frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Compliance is not equal to Security

1•introvertmac•38m ago
For over a decade, I’ve been doing bug bounty, security audits, and security consulting. And if there’s one thing I’ve seen repeatedly, it’s this:

Most startups call a security engineer or hire a security agency only when a compliance deadline is a few weeks or month away.

Whether it’s PCI DSS, ISO 27001, SOC 1, SOC 2, or the new push from the EU for MICA and DORA in the Web3 and Fintech spaces, the motivation is almost always the same. It’s a sales blocker, get it done!

In the last few years, I had the opportunity to consult for a few “fully compliant” startups that gave me deeper access: GitHub, read-only database access, CI/CD configs, etc.

That’s when things got interesting.

What I Found Inside ‘Compliant’ Startups

Here are some real examples (details anonymized):

1. Secrets lying around in GitHub repos: Even though the company had a dedicated secrets manager, old secrets, tokens, and environment variables were still scattered inside the repo — some untouched for years.

2. Non-engineering teams “vibe-coding” in public Replit: Because the company wanted “everyone to code,” non-engineers were experimenting on public Repl.it projects with ChatGPT API keys and MongoDB connection URLs. I stopped a potential data leak before DB connection URL became public.

3. A public Docker image sitting out there for 5 years: It had an old Zendesk API key inside it. Anyone could have pulled it, and with that, accessed user PII.

4. Multiple unreported exploits: Issues that would’ve become serious incidents and many unreported exploited issues, none of which were caught by their compliance process.

Yet this company was proudly:

“100% SOC2 compliant.”

And closing enterprise deals. They were green-lit 100% compliant on Vanta. They had their SOC 2 badges on the home page.

Compliance frameworks are not useless. They establish a necessary baseline, enforce good practices, and build a framework for trust. They answer the question, “Do you have a process?”

But they do not answer the critical questions: “Is your team following that process right now?” or “What chaos did innovation create yesterday that exists outside the process?”

Compliance auditors check if you have the right documents, policies, and controls at the moment of audit. Attackers look for misconfigurations, forgotten credentials, abandoned code, and human mistakes every single day.

A company can be “fully compliant” and still be one bad commit away from a major breach.

A Simple Rule Founders Should Use When evaluating a startup or when building your own:

Don’t judge security by compliance certificates or shiny 100% compliant Vanta dashboards. Judge by the number of full-time security engineers relative to the team size.

A company with 0-1 security engineer and a SOC2 certificate is not secure. They’re just compliant.

Security is a continuous effort. It is significantly more affordable to build an in-house security culture and hire a full-time engineer than it is to pay a big name security agency for a panic audit, or worse, pay for a data breach cleanup.

If You’ve Read This Far: Thanks for listening to my rant.

If you are looking for a security consultant (who cares about more than just the checkbox), feel free to reach out at bhattacharya.manish8@gmail.com.

Recommendations for Getting the Most Out of a Technical Book

https://sebastianraschka.com/blog/2025/reading-books.html
1•naves•1m ago•0 comments

Palantir shifted course to play key role in ICE deportations

https://www.washingtonpost.com/technology/2025/12/03/palantir-immigration-ice/
2•SanjayMehta•4m ago•0 comments

Show HN: Frozen Function-agnostic goldenratio calculus (pip install phi-engine)

https://github.com/Purrplexia/LettersToMyHeroes/blob/main/Cantor_GoldenContinuum/code/phi_engine/...
1•purrplexia•4m ago•0 comments

PHP executes constant-time crypto – zero-knowledge benchmark inside

1•php-next•4m ago•0 comments

The Structural Limits of Global Central Banking

https://shanakaanslemperera.substack.com/p/the-monetary-singularity-how-december
1•jnord•5m ago•0 comments

