frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

BTDUex Safe? The Back End Withdrawal Anomalies

1•aoijfoqfw•2m ago•0 comments

Show HN: Compile-Time Vibe Coding

https://github.com/Michael-JB/vibecode
1•michaelchicory•5m ago•0 comments

Show HN: Ensemble – macOS App to Manage Claude Code Skills, MCPs, and Claude.md

https://github.com/O0000-code/Ensemble
1•IO0oI•8m ago•1 comments

PR to support XMPP channels in OpenClaw

https://github.com/openclaw/openclaw/pull/9741
1•mickael•9m ago•0 comments

Twenty: A Modern Alternative to Salesforce

https://github.com/twentyhq/twenty
1•tosh•10m ago•0 comments

Raspberry Pi: More memory-driven price rises

https://www.raspberrypi.com/news/more-memory-driven-price-rises/
1•calcifer•16m ago•0 comments

Level Up Your Gaming

https://d4.h5go.life/
1•LinkLens•20m ago•1 comments

Di.day is a movement to encourage people to ditch Big Tech

https://itsfoss.com/news/di-day-celebration/
2•MilnerRoute•21m ago•0 comments

Show HN: AI generated personal affirmations playing when your phone is locked

https://MyAffirmations.Guru
4•alaserm•22m ago•3 comments

Show HN: GTM MCP Server- Let AI Manage Your Google Tag Manager Containers

https://github.com/paolobietolini/gtm-mcp-server
1•paolobietolini•23m ago•0 comments

Launch of X (Twitter) API Pay-per-Use Pricing

https://devcommunity.x.com/t/announcing-the-launch-of-x-api-pay-per-use-pricing/256476
1•thinkingemote•23m ago•0 comments

Facebook seemingly randomly bans tons of users

https://old.reddit.com/r/facebookdisabledme/
1•dirteater_•24m ago•1 comments

Global Bird Count Event

https://www.birdcount.org/
1•downboots•25m ago•0 comments

What Is Ruliology?

https://writings.stephenwolfram.com/2026/01/what-is-ruliology/
2•soheilpro•27m ago•0 comments

Jon Stewart – One of My Favorite People – What Now? with Trevor Noah Podcast [video]

https://www.youtube.com/watch?v=44uC12g9ZVk
2•consumer451•29m ago•0 comments

P2P crypto exchange development company

1•sonniya•43m ago•0 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
2•jesperordrup•48m ago•0 comments

Write for Your Readers Even If They Are Agents

https://commonsware.com/blog/2026/02/06/write-for-your-readers-even-if-they-are-agents.html
1•ingve•48m ago•0 comments

Knowledge-Creating LLMs

https://tecunningham.github.io/posts/2026-01-29-knowledge-creating-llms.html
1•salkahfi•49m ago•0 comments

Maple Mono: Smooth your coding flow

https://font.subf.dev/en/
1•signa11•55m ago•0 comments

Sid Meier's System for Real-Time Music Composition and Synthesis

https://patents.google.com/patent/US5496962A/en
1•GaryBluto•1h ago•1 comments

Show HN: Slop News – HN front page now, but it's all slop

https://dosaygo-studio.github.io/hn-front-page-2035/slop-news
6•keepamovin•1h ago•1 comments

Show HN: Empusa – Visual debugger to catch and resume AI agent retry loops

https://github.com/justin55afdfdsf5ds45f4ds5f45ds4/EmpusaAI
1•justinlord•1h ago•0 comments

Show HN: Bitcoin wallet on NXP SE050 secure element, Tor-only open source

https://github.com/0xdeadbeefnetwork/sigil-web
2•sickthecat•1h ago•1 comments

White House Explores Opening Antitrust Probe on Homebuilders

https://www.bloomberg.com/news/articles/2026-02-06/white-house-explores-opening-antitrust-probe-i...
1•petethomas•1h ago•0 comments

Show HN: MindDraft – AI task app with smart actions and auto expense tracking

https://minddraft.ai
2•imthepk•1h ago•0 comments

How do you estimate AI app development costs accurately?

