frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

They were drawn to Korea with dreams of K-pop stardom – but then let down

https://www.bbc.com/news/articles/cvgnq9rwyqno
1•breve•2m ago•0 comments

Show HN: AI-Powered Merchant Intelligence

https://nodee.co
1•jjkirsch•4m ago•0 comments

Bash parallel tasks and error handling

https://github.com/themattrix/bash-concurrent
1•pastage•4m ago•0 comments

Let's compile Quake like it's 1997

https://fabiensanglard.net/compile_like_1997/index.html
1•billiob•5m ago•0 comments

Reverse Engineering Medium.com's Editor: How Copy, Paste, and Images Work

https://app.writtte.com/read/gP0H6W5
1•birdculture•10m ago•0 comments

Go 1.22, SQLite, and Next.js: The "Boring" Back End

https://mohammedeabdelaziz.github.io/articles/go-next-pt-2
1•mohammede•16m ago•0 comments

Laibach the Whistleblowers [video]

https://www.youtube.com/watch?v=c6Mx2mxpaCY
1•KnuthIsGod•17m ago•1 comments

Slop News - HN front page right now hallucinated as 100% AI SLOP

https://slop-news.pages.dev/slop-news
1•keepamovin•22m ago•1 comments

Economists vs. Technologists on AI

https://ideasindevelopment.substack.com/p/economists-vs-technologists-on-ai
1•econlmics•24m ago•0 comments

Life at the Edge

https://asadk.com/p/edge
2•tosh•30m ago•0 comments

RISC-V Vector Primer

https://github.com/simplex-micro/riscv-vector-primer/blob/main/index.md
3•oxxoxoxooo•34m ago•1 comments

Show HN: Invoxo – Invoicing with automatic EU VAT for cross-border services

2•InvoxoEU•34m ago•0 comments

A Tale of Two Standards, POSIX and Win32 (2005)

https://www.samba.org/samba/news/articles/low_point/tale_two_stds_os2.html
2•goranmoomin•38m ago•0 comments

Ask HN: Is the Downfall of SaaS Started?

3•throwaw12•39m ago•0 comments

Flirt: The Native Backend

https://blog.buenzli.dev/flirt-native-backend/
2•senekor•41m ago•0 comments

OpenAI's Latest Platform Targets Enterprise Customers

https://aibusiness.com/agentic-ai/openai-s-latest-platform-targets-enterprise-customers
1•myk-e•43m ago•0 comments

Goldman Sachs taps Anthropic's Claude to automate accounting, compliance roles

https://www.cnbc.com/2026/02/06/anthropic-goldman-sachs-ai-model-accounting.html
3•myk-e•46m ago•5 comments

Ai.com bought by Crypto.com founder for $70M in biggest-ever website name deal

https://www.ft.com/content/83488628-8dfd-4060-a7b0-71b1bb012785
1•1vuio0pswjnm7•47m ago•1 comments

Big Tech's AI Push Is Costing More Than the Moon Landing

https://www.wsj.com/tech/ai/ai-spending-tech-companies-compared-02b90046
4•1vuio0pswjnm7•49m ago•0 comments

The AI boom is causing shortages everywhere else

https://www.washingtonpost.com/technology/2026/02/07/ai-spending-economy-shortages/
2•1vuio0pswjnm7•50m ago•0 comments

Suno, AI Music, and the Bad Future [video]

https://www.youtube.com/watch?v=U8dcFhF0Dlk
1•askl•52m ago•2 comments

Ask HN: How are researchers using AlphaFold in 2026?

