed by investors. Endorsed by half of LinkedIn’s sales influencer community. They store your sales calls, job interviews, performance reviews, internal strategy sessions. The kind of content where someone says “this call is being recorded” and everyone nervously laughs and then shares trade secrets for 45 minutes.
我在 2026 年 1 月 28 日报告了这个问题。现在已经是 2026 年 7 月了,六个月过去了,Firestore 数据库依然完全敞开。首席技术官(CTO)从未回复。我猜可能是我的邮件太长了,他们没看。什么是 tl;dv?tl;dv (Too Long; Didn’t View) 是一个 AI 会议录制平台。它会将一个机器人放入你的 Google Meet、Zoom 或 Teams 通话中,录制所有内容、进行转录,并利用 AI 生成摘要。它拥有超过 200 万用户,有投资人背书,并受到 LinkedIn 上半数销售网红社区的推崇。他们存储你的销售电话、求职面试、绩效评估和内部战略会议。就是那种有人说“本次通话正在录音”,大家紧张地笑笑,然后分享 45 分钟商业机密的内容。
The Vulnerability
漏洞所在
When you sign up for tl;dv, the platform authenticates you with a JWT and exchanges it for a Firebase token via gw.tldv.io/v1/users/firebase/token. That token lets you query their Firestore database at projects/lmi-store/databases/(default). The meetings collection has no tenant isolation. Any authenticated tl;dv user can query every meeting across every account on the platform. Each meeting record hands you the creator’s email address, the conference ID (which is a joinable Google Meet or Teams room), the provider, the recording status, and timestamps. For meetings in recording status, that conference ID is a live, active call. You can watch the collection in real time, see a meeting start recording, grab the ID, and walk into someone’s call uninvited. At any given time there are roughly 1,000 meetings with status: recording sitting in the collection. A thousand live calls with exposed conference IDs. An attacker with a bot could join all of them simultaneously.
当你注册 tl;dv 时,平台会通过 JWT 对你进行身份验证,并通过 gw.tldv.io/v1/users/firebase/token 将其交换为 Firebase 令牌。该令牌允许你查询他们位于 projects/lmi-store/databases/(default) 的 Firestore 数据库。会议集合(meetings collection)没有任何租户隔离。任何经过身份验证的 tl;dv 用户都可以查询平台上所有账户的每一场会议。每条会议记录都会提供创建者的电子邮件地址、会议 ID(即可以加入的 Google Meet 或 Teams 会议室)、服务提供商、录制状态和时间戳。对于处于录制状态的会议,该会议 ID 是一个实时、活跃的通话。你可以实时监控该集合,看到会议开始录制,获取 ID,然后不请自来地进入别人的通话。在任何给定时间,集合中大约有 1,000 场处于“录制中”状态的会议。一千个实时通话的会议 ID 就这样暴露了。攻击者可以使用机器人同时加入所有这些通话。
I Joined 2 Meetings
我加入了 2 场会议
I did it. Grabbed a conference ID from Firestore and joined a live Google Meet belonging to the Malaysian Ministry of Education. A lady was presenting to over 157 participants. The tl;dv bot was already in the participant list. I was in the same call. Nobody invited me. The Firestore database did. I also joined a call where students from a major US university were building a startup app. 21 people in the call. They were screen-sharing their entire project, discussing prototypes, and, I kid you not, talking about how they needed to add client-side validation for .edu email addresses. They were also setting up Supabase live on screen, and all I could think was “please set up RLS policies” because most people don’t, and then you end up like tl;dv. I wanted to say something so badly. “Hey, you might want server-side validation too.” But this was a proof of concept, not a consultation.
我确实这么做了。我从 Firestore 获取了一个会议 ID,并加入了一个属于马来西亚教育部(Malaysian Ministry of Education)的实时 Google Meet 通话。一位女士正在向 157 名以上的参与者进行演示。tl;dv 机器人已经在参与者名单中了。我也在同一个通话中。没有人邀请我,是 Firestore 数据库“邀请”了我。我还加入了一个通话,里面是美国某知名大学的学生正在开发一个创业应用。通话中有 21 人。他们正在共享屏幕展示整个项目,讨论原型,而且我没开玩笑,他们还在讨论如何为 .edu 邮箱地址添加客户端验证。他们还在屏幕上实时设置 Supabase,我当时脑子里想的只有:“请务必设置 RLS(行级安全)策略”,因为大多数人都不设置,结果最后就会落得像 tl;dv 这样的下场。我非常想提醒他们:“嘿,你们可能还需要服务器端验证。”但这是一次概念验证,而不是咨询服务。
The Scale
规模
I queried the Firestore meetings collection and saw there were 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains. Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. All .gov domains. Government employees recording calls on a platform that lets any free-tier user enumerate the whole thing. University meetings from Berkeley, the University of Tokyo, De La Salle, Universidad Nacional de Colombia. Dozens of .edu and .ac domains. Corporate meetings from all 35,000 remaining domains. Mitsui-Soko (484 meetings across four regional offices), Mitsui Fudosan, HubSpot, Confluent, Mekari, AnyMind Group. Every company that ever used tl;dv had their meeting metadata in the same unprotected collection. Peak month was July 2025 with 43,209 meetings. Busiest time slot: Wednesday at 2pm UTC, 7,804 meetings. Hump-day standup hour.
