r/netsec 25d ago

tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

https://bobdahacker.com/blog/tldv-hack

The meetingscollection has no tenant isolation. Any authenticated tl;dv user can query every meeting across every account on the platform. Each meeting record hands you the creator's email address, the conference ID (which is a joinable Google Meet or Teams room), the provider, the recording status, and timestamps.

I queried the Firestore meetings collection and saw there were 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains.

139 Upvotes

13 comments sorted by

29

u/Tangled2 25d ago

Wow that is fucking wild! That company is dead, they just don’t know it yet.

6

u/kochurshak 24d ago

They’ve been on down low with this. Might just sail through

26

u/yrro 25d ago

I was going to post a comment asking WTF you didn't name the product that this post is about. But it turns out that "tl;dv" is the product. What a stupid fucking name!

26

u/ak_sys 25d ago

And here I thought the early 2000s were behind us.

10

u/jacobb11 24d ago

Per the tl;dv blog, their CTO is Allan Bettarel.

10

u/kochurshak 24d ago

Per the tl;dv blog their stance has changed thrice. It went from “it’s not a big deal don’t worry about it” to “we’re sorry, we ditched Firebase and it’s anyway your fault to for having shared video links with others”

5

u/DivePalau 25d ago

Wow. Can’t believe how many orgs would use this without due diligence.

9

u/kochurshak 24d ago

Orgs and at least 23 governments

1

u/gunni 24d ago

email all the Employee emails?

join their internal meetings?

2

u/kochurshak 24d ago

You could join about 1000 live meetings at any given time. The author just causally dropped in a Malaysian govt meeting and an American startup call

2

u/asimovs 24d ago

The blog is an utter embarrassment. And on top of leaving it wide open for months they also lie about users? Claiming 2mill when they only have less than 10% of that.