Sparc Flow

464 posts

Sparc Flow banner
Sparc Flow

Sparc Flow

@sparcFlow

H4cker, author of How to Hack Like a Pornstar https://t.co/VvRLVM6MUB & How to Hack Like a Ghost https://t.co/DXpFnQ3rYR https://t.co/IrQjsNwxGV

Katılım Şubat 2017
114 Takip Edilen3.2K Takipçiler
Sabitlenmiş Tweet
Sparc Flow
Sparc Flow@sparcFlow·
My new book Blitzscaling Security is now available. Dive into the mind of Alex, the first security engineer at a scale-up, & experience the brutal truth behind designing a security that protects and boosts the business The gloves are off with this one :) amazon.com/dp/B0C4LC4FDW
English
5
3
34
10.2K
Sparc Flow
Sparc Flow@sparcFlow·
I mean yes it’s a scandal, but having gone through actual soc 2, iso 27001, pci dss and other types of audits, i don’t see how this is radically different than what auditors do. Do people really think that an ISO auditor actually looked properly at system configs and ran deep and proper technical checks ? Most of these certs are rubber stamps anyway, this is just a step up in terms of the compliance charade.
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
0
0
2
278
Sparc Flow
Sparc Flow@sparcFlow·
Python 3.13 tightened ssl validation requiring an additional extension in certificates. Good right? Wrong. no one is gonna go through the pain of rotating their CA just for a silly obscure extension that barely prevents any real world attack, so there will be a wave of verify_ssl=false in codebases. Typical example of narrow security thinking and opposite consequences
English
0
0
4
190
Sparc Flow
Sparc Flow@sparcFlow·
The article assumes humans stop adapting, capital gains vanish, and markets freeze. You cannot delete incentives from the model, have everyone passive, make AI the only dynamic player and build predictions. That’s simply the wrong world model. Thousands of years of history say otherwise.
Citrini@Citrini7

JUNE 2028. The S&P is down 38% from its highs. Unemployment just printed 10.2%. Private credit is unraveling. Prime mortgages are cracking. AI didn’t disappoint. It exceeded every expectation. What happened?​​​​​​​​​​​​​​​​ citriniresearch.com/p/2028gic

English
0
0
1
230
Sparc Flow
Sparc Flow@sparcFlow·
The article assumes humans stop adapting, capital gains vanish, and markets freeze. You cannot delete incentives from the model, have everyone passive, make AI the only dynamic player and build predictions. That’s simply the wrong world model. Thousands of years of history say otherwise.
English
0
0
0
514
Citrini
Citrini@Citrini7·
JUNE 2028. The S&P is down 38% from its highs. Unemployment just printed 10.2%. Private credit is unraveling. Prime mortgages are cracking. AI didn’t disappoint. It exceeded every expectation. What happened?​​​​​​​​​​​​​​​​ citriniresearch.com/p/2028gic
English
1.9K
4.3K
27.9K
28.5M
Dean W. Ball
Dean W. Ball@deanwball·
This is probably the most believable piece of AI scenario modeling, positive or negative, I have ever read. Plenty of contestable assumptions, of course, but undoubtedly worth your time.
Citrini@Citrini7

JUNE 2028. The S&P is down 38% from its highs. Unemployment just printed 10.2%. Private credit is unraveling. Prime mortgages are cracking. AI didn’t disappoint. It exceeded every expectation. What happened?​​​​​​​​​​​​​​​​ citriniresearch.com/p/2028gic

