But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
I used to work for a company seeking SOC2 compliance. They told me that I had to install corporate malware because of the compliance. I didn't want to install it on my personal computer, which I had been using for work. They sent me a company computer. I installed the corporate malware on that one. I set the company computer aside and continued working on my personal computer. No SOC2 compliance was harmed in the process.
thih9 38 seconds ago [-]
The company computer typically comes with some data protection agreement, where you agree to only access confidential data via the company computer.
fg137 4 hours ago [-]
I used a product with SOC2 certification, which uploads all your chatbot conversations to a server they control (mandatory), potentially including source code and other proprietary data, which can be made visible to public with a single click. Doesn't matter if you are an individual or enterprise user.
They do have enterprise level controls that let admins turn this off. Unfortunately, it is on by default, and some of those basic security controls require a higher tier of service.
It is absolutely wild that these companies treat security like an afterthought. And I also realized SOC2 Compliant meant absolutely nothing.
SAI_Peregrinus 2 hours ago [-]
SOC2 requires a company to write policies in a large number of areas, and to demonstrate that they're complying with the policies they wrote. AFAIK SOC2 does not require anything meaningful about the actual contents of the policies, nor does it require the policies to remain constant.
cyberge99 7 hours ago [-]
Is there an entity that can validate they are not SOC2 compliant outside of their claim?
maebert 6 hours ago [-]
Yes, SOC2 require an audit by an independent auditor, and in principle you can request their audit report from them.
Just email the CTO about it ;)
varispeed 4 hours ago [-]
Reminds me of ISO certification. Where all it does is that your complaints are called non-conformance.
Trasmatta 6 hours ago [-]
Once again proof that SOC2 is nothing but a marketing tactic, and busywork
maxrev17 2 hours ago [-]
VC runway afterburners, engage!!!
cube00 6 hours ago [-]
On a personal note, I recognize that I should have kept the researcher updated after his initial outreach earlier this year, and I take full responsibility for that communication gap.
They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period?
Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.
stellamariesays 7 hours ago [-]
[flagged]
xvxvx 2 hours ago [-]
This should be the kiss of death for any company. The exposure of sensitive data like that, and for that long? There's a serious disconnect between security best practices and law, and how many companies actually operate.
My own company is a sitting duck for hackers right now. I've begged them to implement basic 2FA for 6 months and all they do is brush concerns under the carpet. No one gives a shit, all the way to the very top.
cube00 7 hours ago [-]
I saw an YouTuber the other day sharing their "day in the life" as an Amazon Software Engineer while promoting (as part of a paid sponsorship) the AI note taking feature of SoundCore headphones, claiming they now record their meetings and receive an AI summary at the end.
I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.
asdff 8 minutes ago [-]
Ai notetaking is such as signal for stupidity but I'm not surprised that it is getting so much traction. It is basically like getting all your lecture notes from the A student so you can fuck around instead of paying actual attention to anything, and hoping the A students understanding of the lecture somehow rubs off on you.
Kind of funny how that is the pitch for a lot of these products. AI to help you take notes in meetings. AI to help you pass an interview. AI to read and write for you. AI to let you be a lazy bastard, in other words.
valbaca 3 hours ago [-]
I remember while at Amazon, during the "everyone needs to be using AI in every way" push, one of my teammates was proud to present that he had figured out how to split the audio on his mac to record the meeting (because our meeting software didn't allow for recordings without consent) and fed this into speech-to-text and generated summaries of the meetings without any of us knowing (i.e. no consent).
I let him and our manager know that he'd just violated eavesdropping laws across state lines (he's in D.C. and I'm in WA; RCW 9.73.030).
It's amazing how many people don't think that "AI Notetaker" is the same as "I secretly recorded this (as possibly violated the law)"
altairprime 1 hours ago [-]
Interestingly, Zoom and presumably others are logging and reporting on device SIDs and names, so those AI headsets are in server-side data associated with specific workers. I imagine Zoom would rather not advertise this data collection openly — and I don’t have personal proof that the data is transmitted to their servers, so perhaps it’s just collected at the client and then not harvested, unlikely as that may be. But that worker may find themselves targeted for termination if their employer’s platform discovers their unauthorized use of non-employer AI to process employer private work output by their Bluetooth device name.
newsoftheday 7 hours ago [-]
Not trying to be rude or mean here but it should be, "a YouTuber" since YouTuber starts with a consonant sound.
anenefan 24 minutes ago [-]
You are correct but it is not based on the sound, just if it starts with a vowel. If one listens to people speak, a common mistake, even I do it from copying the same in others, (depending on what crowd I've been around a lot,) is using an before hour as in 'an hour' though most times people will correctly write 'a hour'.
asdff 5 minutes ago [-]
Who writes "a hour"?
Ylpertnodi 7 hours ago [-]
I knew a girl called Anne Yoo.
fg137 3 hours ago [-]
I don't really understand why these "AI notetaking" services/features still exist outside video conference software today -- any company that needs it would have already purchased the license from Zoom/Teams/Slack which takes care of everything including storage and compliance.
palmotea 8 hours ago [-]
Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.
markboo 7 hours ago [-]
AI agent: sorry for that, I'll build the next version will be the most secured one
greenavocado 7 hours ago [-]
Make no mistakes
HPsquared 8 hours ago [-]
Also add the word "secure" a lot.
7 hours ago [-]
DrammBA 7 hours ago [-]
Actually they are taking one from Anthropic's playbook and saying it's the user's fault for misunderstanding what "sharing" means.
gppk 1 hours ago [-]
Heh, interesting. I literally just vibe-coded an app tonight that takes a meeting recording, runs it through whisper to generate the text, then through your local codex gives you a summary and creates actions that are pushable to either github (technical) or PM tool (project level)
Takes about 7 minutes for a 2 hour meeting on my 3080 GPU so well within useful timeframe.
