August 10, 2026
Your meeting has been joined by chaos
Over 181,000 AI meeting recordings left wide open in note taking app
Six months later, strangers could still wander into private work calls
TLDR: A researcher says a popular meeting-recording app left thousands of private meeting details exposed for six months, including live call info. Commenters swung from furious disbelief to pitch-black humor, with many asking how something this sensitive stayed open for so long.
The internet has found its latest "how is this real?" scandal, and the crowd is absolutely not calm. A security researcher says tl;dv, the app that records and summarizes meetings, left a door wide open for six whole months after being warned. That allegedly meant any regular user could browse huge amounts of meeting data and even grab links to some live calls. Yes, the kind of calls where people discuss hiring, strategy, student projects, and government business while nervously joking, "this call is being recorded."
The loudest reaction was pure disbelief. One commenter basically screamed that if they left a flaw this bad open for even six hours, there would be chaos, calling it a "hit the big red off button" level emergency. Others were stunned that such a basic wall between customers appeared to be missing at all, with one person saying this is one of the first things they would check. And then came the darker jokes: one commenter casually said spying on meeting notes "sounds fun," while another twisted the knife with a brutal gag that this was probably the fault of an AI coding helper and the fix would be "better prompts."
The most chilling comment wasn't even funny. It was the one wondering whether foreign governments might have been watching exposed ministry meetings. That's the mood here: part outrage, part gallows humor, part what else is quietly sitting wide open right now?
Key Points
- •The article alleges that tl;dv's Firestore `meetings` collection lacked tenant isolation, allowing any authenticated user to query meeting records across all accounts.
- •According to the report, exposed records included creator email addresses, conference IDs, meeting providers, recording status, and timestamps.
- •The author says live conference IDs for meetings in `recording` status could be monitored in real time and used to join active Google Meet or Teams calls without invitation.
- •As proof of concept, the author says they joined one live meeting tied to the Malaysian Ministry of Education and another involving students at a major US university.
- •The report claims the dataset contained 181,874 meeting records from 84,312 users across 35,003 domains, including government, university, and corporate organizations in multiple countries.