我查询了 Firestore 的会议集合,发现共有 181,874 条会议记录,涉及 35,003 个电子邮件域下的 84,312 名独立用户。其中包括来自 23 个国家的政府会议:巴西、哥伦比亚、秘鲁、乌克兰、萨尔瓦多、菲律宾、智利、印度尼西亚、墨西哥、美国、卡塔尔、马来西亚、乌兹别克斯坦、斯里兰卡、海地、南非、牙买加、洪都拉斯、阿根廷、泰国、日本、以色列和伯利兹。全部都是 .gov 域名。政府雇员在一个允许任何免费层级用户枚举所有数据的平台上录制通话。还有来自伯克利大学、东京大学、德拉萨大学、哥伦比亚国立大学的大学会议,涉及数十个 .edu 和 .ac 域名。以及来自其余 35,000 个域名的企业会议。三井仓库(Mitsui-Soko,四个区域办事处共 484 场会议)、三井不动产、HubSpot、Confluent、Mekari、AnyMind Group。每一家使用过 tl;dv 的公司,其会议元数据都存储在同一个未受保护的集合中。高峰期是 2025 年 7 月,共有 43,209 场会议。最繁忙的时段是协调世界时(UTC)周三下午 2 点,共有 7,804 场会议。那是周中站会的时间。
But Wait, There’s More
还没完,还有更多
I wanted to know how much actual content was accessible too, by default meetings are private (Meaning you cant watch the video or see the transcript), so I scraped 27,334 meeting IDs and checked which ones were public. Over 1,000 were. 715 invitee emails exposed across 228 domains. Highlights: a Brazilian government conservation meeting (PACTO Mata Atlântica) with participants from WWF, The Nature Conservancy, Conservation International, WRI, and the São Paulo state government. Meetings from Ukraine’s Ministry of Digital Transformation. A HubSpot sales call. Sessions involving Universidad Nacional de Colombia and Chile’s Cámara Verde.
我想知道到底有多少实际内容是可以访问的。默认情况下,会议是私密的(意味着你无法观看视频或查看转录内容),所以我抓取了 27,334 个会议 ID 并检查了哪些是公开的。结果有超过 1,000 个是公开的。涉及 228 个域名的 715 个受邀者邮箱被暴露。亮点包括:一场巴西政府的保护会议(PACTO Mata Atlântica),参与者来自世界自然基金会(WWF)、大自然保护协会(The Nature Conservancy)、保护国际基金会(Conservation International)、世界资源研究所(WRI)以及圣保罗州政府。还有来自乌克兰数字化转型部的会议、HubSpot 的销售电话,以及涉及哥伦比亚国立大学和智利绿色商会(Cámara Verde)的会议。
The Pasta Infrastructure
“意大利面”基础设施
tl;dv names their microservices after pasta. A subdomain scan reveals cappellini, carbonara, fusilli, pasta, penne, puttanesca-v0, and ravioli, all under tldv.io. An entire Italian restaurant worth of Express servers.
tl;dv 用意大利面来命名他们的微服务。子域名扫描显示了 cappellini、carbonara、fusilli、pasta、penne、puttanesca-v0 和 ravioli,全部都在 tldv.io 域名下。简直是一整家意大利餐厅的 Express 服务器。
Too Long; Didn’t Score
太长;没得分
While exploring their subdomains I found https://worldcup.tldv.io. A FIFA World Cup 2026 vibecoded prediction game built on Base44 for tl;dv employees. It’s called “World Cup Pick’em” and their internal squad is named “Too Long; Didn’t Score.” Cute. The Player entity API has zero authentication. GET /api/entities/Player returns every player record without a session cookie. 43 players. 19 @tldv.io employees with full names and corporate emails. Raphael Allstadt, my disclosure contact who gave vague reassurances and then went quiet, came in 2nd place with 298 points. His personal Gmail was also in the API response. Player #5 on the global leaderboard is “Super Duper CEO.” I’ll let you guess who that is. The Prediction and Fixture entities are also wide open. A company that records millions of people’s meetings vibecoded an internal fun app that leaks their own employee directory. The irony is al dente.
在探索他们的子域名时,我发现了 https://worldcup.tldv.io。这是一个为 tl;dv 员工构建的 2026 年世界杯预测游戏,基于 Base44 构建。它被称为“世界杯竞猜”(World Cup Pick’em),他们的内部团队被命名为“太长;没得分”(Too Long; Didn’t Score)。真可爱。Player 实体 API 没有任何身份验证。GET /api/entities/Player 无需会话 cookie 即可返回所有玩家记录。共有 43 名玩家,其中 19 名是 @tldv.io 的员工,包含全名和公司邮箱。我的披露联系人 Raphael Allstadt(他给了我模糊的保证然后就没动静了)以 298 分排在第二名。他的个人 Gmail 也出现在 API 响应中。全球排行榜上的第 5 名玩家是“超级无敌 CEO”(Super Duper CEO)。我让你猜猜那是谁。Prediction 和 Fixture 实体也完全敞开。一家录制了数百万人会议的公司,竟然开发了一个泄露自己员工名录的内部娱乐应用。这讽刺得恰到好处(al dente)。
Disclosure
披露
On January 28th I messaged Raphael Allstadt on LinkedIn and told him I’d found a huge vulnerability that leaks user data. He responded within minutes: “thank you! can you report it to our CTO and we will look at it immediately?” I sent the email. He said “thank you!” I asked about a reward. “My CTO will come back to you,” he said. The CTO never came back to me. January 29th: “your…”
1 月 28 日,我在 LinkedIn 上给 Raphael Allstadt 发了消息,告诉他我发现了一个泄露用户数据的巨大漏洞。他在几分钟内回复道:“谢谢!你能报告给我们的 CTO 吗?我们会立即查看。”我发送了邮件。他说“谢谢!”我询问是否有奖励。他说:“我的 CTO 会回复你的。”但 CTO 从未回复我。1 月 29 日:“你的……”