I did it because i didn't want to pay £7 a month for a discord meeting notes taker, but seems generally useful. And ofc you could swap out for a local model if you have more compute than i do...
asdff 4 minutes ago [-]
Why not just pay attention in the meetings you are paid to attend?
Aeroi 8 hours ago [-]
"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "
oof
hashstring 2 hours ago [-]
Hegseth loves this app!
wkirby 7 hours ago [-]
I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem.
The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
It's a hard problem I've been working away on for a while now. It's far from perfect but every step brings it a bit closer.
WhrRTheBaboons 6 hours ago [-]
Seems interesting. What would you say are the biggest missing points currently or things you want to get working/improved but couldn't yet?
properbrew 6 hours ago [-]
Thank you, great question! Hard one to answer, thought about it a lot and it's going to be the diarisation of more than 5+ speakers per audio stream (your microphone + system audio for a max of 10). I actually spent a lot of time that went completely nowhere trying to fine tune my own diarisation model, it was fun to a degree but painful to see my output end up worse than what I currently had after days of work. Having a bot join the call would be such an easy way of diarising, the call software has already done it for you, but feels like a bit of a cop out.
Two more improvements, audio quality improvements which is currently in the works and close to release and a new document generation model. I'm currently using a custom fine tuned Phi-4 (released December 2024!) model, that's _so old_ in the grand scheme of LLMs, I just haven't had time to benchmark and properly test some new models whilst this currently does a good job as it is. There has to be some gains here, but who knows!
artemisart 4 hours ago [-]
Interested also, which text-to-speech model do you use?
For diarisation Granola uses a chrome extension instead of a bot if that can give you ideas.
properbrew 3 hours ago [-]
I think this is just to capture the audio to ship off to their servers and do the crunching. You mentioned the word "extension" and thank you so much, I've been thinking about how to do integrations as it's something a few users have mentioned, but keep the whole "completely offline" angle. I could build standalone extensions that integrate with it if it's something a user wants. So damn obvious in hindsight!
Ahh yea as for the models:
Speech to text - Nvidia Parakeet TDT 0.6b V3
Diarisation - Nvidia Marblenet for the speech detection, TitaNet-Large for the embeddings and then using NeMo multi-scale to do clustering around them
joshspankit 4 hours ago [-]
Since the participants are known and limited, have you tried building around samples tagged with user/person names?
properbrew 3 hours ago [-]
I tried something similar by putting together a "global ledger" of speaker identities. This was more happening during the call than having a predefined one but I just couldn't get it to work properly. The issue being that as soon as some speech gets assigned to a new label or an incorrect one, everything ends up getting misaligned and gets messy quickly.
I might take another look into doing it in a different way that gradually builds up from successful calls, I just need to think of how to do this in a simple(ish) way for non-technical users and a way that still works well enough on low to mid tier laptops.
wkirby 6 hours ago [-]
Literally starting my monday weekly standup now, I'll run it and see what's up. Thanks!
properbrew 3 hours ago [-]
Thank you! Feel free to drop me and email (info in bio or on the website) if you run into any issues or have any suggestions.
eterm 2 hours ago [-]
> The breakdown in the pipeline seems to be reliable local diarization
Yep, diarization just hasn't been well solved yet. As soon as it has, the quality in note-takers, meeting transcripts, etc, will sky-rocket across the board.
cyberge99 7 hours ago [-]
Drafts.app is hideous but it has great routing capability and a dictation feature.
I use it to capture what my thoughts and route based on content.
I have a button that routes to an internal voice agent named KiKo.
Ideas get routed to Things or todoist.
Issues get routed to github, etc.
It’s one universal surface for note capture.
But man is it ugly.
wkirby 7 hours ago [-]
My ideal use case is to pipe audio from both my microphone and capture system audio so things like our weekly team standup or my 1:1s with my devs can all have reliable, decent notes without taking me out of the flow of the conversation.
I think clearly the _leader_ in the space is granola, but I'm just not going to use a cloud provider for this.
Drafts have anything like that?
halfcat 5 hours ago [-]
> I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem
Unfortunately it’s mostly not up to you. It’s a weakest-link problem. It doesn’t matter if you don’t use a note taker AI, if even one person on the call uses one. Their tool doesn’t notify you and usually the person doesn’t either.
It also has the reverse impact to the person using the note taker, where people say less around them. Same as if I'm talking to someone with Meta glasses.
I wonder if the people who use these tools know the people they meet with speak less during their meetings, and then all of the participants have a post-meeting call without them to say what they really thought.
wkirby 2 hours ago [-]
> It doesn’t matter if you don’t use a note taker AI, if even one person on the call uses one
Yeah, but I'm unwilling to be that person.
fsuts 7 hours ago [-]
> He responded within minutes: "thank you! can you report it to our CTO and we will look at it immediately?"
Why could he not speak to HIS ceo himself instead of asking Bob to
peezd 5 hours ago [-]
I saw that and chuckled.
Ekaros 8 hours ago [-]
I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.
pc86 8 hours ago [-]
Sturgeon's Law is proved correct time and again. Most things are crap. Most people produce some crap in their lives. Some people only produce crap. Those people still need to eat but unfortunately some of them (somehow) find their way into tech and actually convince people to pay money for crap.
Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.
noir_lord 8 hours ago [-]
Fortunately we have LLM's to not produce that crap... wait, those LLM's were trained on the existing crap and produce the same crap... oh no.
user43928 8 hours ago [-]
I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it.
And even if, a later "is this ready for release" will probably surface such obvious issues.
