Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

51–60 of 327 posts

Re: Delve – Fake Compliance as a Service

#51
post #31

Earlier quoted context omitted.

We just found out about this story and the submissions of it. It looks like it didn't make the front page because it set off HN's voting ring detector. Mods didn't touch either thread except (1) we merged the duplicate discussions and (2) we rolled back the voting ring penalty so that the story would be on the frontpage. This is in keeping with the principle that we moderate stories less, not more, when YC or a YC st…

[flagged]

Having been at this for 12 years I am pretty sure that the bulk of the community does in fact believe us when we say that, and even when we say other things as well.

There are a number of reasons why this is the case. One is that it is true. Another is that we've always treated the good will of the community as by far the biggest asset—in fact, the only asset—that HN has.

Re: Delve – Fake Compliance as a Service

#52

This was such as interesting read, but I found this link via LinkedIn rather than hackernews. I would have expected this to be somewhere at the top right now given how deep the article digs and evidence seems legit.

I think it may be getting (intentionally?) suppressed from the homepage. Given this is a YCombinator website, I wouldn't rule that out. Regardless, it's been an ongoing issue. I know a few involved companies — it takes basically 5 days to get a SOC 2 Type 2 report through Delve. And, of course, they market this way too: "SOC 2 in days". Unbelievable.

I see the submission time as an hour ago, so it actually looks like it got a second-chanced, i.e. boosted by the site admins.

Re: Delve – Fake Compliance as a Service

#53

This was such as interesting read, but I found this link via LinkedIn rather than hackernews. I would have expected this to be somewhere at the top right now given how deep the article digs and evidence seems legit.

I think it may be getting (intentionally?) suppressed from the homepage. Given this is a YCombinator website, I wouldn't rule that out. Regardless, it's been an ongoing issue. I know a few involved companies — it takes basically 5 days to get a SOC 2 Type 2 report through Delve. And, of course, they market this way too: "SOC 2 in days". Unbelievable.

In case anyone hasn't seen my other posts about this:

(1) I had no idea this story existed and woke up to claims that I was obviously* suppressing it.

(2) I looked into it and found that no moderator had touched either of the two submissions of the story, but that both submissions had set off HN's voting ring detector. (Whether there was a voting ring or not, I don't know - that software isn't perfect. It has held up well over the years though.)

(3) We merged the two discussions and placed the merged thread on the front page.

(4) Why? Because we moderate HN less, not more, when YC or a YC startup is part of a story: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu.... This is literally the #1 principle of moderation in the sense that it was the very first thing that pg drilled into me: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que....

* https://quoteinvestigator.com/2018/11/18/know-trouble/

Re: Delve – Fake Compliance as a Service

#54
I've gone through this process and is this not a failure from the institute that are giving away these certifications for a fee without any due diligence?

intermediaries like delve have only amplified this failure.

it was obvious to anyone who was involved in this industry that, all of this is just security theatre with nothing really to back it up.

Re: Delve – Fake Compliance as a Service

#55
post #37

This seems like a hit job by a competitor. Really ruthless. > Two months ago, an email went out to a few hundred Delve clients informing them that Delve had leaked their audit reports, alongside other confidential information, through a Google spreadsheet that was publicly accessible. Who leaked the audit reports? Who sent this email? Who is taking the time to write this analysis and kill the company? In my opinion,…

The key problem is the audits and the auditors. I have independently verified for our vendors that they have the same templated SOC2 as all of the leaked reports, which is concerning because that shows the auditors did not actually validate the controls.

SOC2 is supposed to give you an INDEPENDENT evaluation of the compliance of a company "are they doing what they say they are"

If the SOC2 report is just a pre-populated template, it is meaningless.

It doesn't really matter the motivation of the "DeepDelver" - this has implications across all companies that rely on these vendors that have been "assessed" by Delve.

Re: Delve – Fake Compliance as a Service

#56
Love the depth of this post.

We were actually looking at it as well recently (we're using Drata). I was thinking "Cool, this looks like the next cool step forward". The claims didn't sound out of the world in my ears.

Every time an issue like this appears I wonder how many more undiscovered frauds are out there.

Re: Delve – Fake Compliance as a Service

#57

Earlier quoted context omitted.

I think it may be getting (intentionally?) suppressed from the homepage. Given this is a YCombinator website, I wouldn't rule that out. Regardless, it's been an ongoing issue. I know a few involved companies — it takes basically 5 days to get a SOC 2 Type 2 report through Delve. And, of course, they market this way too: "SOC 2 in days". Unbelievable.

I see the submission time as an hour ago, so it actually looks like it got a second-chanced, i.e. boosted by the site admins.

That's correct - you can see from https://news.ycombinator.com/submitted?id=freddykruger that this post was actually submitted 23 hours ago. The timestamp at the top of the thread is relativized to fit the second-chance pool (https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...).

Re: Delve – Fake Compliance as a Service

#59

Earlier quoted context omitted.

I think it may be getting (intentionally?) suppressed from the homepage. Given this is a YCombinator website, I wouldn't rule that out. Regardless, it's been an ongoing issue. I know a few involved companies — it takes basically 5 days to get a SOC 2 Type 2 report through Delve. And, of course, they market this way too: "SOC 2 in days". Unbelievable.

Surprised/not surprised that this is getting buried from the homepage

It got downweighted by HN's voting ring detector. Mods didn't touch it, except to place the story on the frontpage once we knew it existed.

Re: Delve – Fake Compliance as a Service

#60
Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!"

Thus providing compliance is really just paying someone to shift responsibility.

The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

Post reply on HN