Ali Shobeiri

1.1K posts

Ali Shobeiri banner
Ali Shobeiri

Ali Shobeiri

@Ali_Shobeiri

Technical Staff at @perplexity_ai Previously did YC company, ML at Apple and grew up in Canada

San Francisco, CA 参加日 Mart 2013
441 フォロー中3.8K フォロワー
固定されたツイート
Ali Shobeiri
Ali Shobeiri@Ali_Shobeiri·
I just cloned myself using @OpenAI and every text message I sent since I was 12. I fine-tuned gpt-4o-mini on 150,000 of my text messages. The first model ended up being so unhinged that I could not release it publicly (or risk being cancelled forever). So I had to train another one, on almost all my text messages. And this one you can try for yourself in the thread below
Ali Shobeiri tweet media
English
20
3
135
57K
Barry McCardel
Barry McCardel@barrald·
I love imagining the customer for whom SOC 2 was vitally important – but who was also paying an enterprise contract for Cluely
English
1
0
5
156
Barry McCardel
Barry McCardel@barrald·
there's something truly sublime about cluely being scammed on their SOC 2
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
1
2
56
4.1K
Ali Shobeiri
Ali Shobeiri@Ali_Shobeiri·
@natjin thank you 🙏 i like to think I am the modern day Mark Twain
English
0
0
1
6
nat
nat@natjin·
@Ali_Shobeiri ooo good observation + pattern match! evolving from 'coldest summer is in sf'
English
0
0
1
59
Ali Shobeiri
Ali Shobeiri@Ali_Shobeiri·
time to rip some peptides and lock tf in
English
0
0
11
193
Beff (e/acc)
Beff (e/acc)@beffjezos·
Perplexity Computer in Slack is pretty cracked
English
12
7
204
21.5K
Ali Shobeiri
Ali Shobeiri@Ali_Shobeiri·
most people don't realize what's happening in the Strait of Hormuz 20% of the world's oil ($2B/day) used to flow through each day On March 12th, that number went to 0 for the first time in recorded history in 17 days, gas prices have spiked ~27% and there doesn't seem to be an end in sight
Ali Shobeiri tweet media
English
2
0
13
344
Ali Shobeiri
Ali Shobeiri@Ali_Shobeiri·
@gabriel1 the greatest feeling is when you get Claude to simplify it's code and remove nested if statements
English
0
0
1
199
gabriel
gabriel@gabriel1·
i find great success with standalone "cleanup prompts" to my prs. you can stuff every rule you got into agents.md, but beautiful code is secondary until it's the only focus for example: "simplify all code so it's extremely easy to consume, remove not strictly necessary code"
English
24
5
358
19.1K
Max Brodeur-Urbas
Max Brodeur-Urbas@MaxBrodeurUrbas·
attention all Canadian builders (in SF and in 🍁) -we're hosting a 🇨🇦 demo night at our new SF HQ -we're picking 2 Canadian builders to fly out for free if you want a free trip to sf comment what you're working on, i'll dm you march 26th nice people, nice food and nice demos
Max Brodeur-Urbas tweet media
English
80
22
236
12.9K
Morph
Morph@morphllm·
Introducing FlashCompact - the first specialized model for context compaction 33k tokens/sec 200k → 50k in ~1.5s Fast, high quality compaction
English
75
136
2.1K
207.1K
Ali Shobeiri
Ali Shobeiri@Ali_Shobeiri·
SF spends $101,682 per homeless person per year. SF median household income is $140,970. The city spends 72 cents on each homeless person for every dollar the median household earns. And $101,682 is a floor. It excludes DPH behavioral health (~$100M/yr), MOHCD supportive housing, Public Works, and SFPD costs. Spending tripled since FY2019. The homeless population barely moved.
Ali Shobeiri tweet media
Charlie Smirkley@charliesmirkley

NYC spends more per homeless person than the median NYC household earns. $81,705 per person in FY2025. And $81,705 is a floor. It excludes supportive housing (~$500M/yr), mental health response teams, and NYPD encampment costs. The city projects ~$97K per person in FY2026.

English
0
0
6
379
Ali Shobeiri がリツイート
Perplexity
Perplexity@perplexity_ai·
Computer can now take full control of Comet to complete tasks. When you’re in Comet, Computer spins up a browser agent that can access any site or logged‑in app with your permission, without the need for connectors or MCPs. Available to all Computer users on Comet.
English
162
179
2.1K
337.3K
Ali Shobeiri
Ali Shobeiri@Ali_Shobeiri·
@eve_bouff @soleio Built by the great iOS team actually, don’t want to take credit for their work 🙏
English
0
0
0
13
Ali Shobeiri
Ali Shobeiri@Ali_Shobeiri·
This was a fun one to build. Computer on Slack can turn a Slack thread into a pull request using Claude Code + Codex. When someone reports an issue, I tag Computer. It investigates the problem, then Claude Code + Codex open the PR and review each other’s work until they’re happy with the result. Saves hours a day and reduces context switching.
Aravind Srinivas@AravSrinivas

Slack is going to be the interface for AI in the enterprise. And Perplexity Computer fits in very naturally into that interface. The next multi billion dollar and trillion dollar companies are all running on Slack and will see more tasks delegated to AIs than humans.

English
0
2
24
1.9K
Ali Shobeiri がリツイート
Denis Yarats
Denis Yarats@denisyarats·
This isn’t accurate. The secure sandbox of Perplexity Computer creates a temporary proxy token for every user session. We choose not to hide it from the user because it’s their token. (They can do whatever they want with it, but I don’t recommend posting it on X) It’s not an API key, it’s a short-lived proxy token associated with the session and user. It’s located in the sandbox, because that’s the point of the sandbox. Anything run through it is billed back to your account. Billing is async, which may have caused this user’s confusion. Don’t worry, as soon as we saw this post we ensured this user’s session token was revoked for security. The session he describes generated 197 billing events. We shared billing details with him directly but can’t publicly. (Billing is done at the proxy, and every cost is attached to the proxy token.) Thank you @YousifAstar for creative security research and collaborative spirit. Everyone else - email is a slow way to reach us! We have a thriving VDP that helps keep all of our products secure. perplexity.ai/hub/security-v…
Yousif Astarabadi@YousifAstar

x.com/i/article/2032…

English
59
67
1.4K
363.8K
Casey Neistat
Casey Neistat@Casey·
there are only two circumstances wherein a grown man should call another grown man 'buddy'; 1. if you want to fight 2. if you want to condescend, before you fight
English
510
196
4.8K
467.5K