logoalt Hacker News

Over 181,000 AI meeting recordings left wide open in note taking app

117 pointsby colesantiagotoday at 12:26 PM39 commentsview on HN

Comments

palmoteatoday at 1:15 PM

Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.

show 2 replies
wkirbytoday at 2:01 PM

I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem.

The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.

Ekarostoday at 1:06 PM

I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.

show 1 reply
Aeroitoday at 1:42 PM

"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "

oof

Orastoday at 1:23 PM

Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it.

Wasn't a dating app exposed this year with same negligence or firebase security?

sktbtoday at 12:49 PM

Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.

SpaceL10ntoday at 1:12 PM

Hmm, does Ukraine know that Russia is watching the Ministry of Digital Transformation's meetings?

gyanchawdharytoday at 1:22 PM

This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.

Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026

PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..

https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)

https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)

It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.

show 1 reply
idiotsecanttoday at 1:02 PM

Is this still active? I wouldn't mind spying on some meeting notes. Sounds fun.

show 3 replies
Aeroitoday at 1:22 PM

holy crap. how do you respond as CEO to this and not escalate to like priority #1?

then kick the can for 6 months?

show 2 replies
ayang3000today at 1:57 PM

[flagged]

redsocksfan45today at 1:35 PM

[dead]

alkhtoday at 1:49 PM

[flagged]

new_account_900today at 1:18 PM

[dead]

hluskatoday at 1:25 PM

I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?

show 4 replies
seb1204today at 1:33 PM

So did he email [email protected]? Why not? Maybe someone who understands it would read it.

show 2 replies