Tl;Dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

speckx1 pts0 comments

tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open | bobdahacker

🎄<br>Currently at 39C3 in Hamburg! Feel free to hit me up on my socials<br>💻

-->

tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

August 4, 2026

BobDaHacker

I reported this on January 28th, 2026. It is now July 2026. Six months later. The Firestore database is still wide open. The CTO never responded. I guess my emails were too long and they didn't view them.

What is tl;dv?

tl;dv (Too Long; Didn't View) is an AI meeting recording platform. It drops a bot into your Google Meet, Zoom, or Teams call, records everything, transcribes it, and generates summaries with AI. Over 2 million users. Backed by investors. Endorsed by half of LinkedIn's sales influencer community.

They store your sales calls, job interviews, performance reviews, internal strategy sessions. The kind of content where someone says "this call is being recorded" and everyone nervously laughs and then shares trade secrets for 45 minutes.

The Vulnerability

When you sign up for tl;dv, the platform authenticates you with a JWT and exchanges it for a Firebase token via gw.tldv.io/v1/users/firebase/token. That token lets you query their Firestore database at projects/lmi-store/databases/(default).

The meetings collection has no tenant isolation. Any authenticated tl;dv user can query every meeting across every account on the platform. Each meeting record hands you the creator's email address, the conference ID (which is a joinable Google Meet or Teams room), the provider, the recording status, and timestamps.

For meetings in recording status, that conference ID is a live, active call. You can watch the collection in real time, see a meeting start recording, grab the ID, and walk into someone's call uninvited. At any given time there are roughly 1,000 meetings with status: recording sitting in the collection. A thousand live calls with exposed conference IDs. An attacker with a bot could join all of them simultaneously.

I Joined 2 Meetings

I did it.

Grabbed a conference ID from Firestore and joined a live Google Meet belonging to the Malaysian Ministry of Education . A lady was presenting to over 157 participants. The tl;dv bot was already in the participant list. I was in the same call. Nobody invited me. The Firestore database did.

I also joined a call where students from a major US university were building a startup app. 21 people in the call. They were screen-sharing their entire project, discussing prototypes, and, I kid you not, talking about how they needed to add client-side validation for .edu email addresses. They were also setting up Supabase live on screen, and all I could think was "please set up RLS policies" because most people don't, and then you end up like tl;dv.

I wanted to say something so badly. "Hey, you might want server-side validation too." But this was a proof of concept, not a consultation.

The Scale

I queried the Firestore meetings collection and saw there were 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains .

Government meetings from 23 countries : Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. All .gov domains. Government employees recording calls on a platform that lets any free-tier user enumerate the whole thing.

University meetings from Berkeley, the University of Tokyo, De La Salle, Universidad Nacional de Colombia. Dozens of .edu and .ac domains.

Corporate meetings from all 35,000 remaining domains. Mitsui-Soko (484 meetings across four regional offices), Mitsui Fudosan, HubSpot, Confluent, Mekari, AnyMind Group. Every company that ever used tl;dv had their meeting metadata in the same unprotected collection.

Peak month was July 2025 with 43,209 meetings . Busiest time slot: Wednesday at 2pm UTC , 7,804 meetings. Hump-day standup hour.

But Wait, There's More

I wanted to know how much actual content was accessible too, by default meetings are private (Meaning you cant watch the video or see the transcript), so I scraped 27,334 meeting IDs and checked which ones were public. Over 1,000 were. 715 invitee emails exposed across 228 domains .

Highlights: a Brazilian government conservation meeting (PACTO Mata Atlântica) with participants from WWF, The Nature Conservancy, Conservation International, WRI, and the São Paulo state government. Meetings from Ukraine's Ministry of Digital Transformation. A HubSpot sales call. Sessions involving Universidad Nacional de Colombia and Chile's Cámara Verde.

The Pasta Infrastructure

tl;dv names their microservices after pasta. A subdomain scan reveals cappellini , carbonara , fusilli , pasta , penne , puttanesca-v0 , and ravioli , all under tldv.io. An entire Italian restaurant worth of Express servers.

Too Long; Didn't Score

While...

meetings meeting call from didn recording

Related Articles