Live data from Hacker News

Viewing profile — whatinthenote

whatinthenote

HN member
Joined
Thu, Jul 07, 2022, 9:05 PM UTC
HN karma
11
Public activity
13 items

About whatinthenote

No profile information was provided.

Recent public activity

  1. comment
    Comment #47462212

    It feels like I'm screaming into the void, but compliance work is bad is because people make it so. Willfully paying for a service that offers SOC 2 reports at 1/5th the usual rate…

  2. comment
    Comment #47460048

    Doesn't seem like a problem with SOC 2 compliance, seems like a problem where a company appointed someone who is not suited to handle a SOC 2 project. As for the pre-filled stuff, …

  3. comment
    Comment #39133989

    Same people that thinks they can build an Uber/Lyft/Instagram competitor by themselves over the weekend.

  4. comment
    Comment #33987137

    As the Americans learned so painfully in Earth's final century, free flow of information is the only safeguard against tyranny. The once-chained people whose leaders at last lose t…

  5. comment
    Comment #32358666

    The source being a tweet from clear right wing nutcase. Not gonna waste my time looking through his tweets to learn that he thinks there are "election fraud" in AZ. I'm not a labor…

  6. comment
    Comment #32023614

    What's actual security? Looking for zero days? Malware research? Continuous red team? I think at the end of the day, SOC 2 aims to instill a basic level of organizational security …

  7. comment
    Comment #32023488

    I don't deny that there are certainly companies that act in bad faith (say one thing in their SOC 2, but do another), but I don't consider it to be a fault of the SOC 2 process. Ju…

  8. comment
    Comment #32021270

    I love it when nothing is documented and every process exists in someone's head.

  9. comment
    Comment #32021057

    Actually, the easiest thing is to find a better auditor. A SOC audit isn't like an IRS audit, you actually pay them to come in and audit. Not all are created equal and sometimes yo…

  10. comment
    Comment #32021016

    I don't understand why people assume SOC 2 can cover every single possible scenario. Especially scenarios that have nothing to do with actual SOC 2 controls, but the result of lax …

  11. comment
    Comment #32020892

    I'm trying hard to figure out what any of this has to do with SOC 2. Perhaps consider the phrase "Don't let perfect be the enemy of good". Okta had a shitty breach, but does that m…

  12. comment
    Comment #32019604

    I think one thing that doesn't get covered enough is SOC 2's value in providing additional data for vendor security reviews. That poor CISO that have to work on SOC 2 is probably t…

  13. comment