Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

201–210 of 327 posts

Re: Delve – Fake Compliance as a Service

#201

Earlier quoted context omitted.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…

>Nobody actually gives a shit, about anything.

That's the case until there is the threat of discovery. The real issue is if the PE firm bought the company for the value of the IP and any damages awarded was included in the 'cost of business', which is why liability needs to be extended to those persons who make that decision, not just the corporate entity.

Re: Delve – Fake Compliance as a Service

#202

Earlier quoted context omitted.

Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…

> I’m gonna name some names. *Doesn’t name any names.* Not that I want you to, I feel it would open you up to libel exposure. But can we both acknowledge that you didn’t name the entity that coasted through their audit?

I did, and then I thought twice. Let’s say it’s a synonym for a piece of non-reflective geology.

Re: Delve – Fake Compliance as a Service

#203

Earlier quoted context omitted.

> Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. Trying to understand how someone can have this perspective when it’s usually someone’s full time salaried job in a lot of companies.

Maybe they meant "Not hard != quickly done". I don't think many people think bureaucracy is especially difficult. It's just time consuming. But frankly if they meant that, the statement doesn't really say anything at all. Because what in this world is hard if you stop taking shortcuts and spend time doing it correctly?

Cold fusion.

Re: Delve – Fake Compliance as a Service

#205
post #53

Earlier quoted context omitted.

In case anyone hasn't seen my other posts about this: (1) I had no idea this story existed and woke up to claims that I was obviously* suppressing it. (2) I looked into it and found that no moderator had touched either of the two submissions of the story, but that both submissions had set off HN's voting ring detector. (Whether there was a voting ring or not, I don't know - that software isn't perfect. It has held up…

>I had no idea this story existed and woke up to claims that I was obviously* suppressing it. To be fair, it seems you’re saying the submission was being suppressed, just not intentionally. Lots of props of course for transparency and reboosting the story

When people use the word "suppressed" they usually mean that we were personally intervening to do something suppressive. This being the internet, they say that with supreme confidence whether it's true or not.

For example, the comment I was referring to, which was the first one I saw, said "It is being suppressed by @dang" (https://news.ycombinator.com/item?id=47457010). You can't get more personal, definitive, or wrong than that.

Re: Delve – Fake Compliance as a Service

#207
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

> Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee enterprise.

Have you considered that the kind of companies that demand SOC2 compliance would be happy to pay extra for SOC2 compliance, if you offered it as an optional add-on costing $200k per year?

Re: Delve – Fake Compliance as a Service

#208

Earlier quoted context omitted.

This is clearly false from what I've seen. If you read the source Substack article and look through the list of auditors they have, it is impossible to trace down who the US-based CPA is that's issuing the report. These firms, for all intents and purposes, do not really exist. They use shell addresses in Wyoming and Texas that are registered agent offices, etc. But really all you have to do is look at the reports the…

Present assurance definitely exists in the US. Outside of delve, I have seen their reports for vanta and it’s the same. it was 95% policy inspections and 5% loooked at a GRC tool.

I assume you mean this "Prescient Assurance? As detailed in this section of the post?

6.7 Misled auditor - Prescient

With this conclusion:

Looking at that report, there are clear signs that Delve either knowingly misled Prescient, or that Prescient accommodated Delve’s deficient process. Given their reputation and by the small number of Delve/Prescient reports out there, I’m assuming it is the former.

Re: Delve – Fake Compliance as a Service

#209
post #61

Earlier quoted context omitted.

The value of SOC2 is that it does take some experience to be able to plausibly fake the evidence which weeds out people that truly have no idea what they're doing. It also provides a blueprint of the stuff you should be doing if you actually care. But beyond that it's not worth a whole lot.

yeah it's funny to see some defense of this practice as "well the whole thing is pointless anyway so nothing is lost by defrauding folks". Pretty hollow argument

yes, the equivalent of looking at api spec and saying it's pointless because there's no implementation.

I feel like in the last five years all prior knowledge and art wrt infosecurity was lost from the "dev community". My guess is that hackers have an embarrassment of exploits and are being unusually quiet. I expect a series of major breaches/hacks over the next few months that are ignored and it just becomes normal to have all of your customer data dumped onto the public web. For example, the digital banking system could go under, and most kids would just download some new crypto app. It won't really matter that nothing replaces the dollar or our global banking infrastructure. The zeroing out of the financial system would just be the "coyote suddenly being affected by gravity".

Post reply on HN