[flagged]
Delve – Fake Compliance as a Service
261–270 of 327 posts
Re: Delve – Fake Compliance as a Service
#26280% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…
A lot of compliance is basically corruption - while in country A, you might fall out of a window if you don't buy from the right people at 10x prices, but in 'civilized' country B, you have to buy from vendor X (who has the necessary paperwork), at 10x prices, or you wont be able to sell the product - and there are a million ways that they can turn the levers to kick you out of their markets, or at least make you pay protection money to these compliance organizations.
The systems of grift are very sophisticated, and very obvious to anyone but the people perpetuating and participating in them. As they say,iyt is difficult to get a man to understand something, when his salary depends upon his not understanding it.
A lot of compliance software is griftware - Sonarqube is a prime example - most engineers don't think it adds value, and the 'analysis' it produces is incredibly shoddy, but like a lot of cybersecurity products, it relies on a authoritarian company culture, certification TP conditional on using the software and achieving a good score etc and alarmist language with nice dashboards. A classic example, is it tags public fields in Java as a security issue. And then the management see that you are writing 'insecure code'.
And literal mouthbreathing idiots in upper management eat this shit up, or use it as a punitive measure against the devs who by their very nature do all the meaningful work.
I'm not saying all compliance is worthless, but if you approach quality from first principles, a 'compliant' product usually has to clear a very low bar of quality. And compliance usually keeps the quality low, and prices high, by forcing potential competitors out of the market.
And compliance can keep quality low in other ways, I've seen firsthand - by making devs work on BS tasks, or preventing improvements and fixes to codebases, because they're not tracked appropriately by whatever change management system.
I was incredibly wary of doing hacky solutions in these places, not out of a sense of commitment to quality, but the fact that once management sees your hacks WORK (kinda), all requests to clean up the garbage will be stonewalled.
Thankfully LLMs make this busywork very easy, through making this papermill garbage, and nitpicking busywork very easy, which I feel will bring at least some positive change in the world (at least to those who do meaningful work)
Re: Delve – Fake Compliance as a Service
#26380% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
They fell in the same trap as you did now. You can try to make the libility tree complicated, but in the end the buck will stop with the person in charge unless they put things in place they have to legally put in place. Liability is like water, you can shift it around, but it always has to go somewhere. And if you don't know where it is as a boss, it is likely eating away at your foundation.
In my case they hoped I could just be the responsible electrical engineer on paper and a solve them of their liability. Then I explained them that I could do that, but that legally they would still liable until they provide that role with the time/resources/personal needed to do the job. In my case that would have meant dropping everything I did in my existing roles and reallocating 80% of my work time to that role.
In the end they decided to use an external company that covers that role for real. To them it was just a checkbox in the beginning, but only because they had no expertise in the legal dimension of the whole thing. And sure they could potentially have gone for years without problems, but one wrong electrical fire and they are in jail.
Under GDPR the potential liability we are talking about is 10 Million Euros or 2% of global annual turnover, whichever is higher. But yeah, go ahead, check your boxes.
Re: Delve – Fake Compliance as a Service
#264Earlier quoted context omitted.
Well let's see how good that Swiss Model would work as a big normal state, and not as a small tax haven, smaller than the State of Baden-Württemberg living off those surrounding states (siphoning up wealthy people, who got rich in those countries, and also their academics, that they didn't have to pay the education for)
Free Schengen movement that you germans fought so hard for. Its nice only if you siphon talent from the eastern part of EU and poorer parts of the world (where same brain drain logic and morality applies), but when people go to better places suddenly its an issue?
No need to get angry about this
Also those people from the Eastern EU also have the Liberty to migrate there
Re: Delve – Fake Compliance as a Service
#265Earlier quoted context omitted.
Here's me founding a company and thinking "Shit I really need to be on ITIL 4 and ISO9000 before I even consider taking this to market", but I guess we move in different circles.
Do you really want to be compliant to ITIL 4 or do you want to sell to your target market? I'm pretty sure you want customers who pay money, and ITIL 4 badge is just a small mean to achieve that, not a goal per se.
The things is, you know and I know, ITIL is like sex in high school. Everyone says they're doing it loads, everyone says they know all about it, everyone says they're really good at it, but no-one is any good at it, no-one knows anything about it, and no-one is actually doing any of it at all.
Re: Delve – Fake Compliance as a Service
#266Earlier quoted context omitted.
The risk register is ISO 27001. The "I" in ISO doesn't stand for Internet, it stands for international. You shouldn't be doing business with international customers if you don't have a risk register, which is why they're requesting it.
Shouldn’t according to who? Who appointed ISO to say what should and shouldn’t be done?
Re: Delve – Fake Compliance as a Service
#267Re: Delve – Fake Compliance as a Service
#26880% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
That’s the only actual audit on “security”.
AI pentesting is just another SaaS.
Delve tried to automate the CPA, you can’t automate the audit. Same goes for the penetration test.
Re: Delve – Fake Compliance as a Service
#269Earlier quoted context omitted.
Yes, but your team claimed this set off "voting ring" behavior [0] and it was suppressed for nearly a day because of that. I am very curious how you determine what is, or is not, "voting ring" behavior. I believe Dang is responding in another thread about that. [0]: https://news.ycombinator.com/item?id=47457689
Obviously we don't publish how HN's voting ring detector works. If we did, it would quickly stop working. What matters in this case is (1) it's a software penalty that has nothing to do with the content of a story, (2) moderators didn't touch the submissions or even know they existed, and (3) once we did know that they existed, we merged the threads and placed the story on the frontpage - that is, we went out of our…