I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.
sensanaty 6 hours ago [-]
I love the never-ending "SOTA" treadmill used to defend anything and everything these LLM tools shit up. Doesn't matter what happens, it wasn't one of the "SOTA" models (which changes every 7 seconds) ergo it's irrelevant, how very convenient for the AI pushers!
user43928 4 hours ago [-]
More than half a year ago, someone may or may not have used AI to implement this insecure backend.
That is not a very good basis to start complaining about AI producing insecure code.
If you still want to do it, at least check if it actually is the case with reasonably intelligent current models.
Ekaros 6 hours ago [-]
Can someone give me exact time when SOTA stop being good? Is it a day, week or a month? As such can I consider anything older than that time period to automatically be crap?
wongarsu 7 hours ago [-]
However if you start current SOTA models out on a bad codebase they will happily write more bad code to fit in with the "conventions" of the existing code. Including authentication and isolation. If you start out your app on the wrong foot (for example because you lack the vocabulary to express what you need) you can end up with nicely polished turds
Asking the LLM for a review of the code would still have caught it
skydhash 7 hours ago [-]
Still the six month wait time when everything should be good? /s
user43928 4 hours ago [-]
No, what I said is that I think this has already been good for some time.
bonoboTP 7 hours ago [-]
They were RL trained on verifiable rewards. It's not purely learning to predict the next token of a human produced stream.
esafak 1 hours ago [-]
This is not an issue. IF you prompt it right you could have avoided this with models at least a year old.
owen-hill 7 hours ago [-]
[flagged]
msyea 3 hours ago [-]
My biggest worry is the small talk that you casually have in meetings. Comments about your pattern of life, family, locations, friends and health. Slurping all that up over 100s of meetings is concerning. Stored raw transcripts of meetings is a huge liability. Should redact small talk and only store useful extracts.
ubervisor 44 minutes ago [-]
These companies take anything but responsibility. The fact that they’re trying to downplay it in their own blog post with “but look at the others, they’ve had security issues too,” as if that makes it any better, says it all. I would never trust that company with anything ever again.
quietfox 27 minutes ago [-]
Funny enough, there is a news story in which the same CEO that didn't care about the breach for 6 months told USA Today 'that European tech needs to be “bold but secure” to win the enterprise AI race'.
It's hilarious how these companies handle security breaches.
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
jjice 6 hours ago [-]
I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal.
I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.
Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.
purplemoonx 6 hours ago [-]
So bad.
At these types of startups, developers will find themselves in some debate about the time complexity of a click handler (which is debounced anyway).
Meanwhile Joe CEO is like "HAY GUYS" -drops db-
"CAN U FIX IT BY MONDAY"
suzzer99 6 hours ago [-]
At a few companies I've worked at, they squelch this kind of bug/security breach reporting by immediately making it the discoverer's job to fix the problem and champion it through the system to production, taking on all responsibility if something breaks of course. You only have to go through that once to get the message.
mettamage 4 hours ago [-]
Many SWE teams don't care about security. Even talking about security annoys them. I get it though. I've had offensive security training at uni (VUSEC Amsterdam). It's a way different type of thinking.
suslik 1 hours ago [-]
I hate hearing about security because I saw orgs decimated by paranoid (and incompetent) security to such degree that nothing could be done there and I had to look for a new job.
ThrowawayTestr 6 hours ago [-]
More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.
remuskaos 4 hours ago [-]
I studied physics, did a PhD and postdoc, the whole science shebang. When I got into software development a few years ago, I was put into a well functioning pizza sized team that developed an internal app for another company. The crew was as software-dev as it gets,:
- one architect who was there from the apps inception yen years prior, who knows all the ins and outs of the application
- one project lead, who was with the project two years, who could also code in the classical sense, but was mostly the connection to the customer
- a tester who could not code, but also knew the app in and out (from the user perspective) and found things or relayed and reproduced bugs reported by the customer
- a technical writer who could also code (somewhat), but was more responsible to think of user behavior, undefined app behavior, edge cases, logic issues etc
- and several disposable code monkeys, who were exchangeable and expendable, who did most of the tickets. I joined as one of these
The work was great, the team functioned great and we delivered what the customer wanted. But what really struck me was that software dev is not science, or engineering, or an art form, it's most akin to a trade like plumbing or carpentry. I had computer science as minor in university and pretty much none of what I learned there helped for "real" work. I learned SVN in university, but obviously the team used git. And all of the software development and programming courses I did taught me nothing of how real software is structured or how a team works.
That impression only more strongly once I had to train new hires, PhDs in comp science, who knew basically nothing about real software development.
Again, it's a trade, something you learn on the job from someone who already knows it, like a master carpenter.
dcrazy 2 hours ago [-]
Heh, that idea resonates with me. I’ve been contemplating some projects that will require pulling permits, and as part of that process have been trying to understand how an engineer reviewing my submitted plans would think.
While you could absolutely generate a list of compliance checks to execute like a formula, at the end of the day you need to have absorbed enough experience that, when presented a physical or imagined project, your brain is immediately able to make connections between what it sees and the general principles of how you build something correctly.
Since I don’t have that experience, I know I need to stick to the well-trod path. No clean-sheet deck construction methods for me. :)
purplemoonx 6 hours ago [-]
The entire reason the company was funded is the US government started enforcing FCRA compliance on 1099 Uber drivers.
So the government did get involved and regulated Uber and the entire gig economy, and the private sector is so powerful they just made their own background check company with hundreds of millions of dollars in VC and hype, gave them Uber as their flagship customer and wiped their hands.
No doubt in my mind these people were "just happy to be here" at best, criminals at worst, and have no business working with PII and background checks. Founders and everyone there.
But I still think the company should be found liable, not an individual engineer. They would be a lot more incentivized to hire based on merit, and not incentivized to literally be corrupt like they are now.
With your idea of punishing the engineer... these VCs would love that. Shift even more blame onto the worker, why not, we've taken it for everything else
Calazon 4 hours ago [-]
Of course it's not real engineering, and most software development never was real engineering.
