Tag
A security researcher reveals that tl;dv, an AI meeting recording platform, left its Firestore database exposed for months, allowing any authenticated user to access over 181,000 meeting records and live conference IDs for thousands of ongoing calls, including government and university meetings.
Explains how a traditional backend inflates AI agent token usage and demonstrates a context-engineering approach that reduces Claude Code session costs by 2.5x without changing models or prompts.
The author built a vulnerable React Native app to test if LLMs could exploit a common Firebase misconfiguration, finding that only a few models (GPT 5.5, Deepseek V4 Pro, Claude Sonnet 4.6, Claude Opus 4-8) succeeded, with GPT 5.5 having the highest solve rate.