Spud

10.2K posts

Spud banner
Spud

Spud

@SpudSecurity

Leftist who likes to annoy fascists | He/them | Looking for a muscle mommy or daddy for uppies | Queer | Will break embedded systems for Red Bull | car guy

Stuck on the beltway, VA Katılım Ocak 2016
665 Takip Edilen548 Takipçiler
Sabitlenmiş Tweet
Spud
Spud@SpudSecurity·
Hello to all the new people following me! My name is spud. I stop hackers and hack embedded systems. Can’t talk about my job so I spend my days occasionally talking about infosec but mostly annoy fascists/TERFs and post cat and train pics. Welcome!
English
0
0
18
3.7K
Spud
Spud@SpudSecurity·
I have no words. Absolutely incredible.
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
0
0
1
28
Spud retweetledi
Max Dubler, AICP 🏳️‍🌈
The backstory here is that the Squamish people of what is now Vancouver were illegally dispossessed of this land a century ago. They sued, got their land back, and used their sovereignty to ignore local zoning rules and build 6,000 new homes over the objections of nearby NIMBYs.
The Vancouver Sun@VancouverSun

Sen̓áḵw Towers set to open 113 years after Squamish people forced from site vancouversun.com/news/local-new…

English
89
928
13.3K
497.5K
Spud
Spud@SpudSecurity·
@notsyllytyler There’s literally a stop next to the stadium already.
English
1
0
14
764
tyler⚙️🍉
tyler⚙️🍉@notsyllytyler·
Ugly and should not be allowed. We have commuter stations with massive parking garages that are never used. Park there, take the train to the stadium. Anything less is an abdication of both our duty to the environment and the project of keeping DC beautiful.
Cuneyt Dil@cuneytdil

The Commanders want to build massive parking decks, up to 110 feet or 11 stories tall, new filings show. Renderings don't do it justice but it'll poke out in the skyline. axios.com/local/washingt…

English
21
91
1.4K
39.6K
Spud
Spud@SpudSecurity·
My parents had the Chevy equivalent of the beige one and that thing was so goated. On our trips to Orlando we’d pack the SNES or N64 into the back of that and played the shit out of some Mario kart and whatnot. It was awful performance and mechanical wise but I do miss it
lusso@luusssso

It’s the late 20th century You’re on a road trip sitting high in the captain’s chair The carpeted interior is under your feet as your watch a VHS on the 8” TV mounted in front of you The window curtains are pulled shut creating the coziest of vibes Easily a top 5 American experience

English
1
0
5
147
Spud
Spud@SpudSecurity·
@TheBestBradlee I think more like they think its childish and unprofessional
English
0
0
0
2
Spud
Spud@SpudSecurity·
I have a whole fucking decade of experience in this field with commendations from the USSS and Marine Corps generals. I have more stickers than I know what to do with. I’m sorry nobody invites you anywhere.
Dmitriy Kashirin@DKDevTalks

@endingwithali I can’t recall seeing experienced engineers, pentesters, or hackers with stickers, but I’ve seen plenty of inexperienced form monkeys with laptops covered in stickers.

English
2
0
19
933
Spud
Spud@SpudSecurity·
@klrgrz @Unit42_Intel Oh heck. I’m applying but I’m 100% a great fit I have experience with this on the government side in IR for various agencies. I’d love to chat!
English
3
0
9
148
Spud
Spud@SpudSecurity·
@algxtradingco @gorillaz4Sale @electrifying "you don’t need to advertise or anything like that, you should try, see if you can do something that has any value" > advertises on twitter > website isn’t in use > hasn’t posted content in forever > nobody is buying your products based on the comments on said product.
English
2
0
2
43
Spud
Spud@SpudSecurity·
@algxtradingco @gorillaz4Sale @electrifying > "people are still gonna use my stuff" You stopped your ai slop grift at least a year ago and I’ve had shitty train videos have more viewers than your most viewed video.
English
3
0
2
51
Spud
Spud@SpudSecurity·
@algxtradingco Well no it’s the end of day you just keep saying you’re very busy but somehow not busy enough
English
2
0
2
25
Spud
Spud@SpudSecurity·
Oh he’s also mentally unwell too. That’s unfortunate
English
0
0
1
15
Spud
Spud@SpudSecurity·
@algxtradingco Wait then why do you care about "sexless parties" if you’re so busy?
English
0
0
2
22