tunient

11.3K posts

tunient

tunient

@tunient

having fun email: tun(at)airmail(dot)cc, tunient(at)proton(dot)me bsky: https://t.co/nRQx9ns7dV

Katılım Ekim 2021
497 Takip Edilen1.4K Takipçiler
Sabitlenmiş Tweet
tunient
tunient@tunient·
if you want to contact me, please email me: tun(at)airmail(dot)cc
English
3
1
38
47.2K
tunient
tunient@tunient·
@poiThePoi ig maybe this means more work for governance, risk, and compliance professionals (at reputable firms)
English
1
0
2
34
Poi
Poi@poiThePoi·
The funniest bit of this is that because of things like this, no one trusts your SOC2 compliance report and so then they ask you for all of the evidence. So you poisoned the commons and it didn't even work.
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
1
2
11
637
tunient
tunient@tunient·
@animalologist personally i feel like it'd feel routine after the first few times and wouldn't really transfer to other fears. ig it's a pretty good deal if the falling is guaranteed to be harmless
English
1
0
75
3.5K
Samnite
Samnite@LastPopo·
@dhaaruni @climatepaige Anecdotally, almost every Chinese guy I know has a thing for blondes even if they aren’t dating one
English
1
0
1
49
Angelica 🌐⚛️🇹🇼🇨🇳🇺🇸
Did YOU want to watch CCTV's AI Martial Arts cartoon about the Straits of Hormuz crisis? Complete with fighting Persian Cats? Well I subtitled it for you so you can enjoy it in all its trope-laden glory! Remember kids, the mountains will stay standing while the green water flows, and the true art of war is not figuring out how to fight, but how to stop!🥷😼🦅
Steve Hou@stevehou

Chinese state media made an AI-generated cartoon about the US-Iran conflict. Extremely well done!

English
151
885
3.1K
303.8K
kat
kat@transkatgirl·
my friend has a macbook with 128 gb of ram, and apparently firefox is using ALL of it they tried to close out firefox like 10 minutes ago but it’s still not finished shutting down
English
9
0
55
3.6K
Melian Refugee
Melian Refugee@escapefrommelos·
When you read about the early history of the Spanish conquest of the Americas, you realize Certain Things about Latin America... From Michele de Cuneo, a Spanish nobleman in Columbus’s second expedition to the Americas: "While I was in the boat, I captured a very beautiful woman, whom the Lord Admiral [Columbus] gave to me. When I had taken her to my cabin she was naked — as was their custom. I was filled with a desire to take my pleasure with her and attempted to satisfy my desire. She was unwilling, and so treated me with her nails that I wished I had never begun. I then took a piece of rope and whipped her soundly, and she let forth such incredible screams that you would not have believed your ears. Eventually we came to such terms, I assure you, that you would have thought she had been brought up in a school for whores."
English
309
371
11.6K
1.8M
disc : sf rn!
disc : sf rn!@arabelladevine·
on hinge rejecting dozens and hundreds of men with practised rapidity muttering you are not my pervert protector you are not my pervert protector
English
8
1
97
3.2K
Kendra Barnett
Kendra Barnett@KendraEBarnett·
Totally normal and cool
Kendra Barnett tweet media
English
36
332
3.6K
251.5K
crystal
crystal@crystalxduan·
everyone else talks about how chinese they're becoming but they never talk about how chinese they're being
English
2
0
24
616
☾
@untamedyouths·
I MISS THEM 😭😭😭😭
English
6
438
2.6K
380.4K
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
100% of the ppl I know with AI gf are still with AI gf. Worrying trend for women, who are getting locked out of these opportunities.
English
10
9
115
15.4K
Conrad Bastable
Conrad Bastable@ConradBastable·
@liminal_warmth This is true for everything btw! The vast corpus of web-related code online makes the AI a genius with it and an idiot without it. Eg it’s pretty bad with slides still but anything you could do with slides will now work as a standalone one-off internal webpage. HTML vindicated!
English
1
0
3
232
Liminal Warmth ❤️‍🔥
Liminal Warmth ❤️‍🔥@liminal_warmth·
Increasingly it seems like browser games are the way to go right now since the model can actually test them independently more easily with a variety of tools Kind of a shame that this is so much harder outside of browser frameworks
zebleck@zebleckAI

Plan the architecture of your vibecoded games thorougly from the start, it will compound a LOT. Because TinyRTS was already a deterministic simulation, we were able to implement a memory-efficient replay system in one shot! Keep in mind this is all running in the browser.🤯

English
2
1
45
2.6K
tunient
tunient@tunient·
@hiAndrewQuinn @GroovySciFi nice! how'd you get your 2nd, 3rd, and 4th passport if you're able to share? a lot of routes i'm aware of for people without ancestry seem to involve a large investment, living somewhere for a few years, marrying someone (or some combo)
English
1
0
4
261
Andrew Quinn
Andrew Quinn@hiAndrewQuinn·
@GroovySciFi raises hand, closing in on passport #4 this year. gets a lot tougher once you have to start learning new languages
English
1
0
19
4.8K
Baudrillard Forever
Baudrillard Forever@GroovySciFi·
I first encountered this type of person when I moved to Montreal. I became conscious of a nascent (post-Y2K) World Class. Multiple passport holders, credentialed parents, upper middle class to lesser wealthy.
Baudrillard Forever tweet media
English
54
89
4.2K
486.1K
tunient
tunient@tunient·
@Robotbeat @Noahpinion i wonder whether it should affect things like retirement savings and choice of account. idt i'm confident enough to stop saving money entirely but i'm more skeptical about 59.5 year old me existing and endorsing saving money now (not financial advice.) x.com/catehall/statu…
Cate Hall@catehall

In 2017 I was convinced AI timelines were <5 years so I cashed in my 401k and blew away the money and let me tell you this particular form of intellectual consistency is Not Recommended

English
0
0
1
34
Robotbeat🗽 ➐
Robotbeat🗽 ➐@Robotbeat·
@Noahpinion You can prune out any of the timelines where humans just don't exist. Not because they won't happen but because we won't be there to worry about it, so we don't need to plan for it (at least, not us little people). Therefore, plan for AI to be useful but not catastrophic.
English
2
1
16
926