Show HN: Tuvix – A Modern RSS Aggregator

https://tuvix.app/
1•TechSquidTV•5m ago•0 comments

EU Finalizes Deal to Phase Out Russian Gas Imports by 2027

https://www.bloomberg.com/news/articles/2025-12-03/eu-finalizes-deal-to-phase-out-russian-gas-imp...
1•toomuchtodo•6m ago•1 comments

Getting from Tested to Battle-Tested

https://blog.janestreet.com/getting-from-tested-to-battle-tested/
2•eclectician•6m ago•0 comments

In-Stadium Streaming in 2025: Real-Time Capabilities Developers Should Know

https://www.red5.net/blog/in-stadium-streaming-for-live-sports-broadcasting-and-event-production/
1•mondainx•8m ago•1 comments

The Sights and Sounds of Bhutan

https://waitbutwhy.com/2025/11/bhutan.html
1•naves•11m ago•0 comments

Why Does A.I. Write Like That?

https://www.nytimes.com/2025/12/03/magazine/chatbot-writing-style.html
1•cainxinth•13m ago•0 comments

The Linux kernel is just a program

https://serversfor.dev/linux-inside-out/the-linux-kernel-is-just-a-program/
2•zsoltkacsandi•13m ago•0 comments

Large DOM sizes affect interactivity, and what you can do about it (2023)

https://web.dev/articles/dom-size-and-interactivity
1•todsacerdoti•14m ago•0 comments

The face-palming reason Iran is running out of water

https://www.washingtonpost.com/opinions/2025/11/28/iran-tehran-water-shortage-desalination-farming/
1•breppp•16m ago•0 comments

Bio-Mimetic Legislative Engine

1•Mycobacterium•17m ago•0 comments

U.S. Pauses Immigration Applications from Nations on Travel Ban List

https://www.nytimes.com/2025/12/02/us/politics/trump-travel-ban-citizenship-green-cards-dc-shooti...
3•garbawarb•21m ago•0 comments

Seedream 4.5

https://seed.bytedance.com/en/seedream4_5
3•meetpateltech•25m ago•0 comments

This Month in Ladybird: November 2025

https://buttondown.com/ladybird/archive/this-month-in-ladybird-november-2025/
1•bpierre•28m ago•0 comments

Ask HN: Have you ever skipped filing a patent due to cost or uncertainty?

1•shaheeniquebal•34m ago•1 comments

What Does IHS Really Mean?

https://www.catholicshare.com/what-does-ihs-really-mean/
1•thunderbong•36m ago•0 comments

Tell HN: Compliance is not equal to Security

1•introvertmac•38m ago•0 comments

Brussels pushes for 70% of critical goods to be 'made in Europe'

https://www.ft.com/content/b0200e50-dd3a-4e9e-8908-40ead49e7daa
4•doener•40m ago•0 comments

AWS Lambda announces durable functions

https://aws.amazon.com/about-aws/whats-new/2025/12/lambda-durable-multi-step-applications-ai-work...
4•pallevante•41m ago•0 comments

Bitplane-Cursor: An iconic mouse Cursor theme for X

https://bastian-frank.de/tech-blog/bitplane-cursor
1•doener•43m ago•0 comments

Ask HN: Contract shops who can prepare codebases for internationalization

1•sarabande•43m ago•0 comments

Paint the Code

https://adelbordbari.github.io/code/2025-12-03-paint-the-code/
1•imnitwit•44m ago•0 comments

GNU Taler v1.2 Released

https://www.taler.net/en/news/2025-12.html
1•F3nd0•46m ago•0 comments

A Technical Tour of the DeepSeek Models from V3 to v3.2

https://magazine.sebastianraschka.com/p/technical-deepseek
2•giuliomagnifico•49m ago•0 comments

Vite 8 Beta

https://vite.dev/blog/announcing-vite8-beta
2•TheAlexLichter•49m ago•0 comments

VMK Extractor for BitLocker with TPM and Pin

https://post-cyberlabs.github.io/Offensive-security-publications/posts/2024_09_tpmandpin/
1•pregnenolone•50m ago•0 comments