Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

291–300 of 327 posts

Re: Delve – Fake Compliance as a Service

#291

Earlier quoted context omitted.

Shouldn’t according to who? Who appointed ISO to say what should and shouldn’t be done?

The majority of countries that do business today have backed it. You are welcome to ignore it and work against the 160 countries that are using it.

who. Countries are not people.

Re: Delve – Fake Compliance as a Service

#292
post #130

Earlier quoted context omitted.

HN would be an entirely different place if people could just arrange to get their stuff upvoted onto the front page! We've spent hundreds of hours working on this over the years. Still not perfect of course.

My theory is that a lot of people may have looked for a story like this on the home page and then searched ‘Delve’ to see if anything was submitted recently and then upvoted one of those recently submitted posts.

Yeah, I saw comments discussing delve in another HN story's comments, then searched HN to find this

Re: Delve – Fake Compliance as a Service

#294

Earlier quoted context omitted.

Well, yes, but that's the point of many contracts, they are often designed to shift risk to parties that are better equipped to handle those risks. We run our app on GCP because as a 20 person company I don't want to be responsible for physical security and a million other risks. With ISO27001 or SOC 2, I have more information about the other party's ability to manage those risks than just taking their word for it. I…

> With ISO27001 or SOC 2, I have more information about the other party's ability to ... spend time and money to emulate the asinine requirements of outdated standards instead of actually making the product better and more secure. > I'm trusting a third party auditor to vouch for them. Like Delve?

The standards are very sensible. If you can't be bothered to provide even simple evidence that your employees are using basic harddrive encryption, use password managers, and your product has backup in place, I don't want to do business with you.

And Delve isn't an auditor. Though they were apparently in cohoots with equally criminal third party auditors. So I guess I'm going to be looking more closely at just exactly who exactly are auditing our vendors in the future...

Re: Delve – Fake Compliance as a Service

#295
post #3

Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.

FWIW I think the 30u30 to fraud pipeline is overstated. There are 600 people on the American Forbes 30u30 list every year (it's "30 under 30 each year in each of 20 categories"), with 20ish notable instances of fraud, so maybe a quarter percent of the people on the 30u30 list will later become famous for fraud.

Re: Delve – Fake Compliance as a Service

#296

Earlier quoted context omitted.

Most people only care about compliance if it stops them from closing a deal. I was at a startup where some enterprise said we needed a SOC 2. The founder talked them out of it by giving them a discount if they'd waive the requirement.

My company is tiny (just me) and at one point a client sent over a questionnaire that I needed to fill out. Half the things I already did, about 1/4th I did right then so I could check the box (added features/reports/etc), and the last 1/4th I looked into (including SOC2) and decided I’d rather lose the deal than try to do those things. I was completely truthful in the questionnaire and for those sections I just put…

> I ended up getting the contract and they never asked for those extra things.

Same boat about 2 years ago: the compliance is a lot more flexible than you would think - it doesn't matter if you have a poor password policy, what matters is that you document you have a poor password policy.

Your client didn't have to get a compliant vendor to remain compliant themselves; what matters to their compliance is formal attestations from their vendor about where they are not compliant.

As a 1-man show I went through the same thing, still got the contract even though I had to formally attest to not having maybe 25% of those boxes ticked. The whole point is that it is recorded that you don't have MFA, or that you failed a pentest on these 5 items... or that you have a vendor who fails these specific 43 requirements.

Re: Delve – Fake Compliance as a Service

#297
post #18

I remember having sales calls with them and the vibe was that it was "cheap and quick"... exactly what you want for your compliance

In a way, this may be a good thing for the 'compliance' ecosystem because it will prompt people to actually read the report and check the evidence, as opposed to trusting a badge.

If you read through the report PDFs of affected companies, you'll find a lot of stock wording and phrases that don't even make sense.

Re: Delve – Fake Compliance as a Service

#298

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…

There is no relation between checking a box and becoming legally responsible for the vast majority of certifications.

The company may be legally in troble if the planets are aligned but that's all.

Re: Delve – Fake Compliance as a Service

#299

Earlier quoted context omitted.

The majority of countries that do business today have backed it. You are welcome to ignore it and work against the 160 countries that are using it.

who . Countries are not people.

You can just Google this. https://www.iso.org/who-develops-standards.html
Post reply on HN