English
49
72
1.7K
957.5K
Sparc Flow
Sparc Flow@sparcFlow·
@Money7218 My goal was to capture hacker thought patterns and ways of thinking. The tech is just an excuse to illustrate that. So hopefully very relevant in that regard. Hack like a ghost is closer to what you’ll see in a cloud environment however.
English
0
0
0
44
E Money
E Money@Money7218·
@sparcFlow I was just wondering if this book still relevant or is it outdated?
English
2
0
0
20
Sparc Flow
Sparc Flow@sparcFlow·
@Jason @theallinpod Welfare state => more attempts to illegaly immigrate => bigger voter base for those that allow them in. Yes it’s that simple indeed, just follow the incentives.
English
0
0
0
6
The All-In Podcast
The All-In Podcast@theallinpod·
David Sacks: “ The Democrats want to thwart mass deportations because illegal immigrants are a vital part of their power base.” 🚨 “And you can see this in the 2030 apportionment forecast, which just came out.” “Illegal aliens count towards the census, which occurs every decade, and the census determines the apportionment of congressional seats and electoral votes.” “And what you see in these maps is that citizens of blue states have been migrating to red states because those blue states are failing.” “As a result of that, blue states are expected to lose nine house seats and electoral votes because of the changing population numbers.” “Illegal aliens in blue states have been propping up those numbers, and so for example, in the last election, President Trump would've won an additional nine electoral votes if we had an accurate accounting.”
English
817
5.5K
17.8K
5.8M
Sparc Flow
Sparc Flow@sparcFlow·
@eastdakota They are. Build a search engine and compete. That’s the essence of capitalism. Everyone is free to compete to the best of their abilities.
English
0
0
0
182
Matthew Prince 🌥
Matthew Prince 🌥@eastdakota·
We cannot have a fair market for AI when Google leverages their search monopoly to see 3.2x as much of the web as OpenAI, 4.8x as much as Microsoft, and more than 6x as much as nearly everyone else. Most data wins in AI. Google needs to play by the same rules as everyone else.
Cloudflare@Cloudflare

Google's dual-purpose crawler creates an unfair #AI advantage. To protect publishers and foster competition, the UK’s Competition and Markets Authority must mandate crawler separation for search and AI. cfl.re/4t84kPz

English
145
62
983
635.7K
Sparc Flow
Sparc Flow@sparcFlow·
Prompt injections through zendesk tickets, feature requests, free text fields in the app…we’re not ready for the mess this will cause via claude code directly hooked to these attacker-controlled sources. @bcherny legit question: how do you think about that ? You see a world where LLMs (or the underlying tooling) will distinguish data from actual context ? (Replay of parametrized statements)
English
0
0
2
181
Sparc Flow
Sparc Flow@sparcFlow·
Reading about cowork, clawedbot, etc
Sparc Flow tweet media
English
0
0
2
399
Pedro Domingos
Pedro Domingos@pmddomingos·
I’ve never seen an LLM come up with a new concept.
English
683
110
1.8K
188.4K
Massimo
Massimo@Rainmaker1973·
Massimo tweet media
ZXX
540
11
200
51.4K
Dayhta
Dayhta@0Dayhta·
Security salaries in 2026 are completely broken. I know people making $250k who can't exit vim, and people making $80k who are finding zero-days. We need to talk about this.
English
67
69
1.1K
103.4K
Sparc Flow
Sparc Flow@sparcFlow·
@QuinnyPig @OpenAI Yes but there is also an interesting element to it: «  we scaled PG as much as we could and now are hitting a wall where any cache miss/small schema change can bring us down ». Nice post that will ground people with 100 times less trafic and worry about the wrong things.
English
0
0
7
1.2K
Corey Quinn
Corey Quinn@QuinnyPig·
This is genius in its simplicity. They’re not using exotics. It’s just… best practices. Ten years of “shard everything, adopt NoSQL, go distributed, sacrifice a goat to CAP theorem,” and here’s @OpenAI serving a billion users with “have you tried adding read replicas?”
Ben Dicken@BenjDicken

OpenAI just published a great article on scaling Postgres. The right combination of proxies, read-replicas, and sharding can take you to millions of QPS.

English
32
42
631
118.4K
Sparc Flow
Sparc Flow@sparcFlow·
« Basic Economics » changed my thinking and perception of the world, governance and incentives in a way that very few books ever did.
English
0
0
1
143
Sparc Flow retweetledi
Josh Elman
Josh Elman@joshelman·
One of the best explainers of how LLMs work overall that I have read - and it explains KV caching too ngrok.com/blog/prompt-ca…
English
12
127
1.3K
150.2K