Trying to apply real engineering licensing ideas to software would just result in the word "engineering" no longer being used in the vast majority of cases. If that's your goal, then sure, great. But it won't stop ridiculous security mistakes from being made, they'll just be made by people with different job titles.
siva7 6 hours ago [-]
Software lost that status in the vibe coding era. It's an art form now, not necessarily something worse or easier, just different than engineering. But probably not the career path anymore for those who prefered math over philosophy in college.
batshit_beaver 6 hours ago [-]
It was this way well before vibe coding. Over a decade of zero interest rates combined with talent wars and other anticompetitive behaviors by large tech companies did the industry in.
8n4vidtmkvmk 4 hours ago [-]
Amusingly i specialized in both AI and philosophy in college. Guess I'll be ok.
customguy 6 hours ago [-]
Software never had that status. I was disgusted by the decline I could see in the 90s even, and I was a teenager, I had no clue and still don't. I cannot imagine how it must be for people who do have a clue. They're probably all drinking.
altmanaltman 5 hours ago [-]
Software engineering has always had that perception, long before vibe coding. Also you might call it an "art" but most normal people will not see it as such (if you actually care about defintions, in theory we can call anything anything if we want)
mapt 6 hours ago [-]
If a civil engineer made a negligent mistake that bad which "made it to production", rather than being caught before the structure collapsed, he would spend a decade in prison for negligent homicide.
To be fair, if the story in the comment you are replying to is actually factual and the company is found to be leaking private information on this scale, it can face pretty harsh legal consequences.
purplemoonx 4 hours ago [-]
Someone should investigate, interview me.
They violated their termination agreement with me already when they went way out of their way to make sure I would not get hired at certain other companies when I left.
mschuster91 7 hours ago [-]
> I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time.
In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.
purplemoonx 7 hours ago [-]
Idk licensing and regulation sounds like involving more institutional arrogance.
We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doing.
Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing. People who have done it a thousand times should get that job, not some dumb kid who just got out of school.
QuadmasterXLII 6 hours ago [-]
this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.
perpetuallunch 6 hours ago [-]
There is exactly zero evidence that any religion isn’t true.
How could there be?
Evolution can’t disprove the existence of God.
arethuza 6 hours ago [-]
All depends which god we are disproving the existence of?
purplemoonx 5 hours ago [-]
Prove Zeus didn't fart the Earth into existence, otherwise that's what happened
goatlover 4 hours ago [-]
Welcome to Invisible Pink Unicorns and orbiting tea pots. You're just a fleeting experience of a Boltzmann Brain in the background of high entropy universe.
We don't need to disprove radically skeptical or outlandish beliefs. They're not consistent with everything else we know. There's no good reason to take them seriously.
purplemoonx 6 hours ago [-]
Allow me to introduce you to: Burden of Proof.
toomuchtodo 6 hours ago [-]
As a cybersecurity practitioner, regulation and oversight is the only incentive that moves the needle in my experience. If there are no costs or negative outcomes for not caring about security, security will not be prioritized. Big fan of SEC Breach Reporting via Form 8-K, as well as state reporting requirements.
Kinda feel like you get corruption no matter if it's pure socialism or pure capitalism, and that any system is a reflection of the people.
mschuster91 6 hours ago [-]
> Idk licensing and regulation sounds like involving more institutional arrogance.
Well it works. Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on a modern ship is a pretty rare thing to happen (either as employee or passenger) if you contrast it with the situation just five decades or so ago.
> We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
Degree mills aren't the kind of gatekeeping I'm talking about. If you screw up, you still can go to another company and continue screwing up there, which also means there is barely any incentive to hold education institutions accountable to deliver good education. In the regulated trades however? Screw up enough and you're out for good.
> Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing.
Trades licensing is merit based.
purplemoonx 6 hours ago [-]
Commercial aviation involves other people's lives in real-time. I put that more like being a lifeguard or EMT.
Recreational aviation has a lot less regulation. I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
Shouldn't need a license to make React components, sorry.
mschuster91 5 hours ago [-]
> Recreational aviation has a lot less regulation.
Yup, and the result is that GA has orders of magnitude worse accident rates.
> I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
In most of Europe, this just doesn't fly (pun intended), you need a license for almost all aeronautical activities, and on top of that a fair few countries (most notably Germany) only allow start and land from official airstrips.
> Shouldn't need a license to make React components, sorry.
Oh I'd say, yes, a license is a good idea, simply given how often developers put in stuff from marketing that violates laws. Forcing a license that can be revoked now gives engineers the ability to push back against management because now their licenses are on the line.
purplemoonx 5 hours ago [-]
> this just doesn't fly
How dare you. And to your point, you'd never catch me on one of those paraglider things!
> Oh I'd say, yes, a license is a good idea, simply given how often developers put in stuff from marketing that violates laws.
My only license is MIT :cool:
bluGill 6 hours ago [-]
> Trades licensing is merit based.
Only on the bottom end. People with zero merit get forced out - eventually in most cases. However a lot of people who have merit are not allowed in.
mschuster91 4 hours ago [-]
> People with zero merit get forced out - eventually in most cases.
Yeah but in many cases often only after decades and still with a sizable final paycheck on departure. "Failing upwards" is a thing, and it happens far too often.
tonyhart7 5 hours ago [-]
unfortunately, that just how organization was
buzer 36 minutes ago [-]
My first thought was "huh, I wonder if they follow GDPR, that starts sound to like Article 32 violation" (related to security of processing). I checked the privacy policy and yes, they are based in Germany so GDPR likely applies to all of their processing.
