logoalt Hacker News

yellow_leadyesterday at 2:12 PM8 repliesview on HN

Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art...

But they try to play it off as though this were public data:

> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.

Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.

[1] https://tldv.io/features/security-commitment/


Replies

laserlightyesterday at 7:02 PM

I used to work for a company seeking SOC2 compliance. They told me that I had to install corporate malware because of the compliance. I didn't want to install it on my personal computer, which I had been using for work. They sent me a company computer. I installed the corporate malware on that one. I set the company computer aside and continued working on my personal computer. No SOC2 compliance was harmed in the process.

show 1 reply
fg137yesterday at 5:13 PM

I used a product with SOC2 certification, which uploads all your chatbot conversations to a server they control (mandatory), potentially including source code and other proprietary data, which can be made visible to public with a single click. Doesn't matter if you are an individual or enterprise user.

They do have enterprise level controls that let admins turn this off. Unfortunately, it is on by default, and some of those basic security controls require a higher tier of service.

It is absolutely wild that these companies treat security like an afterthought. And I also realized SOC2 Compliant meant absolutely nothing.

show 1 reply
antoniojtorrestoday at 3:56 AM

Besides the downplaying and obfuscation about the timeline on the first half, I find the inclusion of anthropic and zoom examples to be wild. Just spraying in all directions.

cyberge99yesterday at 2:28 PM

Is there an entity that can validate they are not SOC2 compliant outside of their claim?

show 1 reply
varispeedyesterday at 5:42 PM

Reminds me of ISO certification. Where all it does is that your complaints are called non-conformance.

Trasmattayesterday at 3:38 PM

Once again proof that SOC2 is nothing but a marketing tactic, and busywork

show 1 reply
cube00yesterday at 3:01 PM

On a personal note, I recognize that I should have kept the researcher updated after his initial outreach earlier this year, and I take full responsibility for that communication gap.

They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period?

Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.

stellamariesaysyesterday at 2:13 PM

[flagged]