Live data from Hacker News

Delve removed from Y Combinator

ycombinator.com

311–320 of 344 posts

Re: Delve removed from Y Combinator

#311

Earlier quoted context omitted.

We have done SOC2 and it's not fake. Its real and enforced some good practices and we spent a lot of time collecting evidence and submitting it. You can take it seriously or you can choose not to.

What evidence did you collect that was not automated?

A startup might have trouble with, and might not have enough automation for:

- proving churned customer data was deleted completely and within the agreed-on period of time

  - - not enough to have a record

  - - auditors will ask you to prove the data is not laying around
- proving all changes shipped are reviewed and linked to tracked work

- proving branch rules are set to require PRs and prohibit changing history on release/trunk branches

  - - auditors will ask you to show live that you can’t approve your own changes

  - - some auditors might ask you for an audit log to prove no unexpected branch rule changes occurred —- depending on the observation period, you might have to build your own audit log capture to prove this
- proving you performed penetration testing

- proving you performed a disaster recovery test in production with the frequency you claim (e.g. annually)

  - - running a DR test might be more than a few hours depending on your data size and level of infra automation

  - - this is often something that startups are ready to execute, but don’t invest a lot of time automating
- proving you have and enforce full-disk-encryption on all your employee laptops

  - - this is automated with MDM but a startup might not be running an MDM yet
- proving you are rotating credentials on the frequency you ascribe to in your policies

  - - automated reports are available for some credentials, e.g. AWS keys, but takes more work for smaller vendors

  - - even with AWS, you might discover you forgot to rotate something, and it might be because it’s non-trivial to execute
- perform quarterly access reviews

  - - some systems are more difficult/time consuming to inspect against your employee and permissions list

  - - ideally this is automated, but often times at a startup, you might not have fully automated authorization and access control, such that when employees change teams or leave the company, that you get notified and don’t miss it
- proving that you act on performance or reliability alerts

  - - auditors will ask you to show live some examples of past alerts and that someone handled it

  - - auditors will often ask you to show live that these alerts are consistently configured for all your production system —- startups might not have the alerting and PagerDuty-like setup be fully automated (e.g. with Terraform)

Re: Delve removed from Y Combinator

#312

Earlier quoted context omitted.

Nobody really tries to get technical people to do the work. Like cool, it's a great idea and would potentially produce positive results if done well, but the roles pay half the engineering roles, and the interviews are stacked towards compliance frameworks. There's very little ability to fix a large public company when HR is involved

Speaking as a technical (data) person currently working in internal audit for a not quite public company, it's not entirely uncommon. I do agree that the pay isn't great, but it's the fact that it's considered a cost centre that's been the issue for me.

Everything except for sales tends to be seen as a cost centre. It's ridiculous.

Re: Delve removed from Y Combinator

#314

Earlier quoted context omitted.

And they do not track the industry at all, at best they'll help you win the war of five years ago.

Imagine my face when I had to take periodic backups of stateless, immutable read-only filesystem, non-root containers for "compliance".

Maybe that's just a goid moment to review your _policy_. About a half of our compute is exactly that, and we just don't have to do this sort of backups, that'd be silly.

We don't deal with the military though, only fintech (prime brokers and major banks, funds) some government. Plenty of certifications (have someone all site all year round),!no silliness.

Re: Delve removed from Y Combinator

#315

Earlier quoted context omitted.

"I wish them well" is an idiom for "I never want to see them again". Kinda like "bless your heart", which means nothing of the sort.

Why do non-Southerners keep insisting on this? Bless your heart can be said sincerely or ironically, like pretty much any other phrase.

Yeah, it's a pretty versatile phrase that's hard to explain. But it does often have a connotation of childishness or naivety, even when used sincerely.

It is often used an expression of thanks or appreciation, but I associate that more with an elder speaking to someone younger.

Most of the time, it is an genuine expression of true empathy, but it's not uncommon to be used as a passive aggressive expression of false empathy. It's that childish connotation that give it the extra bite when used passive aggressively.

And that plausible deniability, where the phrase is used in a genuine context often enough that sometimes you can't tell that someone is throwing shade, is very much a reflection of southern culture.

Source: Grew up in Georgia and North Carolina, with some family in Alabama.

Re: Delve removed from Y Combinator

#316
post #299

The headline here says "Delve removed from Y Combinator", but the link doesn't go to a statement by Y Combinator. It goes to a 404. Is there reason to believe that Delve has been removed from Y Combinator, the organization, or is this more an announcement that Delve has been removed from Y Combinator's website?

404 == "removed from Y combinator"

Meaning what?

Re: Delve removed from Y Combinator

#317

Earlier quoted context omitted.

They’re responsible for the existence of scribd. Not aware of any other obviously socially net negative companies.

For the uninformed what’s the deal with scribd?

Scribd scrapes the web of all the .PDFs that it can find, then gates them behind a paywall and SEOs their way to the top of Google's rankings. That's it, that's all they do. They run a zero value tollbooth with other peoples' IP, taking advantage of users who don't have the search-fu to hunt down the documents themselves.

They should pretty much die in a grease fire.

Re: Delve removed from Y Combinator

#318

Earlier quoted context omitted.

They could. But they don't. I've seen this up close. The regulatory bodies as a rule are understaffed, overworked and underpaid. I'm sure they'd love to do a much better job but the reality is that there are just too many ways to give them busywork allowing the real crap to go unnoticed until it is (much) too late.

Because they’re put there as a box ticking exercise without ever being given the power or resources to be able to do damage or negatively impact the bottom line of the big rule breakers. It’s just supposed to maintain the appearance of doing something without ever supporting these activities for real. For the most part they are a true Potemkin village. If the risk is diffuse (just some average Joe suckers will lose m…

I hate to say this but I suspect you are right.

Re: Delve removed from Y Combinator

#319
post #117

Earlier quoted context omitted.

It's auditing, nobody that is good at doing anything goes to auditing, unfortunately its one of those jobs. I haven't interacted with any auditor that actually understood all they were auditing, some are better than others but the average is worse than almost any other job description I have dealt with.

The industry is paid to provide a fig leaf for shady practices. Everyone knows what's going on, no one is going to do anything about it unless governments step in and give regulators more resources and more teeth, and "errors" lead to prosecutions and jail time. None of those are likely. This is the industry that missed Enron, WorldCom, Wirecard, Lehman, and many others.

> Wirecard

Don't get me started. That hasn't even properly ended yet, the fall-out is continuing to today.

Re: Delve removed from Y Combinator

#320

Related from an hour earlier: Delve removed from YC website [archive.org] https://news.ycombinator.com/item?id=47634405

an example of why to avoid archive links in submissions (save 'em for comments), because the source link here will win.

Thanks! felt crazy linking to a 404 ;) live and learn
Post reply on HN