news.volyx.in

Tl;dv: Over 180k meetings left wide open (bobdahacker.com)

631 points by colesantiago · 16 days ago · 208 comments on HN

Article summary

A security researcher discovered a vulnerability in the tl;dv meeting recording platform, which allowed any authenticated user to access and join meetings across all accounts, including sensitive government and corporate meetings. The researcher reported the issue to the company six months prior, but it remains unfixed. The vulnerability affects over 181,000 meeting records and has significant security implications. The company's lack of response and failure to prioritize the issue has raised concerns about their security practices.

Main themes

  • Security vulnerability
  • Data exposure
  • Company negligence
  • Meeting recording platform
  • Authentication issues
  • Compliance and regulation

What commenters say

  • The company's six-month delay in addressing the vulnerability is unacceptable and demonstrates a lack of prioritization of security concerns.
  • The vulnerability is a result of lazy software engineering and a lack of expertise in secure development practices.
  • Exposing the company's clients to risk by publicly disclosing the vulnerability is unnecessary and potentially harmful.
  • The use of AI models in development can help prevent similar security issues, but it is not a guarantee of security and should not be relied upon as the sole means of ensuring secure code.
  • The company's security certifications should be revoked due to their failure to respond to and address the vulnerability in a timely manner.
  • The vulnerability highlights the need for secure by default design principles, rather than prioritizing ease of use over security.
  • The researcher's decision to publicly disclose the vulnerability after six months of inaction from the company is justified, as it brings attention to the issue and prompts action.
  • The company's lack of transparency and communication with the researcher and the public is a significant concern and undermines trust in their security practices.