However that privacy policy raises also quite a few concerns. They say that "profile image URL" is based on contractual obligation which is quite weird, just why profile image is necessary to fulfill a contract? Additionally IP address and location are collected for "adapted pricing" and it's "legal and contractual obligation". I can somewhat understand that if it's used to calculate VAT, but "adapted pricing" sounds much wider thing. And even VAT calculation itself isn't really "adapted pricing", it's something that the company needs to handle. They are of course free to change the price based on that, but that price change goes more to legitimate interest rather than legal (or contractual) obligation.
They also claim that "Product analysis and improvement, marketing and attribution, incident management and in some of our logs" as well as "Analysis of products and navigation on the site and application" are also "legal and contractual obligation". I honestly want to hear what contract necessitates those or exactly what law requires them to do that.
sktb 9 hours ago [-]
Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.
Cthulhu_ 7 hours ago [-]
In this case the CEO was aware of it and... did nothing.
Oras 8 hours ago [-]
Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it.
Wasn't a dating app exposed this year with same negligence or firebase security?
asdf88990 6 hours ago [-]
If something happens again and again, it is by choice. Firebase chooses to make it “easy” to get started rather than “secure by default”.
Cthulhu_ 7 hours ago [-]
It's almost like people need knowledge and experience to work with tools securely. The problem with Firebase (I think) is that its marketing is "it's easy to use" and I'm confident most problems - like storing this info - is easy to figure out and finish, then move on to the next thing.
But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.
nashashmi 6 hours ago [-]
This breach will help with tl;dv's awareness. More people will suddenly become aware of it. The downside is that less private conversations will be hooked up to tl;dv, and more public seminars will be fed instead. This is a win-win overall. And it is a PSA to all other companies to secure their servers a little bit better.
sensanaty 6 hours ago [-]
The worst part of these AI meeting notes and recordings is that I have literally never seen anybody, in any situation, go back to them. The (very) few times I ever bothered to check the transcripts and especially the summaries immediately after a meeting, without fail they'd have something in them that is the complete opposite of what someone said in the meeting, or they'd miss extremely important clarifications or context. Literally worse than useless, actively detrimental, but you bet your ass whichever moron forced these to be on for every meeting is putting it on their resume - "Increased long-term organizational cohesiveness via comprehensive automated meeting notes" or whatever type of bullshittery.
IAmBroom 3 hours ago [-]
That is a wild claim. Every single quarterly meeting my company has with customers begins with redistributing the notes from the previous meeting, and "to-do" points are regularly referenced.
AI notes are a godsend, because instead of forcing one person to keep careful notes throughout, the meeting's host can quickly review, edit, and send out the minutes - a job that otherwise would literally take more time than the meeting, because one person spent the meeting just taking notes. The AI notes require careful review, and contain a lot of repetitive fluff, but all notes require review before distribution.
So, now you are aware that this is a normal thing in other companies.
Terr_ 1 hours ago [-]
> That is a wild claim.
Perhaps we can all agree that usage is very bimodal, between the people who refer to auto-notes constantly vs never?
hashstring 2 hours ago [-]
The disclosure section is gold. It’s such an accurate description.
Major consumer companies reply just like that.
It’s incompetence and I think to an extent also arrogance.
odo1242 20 minutes ago [-]
This is essentially the #1 Firebase footgun. Having client-accessible databases with optional rule-base security has always seemed a bit dumb.
SpaceL10n 8 hours ago [-]
Hmm, does Ukraine know that Russia is watching the Ministry of Digital Transformation's meetings?
"Raphael Allstadt, co-founder of Germany’s fastest-growing startup, tl;dv, argues that European tech needs to be “bold but secure” to win the enterprise AI race."
"But Silicon Valley may have more engineering talent on paper; Europeans care far more about data, security, and privacy. That means our builders pay closer attention, build compliance in from the start, and are ultimately better suited to serve the enterprise market, especially here in Europe.”
As tl;dv scales, Allstadt’s mission remains twofold: to prove that a European startup can out-execute the US giants on product, while maintaining the privacy standards Europe demands.
The irony
gvv 5 hours ago [-]
Funny, my first thought was that this has to be related to Firebase...
headz 6 hours ago [-]
OK, the issue sucks. That said, the post was written by an LLM and It's not pleasant to read. If I didn’t work with Claude every day, I might feel differently, but because I do, this reads like slop.
thenatureboy 5 hours ago [-]
doesnt change the fact that the vulnerability existed. Stop whining
mastermedo 5 hours ago [-]
TBH I've been finding Claude quite funny lately, the pasta jokes are pretty good.
> The irony is al dente.
gyanchawdhary 8 hours ago [-]
This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.
PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..
It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.
lostlogin 8 hours ago [-]
> 4TB/40,000 contractors voice + government ID + selfie leaked
Leaked selfies? Do you mean ID photos?
zeroxfe 7 hours ago [-]
Selfies are used during live ID verification. (All of this is supposed to be encrypted, and destroyed within certain regulatory bounds.)
6 hours ago [-]
usamaasfar 7 hours ago [-]
I'm starting to believe Firebase is cursed at this point.
SpaceL10n 5 hours ago [-]
We're going to open your database by default, but PLEASE remember to secure it later! Footgun deployed successfully.
ex1fm3ta 4 hours ago [-]
at this point, it's a feature, not a bug.
iJohnDoe 7 hours ago [-]
I think this is one of the few times public disclosure wasn’t a good idea. Some of these are government meetings and could put lives in danger.
Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.
nope1000 7 hours ago [-]
To forget tenant isolation on one endpoint is bad enough but to ignore it for 6 months is madness. I am at a SaaS company and our customers have such strict security requirements for us and that is for less confidential data.
Aeroi 8 hours ago [-]
holy crap. how do you respond as CEO to this and not escalate to like priority #1?
then kick the can for 6 months?
lostlogin 8 hours ago [-]
> how do you respond as CEO to this and not escalate to like priority #1? then kick the can for 6 months?
