Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it.

    Wasn't a dating app exposed this year with same negligence or firebase security?

    by Oras
  • It's almost like people need knowledge and experience to work with tools securely. The problem with Firebase (I think) is that its marketing is "it's easy to use" and I'm confident most problems - like storing this info - is easy to figure out and finish, then move on to the next thing.

    But this is lazy / "move fast" software engineering. They mention all of these certifications, I think they should be stripped of them for a year because of a failure to respond / act.

  • If something happens again and again, it is by choice. Firebase chooses to make it “easy” to get started rather than “secure by default”.
  • Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.
    by sktb
  • In this case the CEO was aware of it and... did nothing.
  • My biggest worry is the small talk that you casually have in meetings. Comments about your pattern of life, family, locations, friends and health. Slurping all that up over 100s of meetings is concerning. Stored raw transcripts of meetings is a huge liability. Should redact small talk and only store useful extracts.
  • Some notetakers filter that stuff out automatically.
  • I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem.

    The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.

  • Drafts.app is hideous but it has great routing capability and a dictation feature. I use it to capture what my thoughts and route based on content. I have a button that routes to an internal voice agent named KiKo. Ideas get routed to Things or todoist. Issues get routed to github, etc. It’s one universal surface for note capture.

    But man is it ugly.

  • > The breakdown in the pipeline seems to be reliable local diarization

    Yep, diarization just hasn't been well solved yet. As soon as it has, the quality in note-takers, meeting transcripts, etc, will sky-rocket across the board.

  • That’s a very fair concern. I completely understand why you’d want to avoid exposing yourself or your clients to that risk.

    I also agree that diarization and speaker identification are probably one of the hardest parts to get right if the speakers aren’t separated correctly, even a great summary won’t fix it.

    We’re looking into more privacy preserving approaches for MindNote (a multimodal AI Notetaker), including local/on-device processing, so this is really useful feedback. Thanks for sharing your experience!

  • I'm definitely biased as the developer, but maybe try https://whistle-enterprise.com and see how it works for you.

    It's a hard problem I've been working away on for a while now. It's far from perfect but every step brings it a bit closer.

  • > I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem

    Unfortunately it’s mostly not up to you. It’s a weakest-link problem. It doesn’t matter if you don’t use a note taker AI, if even one person on the call uses one. Their tool doesn’t notify you and usually the person doesn’t either.

    It also has the reverse impact to the person using the note taker, where people say less around them. Same as if I'm talking to someone with Meta glasses.

    I wonder if the people who use these tools know the people they meet with speak less during their meetings, and then all of the participants have a post-meeting call without them to say what they really thought.

  • I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.
  • Sturgeon's Law is proved correct time and again. Most things are crap. Most people produce some crap in their lives. Some people only produce crap. Those people still need to eat but unfortunately some of them (somehow) find their way into tech and actually convince people to pay money for crap.

    Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.

    by pc86
  • This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.

    Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026

    PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..

    https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)

    https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)

    It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.

  • > 4TB/40,000 contractors voice + government ID + selfie leaked

    Leaked selfies? Do you mean ID photos?

  • Genuinely thought you meant you carry out deepfake voice phishing.
  • > He responded within minutes: "thank you! can you report it to our CTO and we will look at it immediately?"

    Why could he not speak to HIS ceo himself instead of asking Bob to

  • I've know executives like this; at some level they seem to be self aware enough* to realize that any message that passes through them will be garbled beyond recognition and so actively encourage people to route around them.

    * I know they're just saying the words a self aware person would say to give that impression, but it can be eerily convincing.

  • I saw that and chuckled.
  • > Why could he not speak to HIS ceo himself instead of asking Bob to

    You can't expect a founder/CEO to spend 2 minutes relaying an email with critical security information to his own CTO, he's surely way too busy disrupting and pivoting and doubling down on product market fit.

  • "Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "

    oof

  • Hegseth loves this app!
  • Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.
  • Actually they are taking one from Anthropic's playbook and saying it's the user's fault for misunderstanding what "sharing" means.
  • Also add the word "secure" a lot.
  • AI agent: sorry for that, I'll build the next version will be the most secured one
  • This should be the kiss of death for any company. The exposure of sensitive data like that, and for that long? There's a serious disconnect between security best practices and law, and how many companies actually operate.

    My own company is a sitting duck for hackers right now. I've begged them to implement basic 2FA for 6 months and all they do is brush concerns under the carpet. No one gives a shit, all the way to the very top.

  • I saw an YouTuber the other day sharing their "day in the life" as an Amazon Software Engineer while promoting (as part of a paid sponsorship) the AI note taking feature of SoundCore headphones, claiming they now record their meetings and receive an AI summary at the end.

    I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.