Recordings security issue

Hi,

It has come to our attention that there might be a serious security issue with BBB recordings. This seems to be an already known issue which is why I’m not going through the trouble of doing a specific disclosure here.

My question is: how can we tell which recordings there are on our server?

If I look in /admins/recordings on our instance, I see only public recordings which is a relief, but if I search for a recording, i find more!

How do you manage recordings to make sure they are not publicly accessible? And how do you deal with the issue that recordings are done even though the recording button has not been pressed?

Thanks for any feedback.

2 Likes

@Graham have you seen this? :backhand_index_pointing_up:

Thanks for reporting this. Please see Meet.coop update October 2025 for an update @anarcat

1 Like

thank you for the transparency, @kawaiipunk

1 Like

Hi!

sorry to bring this topic up again, but from the updates i see on Meet.coop update October 2025 - #40 by kawaiipunk , i don’t clearly see what the way forward is for us at Tor…

for context, we had been using tor.meet.coop for a while until we realized the server was unmaintained and found the critical issues mentioned here. since then, the DNS record was taken offline, but from what I understand the underlying server (ca.meet.coop) is still online, along with our user and recordings database…

is there a way our personal data could be wiped from there?

if you need it, i have a spreadsheet of users I found while browsing around the admin interface before the DNS record was yanked…

thanks!

2 Likes