We might be able to check the meeting minutes and get the answer?
root-parent 8 hours ago [-]
A post on LinkedIn where this CEO seems very active should solve that.
homeonthemtn 6 hours ago [-]
Wow.
Trasmatta 6 hours ago [-]
> tl;dv names their microservices after pasta. A subdomain scan reveals cappellini, carbonara, fusilli, pasta, penne, puttanesca-v0, and ravioli, all under tldv.io. An entire Italian restaurant worth of Express servers.
Pretty appropriate, given a vulnerability of this severity. Literal microservice spaghetti.
(Also, please, let's all move back to boring names for services and servers. Nobody likes trying to decode what all these silly names mean.)
EDIT:
omg, the disclosure communication is infuriating.
> We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO
This should have been a P1 that was fixed same day, and they strung him along for months. Absolute amateurs.
idiotsecant 8 hours ago [-]
Is this still active? I wouldn't mind spying on some meeting notes. Sounds fun.
mdrzn 8 hours ago [-]
If they haven't fixed it in 6 months, I'd say it's fair game to scrape as much as you can.
bpodgursky 7 hours ago [-]
I know this is a joke but it's still a felony, for your own sake don't do this.
IAmBroom 3 hours ago [-]
Serious question: how is it a felony?
Distributing it might count as copyright piracy, but merely downloading public data?
wavemode 2 hours ago [-]
The federal government outlaws "knowingly accessing a computer without authorization or exceeding authorized access" to obtain information from any "protected computer" (which, in this context, means any computer involved in interstate commerce - which, in practice, has been ruled such that it certainly includes any Internet-connected server of a corporation).
Your defense would have to be that you were authorized to access the data, or that you did not know that you weren't authorized to access the data. Not merely that the data was easily accessible.
Ekaros 3 hours ago [-]
Just because company failed to limit access does not mean it is public data. Just like stuff not being screwed or glued down doesn't mean you are free to take it.
idiotsecant 3 hours ago [-]
the prison time might be the best part of reading through 180k meeting transcripts
blitzar 8 hours ago [-]
"Lets circle back and touch base to tease out any low hanging synergies we can capitalise on" - repeated 181,000 times
cube00 3 hours ago [-]
"You're on mute"
blitzar 3 hours ago [-]
"Nothing on my end"
8 hours ago [-]
brohee 7 hours ago [-]
Now let's see if European users get their GDPR article 33 notification of the breach...
saadyousfi 6 hours ago [-]
[dead]
ayang3000 7 hours ago [-]
[flagged]
redsocksfan45 8 hours ago [-]
[dead]
plantain 6 hours ago [-]
"Because the common denominator between both of these distinct incidents was Firebase, we are taking the additional step of immediately removing it from our tech stack altogether to definitively eliminate the risk of similar vulnerabilities in the future." - from their post-mortem.
Thank god the root cause was definitively identified! /s
new_account_900 8 hours ago [-]
[dead]
throwaway613746 5 hours ago [-]
[dead]
roysting 3 hours ago [-]
[dead]
alkh 8 hours ago [-]
[flagged]
CurbStomper 4 hours ago [-]
[dead]
hluska 8 hours ago [-]
I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
gossamer 8 hours ago [-]
As I see it he is not the one exposing clients to risk. He is frustrated that no one is fixing it. The company that left themselves open like this are the ones that are exposing their clients.
If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.
root-parent 8 hours ago [-]
You need to read the article.
hluska 8 hours ago [-]
I read the entire article. Did you? There’s no reason in there to expose this company’s clients.
Edit - Are you capable of answering my actual question or was that the best you could do?
mikestew 7 hours ago [-]
Read the article again, then. Anyone that has could get the list with a trivial amount of work. Security through obscurity isn’t going to hide that client list.
And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”
charlieyu1 7 hours ago [-]
I think it is fine, the person hasn't really leaked any critical information. He named a few clients that are mostly government departments, and it would be a public interest concern if said issue is ignored for 6 months anyway
root-parent 8 hours ago [-]
He has been emailing the CEO for six months with no replies. This is has also been posted here before with not a single pip or comment ... :-)
And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
Oras 7 hours ago [-]
Technical due diligence do not including pep test!
dpark 7 hours ago [-]
> And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.
stonedivot 2 hours ago [-]
I totally trusted this vendor selling me this snake oil, and he promised me it would work. I can't believe he let me down. This is all his fault.
dpark 30 minutes ago [-]
Security incompetence doesn’t turn basic meeting recording and transcribing into snake oil.
root-parent 7 hours ago [-]
>> They trusted a company that made a promise and that company let them down.
That is a Boeing and Volkswagen type of excuse. The engineers did it!
dpark 36 minutes ago [-]
No it’s not. Blaming customers is Volkswagen saying it’s your fault for buying a TDI.
Ekaros 7 hours ago [-]
Sometimes shame is only option to get things fixed. Sadly we do not have any reliable government institutions that could mandate immediate shut down of services. Before that only way to get things fixed is public shame.
masfuerte 7 hours ago [-]
What's the alternative? Seriously. He's spent six months trying to get them to fix it. The risk is already there.
reilly3000 5 hours ago [-]
Right. At a certain point, the customers and investors and world need to understand the scope of the negligence so they can prepare for their own fallout of having that information fall into the wrong hands. Public disclosure is a responsibility of being a good citizen and engineer.
I’m so sorry for tl;dv ‘s insurance company.
seb1204 8 hours ago [-]
So did he email privacy@tldv.io? Why not? Maybe someone who understands it would read it.
ncr100 8 hours ago [-]
It's unclear. Only stating the existence of the privacy email.
