Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

261–270 of 327 posts

Re: Delve – Fake Compliance as a Service

#262

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…

Not really, and I kinda envy you that you haven't really worked up close with compliance-related people.

A lot of compliance is basically corruption - while in country A, you might fall out of a window if you don't buy from the right people at 10x prices, but in 'civilized' country B, you have to buy from vendor X (who has the necessary paperwork), at 10x prices, or you wont be able to sell the product - and there are a million ways that they can turn the levers to kick you out of their markets, or at least make you pay protection money to these compliance organizations.

The systems of grift are very sophisticated, and very obvious to anyone but the people perpetuating and participating in them. As they say,iyt is difficult to get a man to understand something, when his salary depends upon his not understanding it.

A lot of compliance software is griftware - Sonarqube is a prime example - most engineers don't think it adds value, and the 'analysis' it produces is incredibly shoddy, but like a lot of cybersecurity products, it relies on a authoritarian company culture, certification TP conditional on using the software and achieving a good score etc and alarmist language with nice dashboards. A classic example, is it tags public fields in Java as a security issue. And then the management see that you are writing 'insecure code'.

And literal mouthbreathing idiots in upper management eat this shit up, or use it as a punitive measure against the devs who by their very nature do all the meaningful work.

I'm not saying all compliance is worthless, but if you approach quality from first principles, a 'compliant' product usually has to clear a very low bar of quality. And compliance usually keeps the quality low, and prices high, by forcing potential competitors out of the market.

And compliance can keep quality low in other ways, I've seen firsthand - by making devs work on BS tasks, or preventing improvements and fixes to codebases, because they're not tracked appropriately by whatever change management system.

I was incredibly wary of doing hacky solutions in these places, not out of a sense of commitment to quality, but the fact that once management sees your hacks WORK (kinda), all requests to clean up the garbage will be stonewalled.

Thankfully LLMs make this busywork very easy, through making this papermill garbage, and nitpicking busywork very easy, which I feel will bring at least some positive change in the world (at least to those who do meaningful work)

Re: Delve – Fake Compliance as a Service

#263

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

I was asked to work for my employer as an responsible electrical engineer — a specific legal role that needs to be filled if your bosses don't want the liability buck to stop with them.

They fell in the same trap as you did now. You can try to make the libility tree complicated, but in the end the buck will stop with the person in charge unless they put things in place they have to legally put in place. Liability is like water, you can shift it around, but it always has to go somewhere. And if you don't know where it is as a boss, it is likely eating away at your foundation.

In my case they hoped I could just be the responsible electrical engineer on paper and a solve them of their liability. Then I explained them that I could do that, but that legally they would still liable until they provide that role with the time/resources/personal needed to do the job. In my case that would have meant dropping everything I did in my existing roles and reallocating 80% of my work time to that role.

In the end they decided to use an external company that covers that role for real. To them it was just a checkbox in the beginning, but only because they had no expertise in the legal dimension of the whole thing. And sure they could potentially have gone for years without problems, but one wrong electrical fire and they are in jail.

Under GDPR the potential liability we are talking about is 10 Million Euros or 2% of global annual turnover, whichever is higher. But yeah, go ahead, check your boxes.

Re: Delve – Fake Compliance as a Service

#264

Earlier quoted context omitted.

Well let's see how good that Swiss Model would work as a big normal state, and not as a small tax haven, smaller than the State of Baden-Württemberg living off those surrounding states (siphoning up wealthy people, who got rich in those countries, and also their academics, that they didn't have to pay the education for)

Free Schengen movement that you germans fought so hard for. Its nice only if you siphon talent from the eastern part of EU and poorer parts of the world (where same brain drain logic and morality applies), but when people go to better places suddenly its an issue?

I just pointed out that the Swiss model probably doesn't work well on a larger scale, and pointed out why.

No need to get angry about this

Also those people from the Eastern EU also have the Liberty to migrate there

Re: Delve – Fake Compliance as a Service

#265

Earlier quoted context omitted.

Here's me founding a company and thinking "Shit I really need to be on ITIL 4 and ISO9000 before I even consider taking this to market", but I guess we move in different circles.

Do you really want to be compliant to ITIL 4 or do you want to sell to your target market? I'm pretty sure you want customers who pay money, and ITIL 4 badge is just a small mean to achieve that, not a goal per se.

It has to work in with a bunch of organisations who are doing (or attempting to do) ITIL 4 and are fairly insistent on things like consistency across ITSM platforms.

The things is, you know and I know, ITIL is like sex in high school. Everyone says they're doing it loads, everyone says they know all about it, everyone says they're really good at it, but no-one is any good at it, no-one knows anything about it, and no-one is actually doing any of it at all.

Re: Delve – Fake Compliance as a Service

#266

Earlier quoted context omitted.

The risk register is ISO 27001. The "I" in ISO doesn't stand for Internet, it stands for international. You shouldn't be doing business with international customers if you don't have a risk register, which is why they're requesting it.

Shouldn’t according to who? Who appointed ISO to say what should and shouldn’t be done?

The majority of countries that do business today have backed it. You are welcome to ignore it and work against the 160 countries that are using it.

Re: Delve – Fake Compliance as a Service

#268

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

Maybe like 40%, but also just check if they got a manual pentest.

That’s the only actual audit on “security”.

AI pentesting is just another SaaS.

Delve tried to automate the CPA, you can’t automate the audit. Same goes for the penetration test.

Re: Delve – Fake Compliance as a Service

#269
post #62

Earlier quoted context omitted.

Yes, but your team claimed this set off "voting ring" behavior [0] and it was suppressed for nearly a day because of that. I am very curious how you determine what is, or is not, "voting ring" behavior. I believe Dang is responding in another thread about that. [0]: https://news.ycombinator.com/item?id=47457689

Obviously we don't publish how HN's voting ring detector works. If we did, it would quickly stop working. What matters in this case is (1) it's a software penalty that has nothing to do with the content of a story, (2) moderators didn't touch the submissions or even know they existed, and (3) once we did know that they existed, we merged the threads and placed the story on the frontpage - that is, we went out of our…

[dead]
Post reply on HN