First Class Duck

46.9K posts

First Class Duck banner
First Class Duck

First Class Duck

@FirstClassDuck

an opinionated and jaded traveler

New York, USA Присоединился Şubat 2013
242 Подписки412 Подписчики
Закреплённый твит
First Class Duck
First Class Duck@FirstClassDuck·
@chait76 @antoniogm Honestly, just work hard, save your money, support your friends and family, be a friendly and compassionate person, and avoid being bitter. Just avoid chasing women for sex, and you’ll live a happy and healthy life. Just keep some platonic friends for brownies. :-)
English
6
3
35
0
First Class Duck ретвитнул
Christy LaMonde | Ms. Canada First 🍁
*discussion with coworker who is pro communism* Me: Have you read The Communist Manifesto? Coworker: No. Why would I? Me: So you know what communists stand for. Coworker: Well idk, it might be biased against communism. Is it written by a capitalist or a communist? Me: Coworker: Me: It's by Karl Marx. Coworker: Who's that? Me:
GIF
English
222
455
4.9K
56.5K
First Class Duck ретвитнул
Kyle Mann
Kyle Mann@The_Kyle_Mann·
When Chuck Norris arrived in heaven, he was the one who had to tell the angels, "Fear not."
English
72
1.1K
7.5K
148.3K
First Class Duck ретвитнул
🫧
🫧@UStwts__·
@space_colonist At this point the only subscriber to Forbes 30u30 is probably the FBi’s fraud unit.
English
1
2
60
7.3K
First Class Duck ретвитнул
Ryan
Ryan@ohryansbelt·
@tenobrus @getdelve @karunkaushik_ @kocalars For those who are curious about what happened, wrote a breakdown here x.com/ohryansbelt/st…
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
0
5
110
39K
First Class Duck ретвитнул
Dead Hardware
Dead Hardware@deadhardware·
@anammostarac VC's when they find out their favorite founder has just been placed on the Forbes 30 Under 30 list:
GIF
English
0
2
9
523
First Class Duck ретвитнул
Maybee
Maybee@maybeeai·
@anammostarac At this point, Forbes 30 Under 30 is starting to look less like a list and more like a warning label.
English
0
3
82
1.9K
First Class Duck ретвитнул
Ramon Mühle
Ramon Mühle@LoLStatsGuy·
@TheStalwart Same in Germany. Trump may be responsible for the biggest dent in CO2 emission growth.
Ramon Mühle tweet media
English
1
5
20
1.6K
First Class Duck ретвитнул
Joe Weisenthal
Joe Weisenthal@TheStalwart·
WOW. Just in the last two weeks, BYD showrooms around the world are seeing a surge in customer demand from people who are deciding that now is the time to switch to EVS, with oil prices so high. bloomberg.com/news/articles/…
Joe Weisenthal tweet media
English
60
515
2K
370.4K
First Class Duck
First Class Duck@FirstClassDuck·
@moseskagan @atlanticesque Nobody trusts the market because the market won't deliver charming brownstones at $200/month while paying upper middle wages to every white collar worker. They can't be artists, especially in a high cost city like NYC or SF, and afford market anything.
English
0
0
0
77
First Class Duck ретвитнул
Moses Kagan
Moses Kagan@moseskagan·
@atlanticesque The fundamental question is: Do you trust that the market will provide (with some reasonable guardrails), or not? There are very smart people who, for whatever reason, just can not understand that good things can come from lots of individuals acting selfishly.
English
7
4
97
2.1K
𝖓𝖎𝖓𝖊 🕯
𝖓𝖎𝖓𝖊 🕯@atlanticesque·
Republicans get *tons* of stuff wrong. Tons. But they tend to govern better because they get the basics right. Most smart policy people are Democrats, but because Democrats get so many fundamental aspects of governance wrong, they're fighting a wicked uphill battle.
Hunter📈🌈📊@StatisticUrban

Every single one of the 15 fastest-growing US major metropolitan areas is in the Sunbelt. All 15 are also in a state Trump won. Only 5 are in swing states. Dallas and Houston added an entire Wyoming's worth of people.

English
101
130
2.3K
180.2K
𝖓𝖎𝖓𝖊 🕯
𝖓𝖎𝖓𝖊 🕯@atlanticesque·
@SukritGanesh If I were to be pedantic, I'd still hold that the last rapid transit *systems* was either WMATA or MARTA, both in the 1970s. A political eon ago, and the latter frankly nothing to be proud of.
English
4
0
24
1.1K
First Class Duck
First Class Duck@FirstClassDuck·
@taipan168 You can pry my gas car from my cold dead hands. :-) With that said, just as the 1970s oil crisis made Japanese cars into the standard for affordable and fuel efficient motoring in North America, this crisis could do the same for Chinese electric cars on a global basis.
English
1
0
0
28
First Class Duck
First Class Duck@FirstClassDuck·
@nobodyknows2322 Hey, some of us live in a coastal city fearing hurricanes! With that said, the fact that the poorest in developing countries are the most likely to suffer fuels their idea that the West must sharply reduce carbon output for moral reasons.
English
0
0
0
34
First Class Duck
First Class Duck@FirstClassDuck·
@ajlamesa @headwaysmatter In theory, Japan is probably the closest case for California, but the Japanese will sell CAHSR’s board on doing things the Japanese way which may lead to vendor lock-in… Otherwise, the Germans and Italians could consult on routes crossing the Appalachians…
English
0
0
1
10
Anthony LaMesa
Anthony LaMesa@ajlamesa·
@headwaysmatter where would we need a serious base tunnel of this scale? maybe Phoenix to LA? Pittsburgh to Cleveland? The CAHSR critics claim that seismic issues in California mean their (hypothetical) tunnels aren't remotely comparable.
English
1
0
1
23
Anthony LaMesa
Anthony LaMesa@ajlamesa·
Substantial progress being made on the new base tunnel that will link the French and Italian high-speed rail systems -- slashing journey times between Lyon and Turin (and Paris and Milan). youtube.com/watch?v=Q0NAE2…
YouTube video
YouTube
English
1
0
3
468