> [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]
This is near the disclosure schedule
intended 7 hours ago [-]
From the article - he reached out to the CEO directly, who acknowledged and said it was being worked on by the CTO. He did this repeatedly over 6 months.
quietfox 3 hours ago [-]
I wonder how the HN algo chose this one link to Bobs blogpost to be the one to hit the front page. This story was committed three more times by three different users, 6 days ago (16 points), 4 days ago (11 points) and another one 4 days ago, again with 16 points.
But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
[1] https://tldv.io/features/security-commitment/
They do have enterprise level controls that let admins turn this off. Unfortunately, it is on by default, and some of those basic security controls require a higher tier of service.
It is absolutely wild that these companies treat security like an afterthought. And I also realized SOC2 Compliant meant absolutely nothing.
Just email the CTO about it ;)
They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period?
Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.
My own company is a sitting duck for hackers right now. I've begged them to implement basic 2FA for 6 months and all they do is brush concerns under the carpet. No one gives a shit, all the way to the very top.
I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.
Kind of funny how that is the pitch for a lot of these products. AI to help you take notes in meetings. AI to help you pass an interview. AI to read and write for you. AI to let you be a lazy bastard, in other words.
I let him and our manager know that he'd just violated eavesdropping laws across state lines (he's in D.C. and I'm in WA; RCW 9.73.030).
It's amazing how many people don't think that "AI Notetaker" is the same as "I secretly recorded this (as possibly violated the law)"
Takes about 7 minutes for a 2 hour meeting on my 3080 GPU so well within useful timeframe.
I did it because i didn't want to pay £7 a month for a discord meeting notes taker, but seems generally useful. And ofc you could swap out for a local model if you have more compute than i do...
oof
The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
It's a hard problem I've been working away on for a while now. It's far from perfect but every step brings it a bit closer.
Two more improvements, audio quality improvements which is currently in the works and close to release and a new document generation model. I'm currently using a custom fine tuned Phi-4 (released December 2024!) model, that's _so old_ in the grand scheme of LLMs, I just haven't had time to benchmark and properly test some new models whilst this currently does a good job as it is. There has to be some gains here, but who knows!
Ahh yea as for the models:
Speech to text - Nvidia Parakeet TDT 0.6b V3
Diarisation - Nvidia Marblenet for the speech detection, TitaNet-Large for the embeddings and then using NeMo multi-scale to do clustering around them
I might take another look into doing it in a different way that gradually builds up from successful calls, I just need to think of how to do this in a simple(ish) way for non-technical users and a way that still works well enough on low to mid tier laptops.
Yep, diarization just hasn't been well solved yet. As soon as it has, the quality in note-takers, meeting transcripts, etc, will sky-rocket across the board.
But man is it ugly.
I think clearly the _leader_ in the space is granola, but I'm just not going to use a cloud provider for this.
Drafts have anything like that?
Unfortunately it’s mostly not up to you. It’s a weakest-link problem. It doesn’t matter if you don’t use a note taker AI, if even one person on the call uses one. Their tool doesn’t notify you and usually the person doesn’t either.
It also has the reverse impact to the person using the note taker, where people say less around them. Same as if I'm talking to someone with Meta glasses.
I wonder if the people who use these tools know the people they meet with speak less during their meetings, and then all of the participants have a post-meeting call without them to say what they really thought.
Yeah, but I'm unwilling to be that person.
Why could he not speak to HIS ceo himself instead of asking Bob to
Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.
And even if, a later "is this ready for release" will probably surface such obvious issues.
I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.
That is not a very good basis to start complaining about AI producing insecure code.
If you still want to do it, at least check if it actually is the case with reasonably intelligent current models.
Asking the LLM for a review of the code would still have caught it
https://archive.is/QQy2b
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.
Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.
At these types of startups, developers will find themselves in some debate about the time complexity of a click handler (which is debounced anyway).
Meanwhile Joe CEO is like "HAY GUYS" -drops db-
"CAN U FIX IT BY MONDAY"
- one architect who was there from the apps inception yen years prior, who knows all the ins and outs of the application - one project lead, who was with the project two years, who could also code in the classical sense, but was mostly the connection to the customer - a tester who could not code, but also knew the app in and out (from the user perspective) and found things or relayed and reproduced bugs reported by the customer - a technical writer who could also code (somewhat), but was more responsible to think of user behavior, undefined app behavior, edge cases, logic issues etc - and several disposable code monkeys, who were exchangeable and expendable, who did most of the tickets. I joined as one of these
The work was great, the team functioned great and we delivered what the customer wanted. But what really struck me was that software dev is not science, or engineering, or an art form, it's most akin to a trade like plumbing or carpentry. I had computer science as minor in university and pretty much none of what I learned there helped for "real" work. I learned SVN in university, but obviously the team used git. And all of the software development and programming courses I did taught me nothing of how real software is structured or how a team works.
That impression only more strongly once I had to train new hires, PhDs in comp science, who knew basically nothing about real software development.
Again, it's a trade, something you learn on the job from someone who already knows it, like a master carpenter.
While you could absolutely generate a list of compliance checks to execute like a formula, at the end of the day you need to have absorbed enough experience that, when presented a physical or imagined project, your brain is immediately able to make connections between what it sees and the general principles of how you build something correctly.
Since I don’t have that experience, I know I need to stick to the well-trod path. No clean-sheet deck construction methods for me. :)
So the government did get involved and regulated Uber and the entire gig economy, and the private sector is so powerful they just made their own background check company with hundreds of millions of dollars in VC and hype, gave them Uber as their flagship customer and wiped their hands.
No doubt in my mind these people were "just happy to be here" at best, criminals at worst, and have no business working with PII and background checks. Founders and everyone there.
But I still think the company should be found liable, not an individual engineer. They would be a lot more incentivized to hire based on merit, and not incentivized to literally be corrupt like they are now.