1•jocho12•55m ago•0 comments

Running the "Reflections on Trusting Trust" Compiler

https://spawn-queue.acm.org/doi/10.1145/3786614
1•devooops•1h ago•0 comments

Watermark API – $0.01/image, 10x cheaper than Cloudinary

https://api-production-caa8.up.railway.app/docs
1•lembergs•1h ago•1 comments

Now send your marketing campaigns directly from ChatGPT

https://www.mail-o-mail.com/
1•avallark•1h ago•1 comments

Queueing Theory v2: DORA metrics, queue-of-queues, chi-alpha-beta-sigma notation

https://github.com/joelparkerhenderson/queueing-theory
1•jph•1h ago•0 comments

Show HN: Hibana – choreography-first protocol safety for Rust

https://hibanaworks.dev/
5•o8vm•1h ago•1 comments

Haniri: A live autonomous world where AI agents survive or collapse

https://www.haniri.com
1•donangrey•1h ago•1 comments

GPT-5.3-Codex System Card [pdf]

https://cdn.openai.com/pdf/23eca107-a9b1-4d2c-b156-7deb4fbc697c/GPT-5-3-Codex-System-Card-02.pdf
1•tosh•1h ago•0 comments

Atlas: Manage your database schema as code

https://github.com/ariga/atlas
1•quectophoton•1h ago•0 comments
Open in hackernews

Tell HN: Compliance is not equal to Security

1•introvertmac•2mo ago
For over a decade, I’ve been doing bug bounty, security audits, and security consulting. And if there’s one thing I’ve seen repeatedly, it’s this:

Most startups call a security engineer or hire a security agency only when a compliance deadline is a few weeks or month away.

Whether it’s PCI DSS, ISO 27001, SOC 1, SOC 2, or the new push from the EU for MICA and DORA in the Web3 and Fintech spaces, the motivation is almost always the same. It’s a sales blocker, get it done!

In the last few years, I had the opportunity to consult for a few “fully compliant” startups that gave me deeper access: GitHub, read-only database access, CI/CD configs, etc.

That’s when things got interesting.

What I Found Inside ‘Compliant’ Startups

Here are some real examples (details anonymized):

1. Secrets lying around in GitHub repos: Even though the company had a dedicated secrets manager, old secrets, tokens, and environment variables were still scattered inside the repo — some untouched for years.

2. Non-engineering teams “vibe-coding” in public Replit: Because the company wanted “everyone to code,” non-engineers were experimenting on public Repl.it projects with ChatGPT API keys and MongoDB connection URLs. I stopped a potential data leak before DB connection URL became public.

3. A public Docker image sitting out there for 5 years: It had an old Zendesk API key inside it. Anyone could have pulled it, and with that, accessed user PII.

4. Multiple unreported exploits: Issues that would’ve become serious incidents and many unreported exploited issues, none of which were caught by their compliance process.

Yet this company was proudly:

“100% SOC2 compliant.”

And closing enterprise deals. They were green-lit 100% compliant on Vanta. They had their SOC 2 badges on the home page.

Compliance frameworks are not useless. They establish a necessary baseline, enforce good practices, and build a framework for trust. They answer the question, “Do you have a process?”

But they do not answer the critical questions: “Is your team following that process right now?” or “What chaos did innovation create yesterday that exists outside the process?”

Compliance auditors check if you have the right documents, policies, and controls at the moment of audit. Attackers look for misconfigurations, forgotten credentials, abandoned code, and human mistakes every single day.

A company can be “fully compliant” and still be one bad commit away from a major breach.

A Simple Rule Founders Should Use When evaluating a startup or when building your own:

Don’t judge security by compliance certificates or shiny 100% compliant Vanta dashboards. Judge by the number of full-time security engineers relative to the team size.

A company with 0-1 security engineer and a SOC2 certificate is not secure. They’re just compliant.

Security is a continuous effort. It is significantly more affordable to build an in-house security culture and hire a full-time engineer than it is to pay a big name security agency for a panic audit, or worse, pay for a data breach cleanup.

If You’ve Read This Far: Thanks for listening to my rant.

If you are looking for a security consultant (who cares about more than just the checkbox), feel free to reach out at bhattacharya.manish8@gmail.com.

Comments

Hakashiro•2mo ago
Compliance is not security, but "security" is too nebulous of a term to actually implement effectively, so companies use the specific regulations and standards to have a measurable target to strive for.

In my company, we have additional security measures and guardrails on top of the bare minimum legally required, but most companies indeed see security as a cost center and decide not to invest until it's too late.