frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Apple Private Cloud Compute SoC 3 audit reports

https://support.apple.com/guide/certifications/apple-private-cloud-compute-soc-3-audit-apc95a31b9d8/web
53•throwfaraway4•2h ago

Comments

bstsb•1h ago
the page keeps 301ing to the home page for me - could be a region issue

https://archive.ph/JYC9B

rogerrogerr•1h ago
Works for me on a major US cell network.
qurren•53m ago
I thought they were working on M5 already? Why are they still auditing M3?
Havoc•53m ago
I'm glad they're doing them.

Audits are decidedly imperfect, but on balance people tend to toe the line better on good practices when they know they're being audited.

arkadiyt•52m ago
For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it.

Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

datakan•33m ago
Everyone lies on SOC2. Auditors don't understand the technologies and just take peoples word for it. It's a shit practice
Terretta•23m ago
Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves.

SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1).

Both may also allow general lag time.

Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they picked. Pick basic controls, it's cheaper to pass easily, and now you have a logo.

This means SOC2s of either type cannot be compared to one another (and SOC2 Type 1 are roughly logo-ware).

SOC3 is, roughly, SOC2 redacted.

Recap:

SOC2 Type 1 is a firm picking some controls to say they'll do them, SOC2 Type 2 is roughly a firm having someone look at whether they're doing that (warning, screenshots might suffice, audit verification is probably not what you think), and SOC3 is public or non-confidential water down of that, typically without findings.

The only thing that matters is what controls, specifically, they're actually audited on. So ideally you want to know what the controls they picked are, and that a SOC2 Type 2 was audited on those.

Btw, keep in mind that "end to end encryption" means "https" and most controls have similarly basic ways of achieving them. It's difficult to fail SOC2 Type 2 core controls if you know "don't be useless" is how you pass them.

Also, it's not $50K even through the big five DIY SOC2 Type 2 shops. You can use the same ones trillion dollar firms use, by signing up online, and you'll be surprised how inexpensive relative to the cost of failing to let a business check that box in their procurement process.

jtrn•45m ago
High security for a low value product.
throwfaraway4•36m ago
Imagine the security for the high value products
jtrn•6m ago
"Here are 2 things, but you can only have 1," it seems.
FinnKuhn•15m ago
I think companies like Deel showed that SOC2 is more show than anything else.

For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

deepsun•8m ago
Well you "claiming controls" to an independent CPA auditor. If a licensed CPA helps you lie -- they might lose their license (and can even get to prison), just like a tax preparer CPA can.
deepsun•12m ago
> "look I can afford 50k"

Oh no. Looks like you never went through SOC2.

1. No, it does not require 50k, an auditor can cost way less (10k? maybe even less).

2. But the process of preparing for the audit will take a lot of work securing your systems (and increasing reliability and privacy as well), as long as you take it seriously. Of course you can lie to the auditor, but it's up on you. And auditor -- they might lose their CPA license and go to prison. Their job is to catch your lies.

Source -- went through it, and took it seriously. It really did increase our security stance, even though we thought we were good at it.

FreeInk: Open ecosystem for e-readers

https://freeink.org/
191•FriedPickles•2h ago•44 comments

OpenAI and Hugging Face partner to address security incident

https://openai.com/index/hugging-face-model-evaluation-security-incident/
107•mfiguiere•35m ago•36 comments

Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber

https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flas...
498•logickkk1•5h ago•389 comments

Long presumed dead, a thriving coral reef is discovered in West Africa

https://e360.yale.edu/digest/benin-coral-reef
234•speckx•5h ago•38 comments

Jack Dorsey launches Buzz to combine team chat, AI agents and Git hosting

https://runtimewire.com/article/jack-dorsey-block-buzz-team-chat-ai-agents-git
129•ryanmerket•3h ago•115 comments

Apple has decided to compete for creativity app users

https://alex4d.com/notes/item/apple-competing-for-creativity-app-users
54•speckx•2h ago•34 comments