With your idea of punishing the engineer... these VCs would love that. Shift even more blame onto the worker, why not, we've taken it for everything else
Trying to apply real engineering licensing ideas to software would just result in the word "engineering" no longer being used in the vast majority of cases. If that's your goal, then sure, great. But it won't stop ridiculous security mistakes from being made, they'll just be made by people with different job titles.
https://www.constructiondive.com/news/contractors-sentenced-...
https://www.reddit.com/r/AskEngineers/comments/cjpva1/is_it_...
https://www.monitor.co.ug/uganda/oped/commentary/it-s-a12-ye...
They violated their termination agreement with me already when they went way out of their way to make sure I would not get hired at certain other companies when I left.
The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time.
In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.
We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doing.
Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing. People who have done it a thousand times should get that job, not some dumb kid who just got out of school.
How could there be?
Evolution can’t disprove the existence of God.
We don't need to disprove radically skeptical or outlandish beliefs. They're not consistent with everything else we know. There's no good reason to take them seriously.
https://www.sec.gov/newsroom/speeches-statements/gerding-cyb...
https://www.ncsl.org/technology-and-communication/security-b...
Well it works. Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on a modern ship is a pretty rare thing to happen (either as employee or passenger) if you contrast it with the situation just five decades or so ago.
> We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
Degree mills aren't the kind of gatekeeping I'm talking about. If you screw up, you still can go to another company and continue screwing up there, which also means there is barely any incentive to hold education institutions accountable to deliver good education. In the regulated trades however? Screw up enough and you're out for good.
> Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing.
Trades licensing is merit based.
Recreational aviation has a lot less regulation. I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
Shouldn't need a license to make React components, sorry.
Yup, and the result is that GA has orders of magnitude worse accident rates.
> I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
In most of Europe, this just doesn't fly (pun intended), you need a license for almost all aeronautical activities, and on top of that a fair few countries (most notably Germany) only allow start and land from official airstrips.
> Shouldn't need a license to make React components, sorry.
Oh I'd say, yes, a license is a good idea, simply given how often developers put in stuff from marketing that violates laws. Forcing a license that can be revoked now gives engineers the ability to push back against management because now their licenses are on the line.
How dare you. And to your point, you'd never catch me on one of those paraglider things!
> Oh I'd say, yes, a license is a good idea, simply given how often developers put in stuff from marketing that violates laws.
My only license is MIT :cool:
Only on the bottom end. People with zero merit get forced out - eventually in most cases. However a lot of people who have merit are not allowed in.
Yeah but in many cases often only after decades and still with a sizable final paycheck on departure. "Failing upwards" is a thing, and it happens far too often.
However that privacy policy raises also quite a few concerns. They say that "profile image URL" is based on contractual obligation which is quite weird, just why profile image is necessary to fulfill a contract? Additionally IP address and location are collected for "adapted pricing" and it's "legal and contractual obligation". I can somewhat understand that if it's used to calculate VAT, but "adapted pricing" sounds much wider thing. And even VAT calculation itself isn't really "adapted pricing", it's something that the company needs to handle. They are of course free to change the price based on that, but that price change goes more to legitimate interest rather than legal (or contractual) obligation.
They also claim that "Product analysis and improvement, marketing and attribution, incident management and in some of our logs" as well as "Analysis of products and navigation on the site and application" are also "legal and contractual obligation". I honestly want to hear what contract necessitates those or exactly what law requires them to do that.
Wasn't a dating app exposed this year with same negligence or firebase security?
But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.
AI notes are a godsend, because instead of forcing one person to keep careful notes throughout, the meeting's host can quickly review, edit, and send out the minutes - a job that otherwise would literally take more time than the meeting, because one person spent the meeting just taking notes. The AI notes require careful review, and contain a lot of repetitive fluff, but all notes require review before distribution.
So, now you are aware that this is a normal thing in other companies.
Perhaps we can all agree that usage is very bimodal, between the people who refer to auto-notes constantly vs never?
Major consumer companies reply just like that.
It’s incompetence and I think to an extent also arrogance.
"Raphael Allstadt, co-founder of Germany’s fastest-growing startup, tl;dv, argues that European tech needs to be “bold but secure” to win the enterprise AI race."
"But Silicon Valley may have more engineering talent on paper; Europeans care far more about data, security, and privacy. That means our builders pay closer attention, build compliance in from the start, and are ultimately better suited to serve the enterprise market, especially here in Europe.”
As tl;dv scales, Allstadt’s mission remains twofold: to prove that a European startup can out-execute the US giants on product, while maintaining the privacy standards Europe demands.
The irony
> The irony is al dente.
Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026
PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..
https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)
https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)
It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.
Leaked selfies? Do you mean ID photos?
Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.
then kick the can for 6 months?
We might be able to check the meeting minutes and get the answer?
Pretty appropriate, given a vulnerability of this severity. Literal microservice spaghetti.
(Also, please, let's all move back to boring names for services and servers. Nobody likes trying to decode what all these silly names mean.)
EDIT:
omg, the disclosure communication is infuriating.
> We're on it. It needs some time, but rest assured we're following through. For further communication, i'll recommend reaching out to our CTO
This should have been a P1 that was fixed same day, and they strung him along for months. Absolute amateurs.
Distributing it might count as copyright piracy, but merely downloading public data?
Your defense would have to be that you were authorized to access the data, or that you did not know that you weren't authorized to access the data. Not merely that the data was easily accessible.
Thank god the root cause was definitively identified! /s
If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.
Edit - Are you capable of answering my actual question or was that the best you could do?
And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”
And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.
That’s a garbage take. These customers didn’t move fast or break things. They trusted a company that made a promise and that company let them down.
That is a Boeing and Volkswagen type of excuse. The engineers did it!
I’m so sorry for tl;dv ‘s insurance company.
> [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]
This is near the disclosure schedule