wenbin.org

1.1K posts

wenbin.org banner
wenbin.org

wenbin.org

@wenbinf

@listennotes: podcast search engine https://t.co/OK4kdUtGhS: used by 12k apps https://t.co/xTqg2HTkR8: serverless cms https://t.co/LJiKRIl9BT: audio to text 📧 [email protected]

Old Gold Mountain, 加利福尼亚共和国 Katılım Mayıs 2013
196 Takip Edilen1.7K Takipçiler
Sabitlenmiş Tweet
wenbin.org
wenbin.org@wenbinf·
Your overthinking is my opportunity.
English
3
47
226
0
Ashley Peacock
Ashley Peacock@_ashleypeacock·
Imagine if every npm package page had a built-in sandbox to test code instantly. I used @Cloudflare’s new Dynamic Workers to build exactly that. It bundles packages at runtime in rapid, isolated sandboxes.
English
16
24
268
28.6K
wenbin.org retweetledi
wenbin.org
wenbin.org@wenbinf·
what if SOC 2 itself is a scam? people need to pretend to be busy to do “work” some made up things create busyness , which looks like “work”
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
0
0
0
163
wenbin.org retweetledi
wenbin.org
wenbin.org@wenbinf·
@a16z The world is a museum without walls.
English
0
0
0
81
a16z
a16z@a16z·
The world is a museum of passion projects
a16z tweet media
English
41
564
3.8K
111K
wenbin.org
wenbin.org@wenbinf·
@aarondfrancis Welcome to the era of LLMs training on AI slop. Apple Podcasts has quietly become a massive repository for ai slop : spam, scams, and gambling sites etc. - and they will feed to training data of new versions of LLMs
wenbin.org tweet media
English
0
0
3
514
Aaron Francis
Aaron Francis@aarondfrancis·
Codex is randomly hitting me with some ancient wisdom... for some reason.
Aaron Francis tweet mediaAaron Francis tweet media
English
127
133
2.1K
412.1K
wenbin.org retweetledi
Listen Notes - Podcast Search & PodcastAPI.com
AI slop is invading every corner of the web At @ListenNotes , we're seeing fake "listeners" request to add AI-generated fake shows that turn out to be the creators themselves. They use ai slop to do bad things e.g., spamming, scamming, etc.
shadcn@shadcn

Mass-generating PRs with your agents and clawbots isn't helping open source. It's quietly burning out the people who actually maintain it. Please stop.

English
0
1
3
181
wenbin.org
wenbin.org@wenbinf·
unix philosophy is timeless cli composability was made for the ai era
English
0
0
1
78
wenbin.org retweetledi
Zineb Riboua
Zineb Riboua@zriboua·
My latest Under Beijing’s Wing: Iran’s Arsenal Addressing the Fatal Flaw Every Iranian salvo forces the United States to reveal electronic warfare capabilities, radar signatures, and interceptor performance data in real combat conditions, giving Chinese military intelligence a live laboratory to study American defense systems without ever confronting them directly. zinebriboua.com/p/under-beijin…
English
34
147
478
169.7K
wenbin.org retweetledi
Alfred Lin
Alfred Lin@Alfred_Lin·
As a founder, you can get a lot of things wrong. But if you're unwiling to die, it will eventually work out. Be optimistic, and try to be right. But even if you're not right, don't die.
English
52
96
1.3K
233.2K
signüll
signüll@signulll·
okay, besides frontier labs, what’s the most anti fragile entity in the ai era?
English
162
2
304
88.8K
Matthew Prince 🌥
Matthew Prince 🌥@eastdakota·
What legacy web software should we rebuild on @Cloudflare Workers next to make faster and more secure? Post your requests! At $1,100 and a week’s work each, we’ve got time and budget to do a bunch…
English
294
33
878
136.1K
Cloudflare
Cloudflare@Cloudflare·
Create Your Dream Project on Cloudflare
English
4
3
49
416.8K
wenbin.org
wenbin.org@wenbinf·
Why haven't @Microsoft / @github evolved Hubot into a personal AI assistant (like OpenClaw)? Hubot had a ~15-year head start in ChatOps... and back when Slack blew up (~2014), the Slack+Hubot integration was quite good. Feels like a missed opportunity!
English
0
0
0
157
wenbin.org
wenbin.org@wenbinf·
@jeff_weinstein @atlas When a startup needs to buy out early SAFEs, it usually signals stalled growth. We need a standardized cancellation tool. Spending heavy legal fees on tiny checks is a waste for everyone - stressed, first-time founders are so vulnerable to predatory terms during a buyout.
English
0
0
1
44
wenbin.org
wenbin.org@wenbinf·
@jeff_weinstein @atlas It would be great to have a one-button SAFE cancellation tool. Might be niche, but imagine a startup needing to buy out early investors a few years after the fundraise…
English
1
0
2
53