Apple defeats liability for not scanning iCloud for CSAM

https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for...
249•speckx•6h ago•221 comments

'VPNs are lawful technical tools,' says EU Court in landmark copyright ruling

https://www.techradar.com/vpn/vpn-privacy-security/vpns-are-lawful-technical-tools-says-eu-court-...
87•healsdata•1h ago•10 comments

Apple Private Cloud Compute SoC 3 audit reports

https://support.apple.com/guide/certifications/apple-private-cloud-compute-soc-3-audit-apc95a31b9...
53•throwfaraway4•2h ago•13 comments

Qwen-Image-3.0: Rich Content, Authentic Details, Deep Knowledge

https://qwen.ai/blog?id=qwen-image-3.0
506•ilreb•12h ago•206 comments

PCjs Machines

https://www.pcjs.org/
159•naves•6h ago•15 comments

France's Anssi Will Block PQC-Free Products from Certification Starting 2027

https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
70•Sami_Lehtinen•4h ago•31 comments

Bloomy (YC S26) is hiring a founding engineer

1•alexsouthmayd•3h ago

Laguna S 2.1

https://poolside.ai/blog/introducing-laguna-s-2-1
104•rexledesma•3h ago•21 comments

Meta's AI models are powering the first wave of Genesis Mission projects

https://ai.meta.com/blog/genesis-mission-lawrence-berkeley-national-laboratory-segment-anything-d...
70•surprisetalk•3h ago•49 comments

Show HN: A self-running space economy SIM in Rust and Bevy

https://github.com/Kalcode/spaceprojectsim
41•kalcode•2h ago•11 comments

My USB Drive Has a Hidden Encrypted Vault

https://rootkitlabs.com/2026/06/22/I%27m-Building-a-Secure-USB-Drive/
102•machinehum•1d ago•65 comments

Slater – Low-memory graphdb designed for read-heavy graphs

https://github.com/Hikari-Systems/slater
14•rickkjp•2h ago•6 comments

Show HN: Read the Tape – Wordle for daytrading, five blind S&P 500 charts a day

https://readthetape.cc/
5•will_asouka•1d ago•0 comments

Advertise in ChatGPT

https://ads.openai.com/
177•montecarl•1h ago•191 comments

The unreasonable difficulty of time series forecasting

https://suzyahyah.github.io/machine%20learning/2026/06/27/trouble-with-time-series.html
88•suzyahyah•3d ago•30 comments

AI Agent – TRMNL

https://help.trmnl.com/en/articles/14130438-ai-agent
17•joeyespo•2h ago•11 comments

Show HN: Justif – Knuth-Plass justification and microtypography for the web

https://justif.lyall.co/
6•lyall•4d ago•2 comments

Show HN: CodeAlmanac – Karpathy-style codebase wiki from your conversations

https://github.com/AlmanacCode/codealmanac/
27•divitsheth•3h ago•12 comments

The World's 2,400 Castles

https://thecastlemap.com/
137•marklit•4h ago•102 comments

The Price of Happiness

https://happiness-science.org/price-of-happiness/
20•andyjohnson0•2h ago•8 comments

Cheap self-hosted Kubernetes on Hetzner cloud (2025)

https://blog.qstars.nl/posts/cheap-self-hosted-kubernetes-on-hetzner-cloud/
48•victorbrink•2h ago•24 comments

Zero-dependency streaming tar parser and writer for JavaScript

https://ayuhito.com/projects/modern-tar/
5•ayuhito•3d ago•0 comments

Show HN: Imagin Raw – A 9MB Open-Source Alternative to Adobe Bridge for Mac

https://github.com/cristibaluta/Imagin-Raw
42•cristi_baluta•3h ago•12 comments

Greedy is optimal for single-pass semi-streaming matching

https://arxiv.org/abs/2607.14656
12•MarcoDewey•2h ago•0 comments