1•insights123•1h ago•0 comments

Going Through Snowden Documents, Part 5

https://libroot.org/posts/going-through-snowden-documents-part-5/
1•goto1•1h ago•0 comments

Show HN: MCP Server for TradeStation

https://github.com/theelderwand/tradestation-mcp
1•theelderwand•1h ago•0 comments

Canada unveils auto industry plan in latest pivot away from US

https://www.bbc.com/news/articles/cvgd2j80klmo
3•breve•1h ago•1 comments
Open in hackernews

Tell HN: Compliance is not equal to Security

1•introvertmac•2mo ago
For over a decade, I’ve been doing bug bounty, security audits, and security consulting. And if there’s one thing I’ve seen repeatedly, it’s this:

Most startups call a security engineer or hire a security agency only when a compliance deadline is a few weeks or month away.

Whether it’s PCI DSS, ISO 27001, SOC 1, SOC 2, or the new push from the EU for MICA and DORA in the Web3 and Fintech spaces, the motivation is almost always the same. It’s a sales blocker, get it done!

In the last few years, I had the opportunity to consult for a few “fully compliant” startups that gave me deeper access: GitHub, read-only database access, CI/CD configs, etc.

That’s when things got interesting.

What I Found Inside ‘Compliant’ Startups

Here are some real examples (details anonymized):

1. Secrets lying around in GitHub repos: Even though the company had a dedicated secrets manager, old secrets, tokens, and environment variables were still scattered inside the repo — some untouched for years.

2. Non-engineering teams “vibe-coding” in public Replit: Because the company wanted “everyone to code,” non-engineers were experimenting on public Repl.it projects with ChatGPT API keys and MongoDB connection URLs. I stopped a potential data leak before DB connection URL became public.

3. A public Docker image sitting out there for 5 years: It had an old Zendesk API key inside it. Anyone could have pulled it, and with that, accessed user PII.

4. Multiple unreported exploits: Issues that would’ve become serious incidents and many unreported exploited issues, none of which were caught by their compliance process.

Yet this company was proudly:

“100% SOC2 compliant.”

And closing enterprise deals. They were green-lit 100% compliant on Vanta. They had their SOC 2 badges on the home page.

Compliance frameworks are not useless. They establish a necessary baseline, enforce good practices, and build a framework for trust. They answer the question, “Do you have a process?”

But they do not answer the critical questions: “Is your team following that process right now?” or “What chaos did innovation create yesterday that exists outside the process?”

Compliance auditors check if you have the right documents, policies, and controls at the moment of audit. Attackers look for misconfigurations, forgotten credentials, abandoned code, and human mistakes every single day.

A company can be “fully compliant” and still be one bad commit away from a major breach.

A Simple Rule Founders Should Use When evaluating a startup or when building your own:

Don’t judge security by compliance certificates or shiny 100% compliant Vanta dashboards. Judge by the number of full-time security engineers relative to the team size.

A company with 0-1 security engineer and a SOC2 certificate is not secure. They’re just compliant.

Security is a continuous effort. It is significantly more affordable to build an in-house security culture and hire a full-time engineer than it is to pay a big name security agency for a panic audit, or worse, pay for a data breach cleanup.

If You’ve Read This Far: Thanks for listening to my rant.

If you are looking for a security consultant (who cares about more than just the checkbox), feel free to reach out at bhattacharya.manish8@gmail.com.

Comments

Hakashiro•2mo ago
Compliance is not security, but "security" is too nebulous of a term to actually implement effectively, so companies use the specific regulations and standards to have a measurable target to strive for.

In my company, we have additional security measures and guardrails on top of the bare minimum legally required, but most companies indeed see security as a cost center and decide not to invest until it's too late.