Hacker Newsnew | past | comments | ask | show | jobs | submit | aberoham's commentslogin

Engineers often over-think compliance. SOC2 is regulatory capture, and an audit that tests your controls. You define the appropriate controls. As long as you do what you say you're going to do, you should pass the audit. It's not rocket science. It's a feature of a correct system that it is auditable. How easy it is to audit is really a function of your maturity. SOC2 and its ilk such as ISO27001 are just maturity signalling mechanisms. Stop overthinking it or applying black and white rules -- in actual practice its always shades of grey and most auditors are just happy to have an engaged and switched on team to be auditing, vs someone who treats it as adversarial. You're paying them!


The problem is it's not the engineers that overthink it. The requirement for soc2 usually comes with the first "serious" customer. It is usually a big blocker on some fat contract and now the business makes it your problem for the next 6 months.

So what do you do? You engage and some 3rd party 1800-need-soc2 clowns which will hold your hand and implement all the cookie cutter solutions they know will make auditor happy (oh and btw, they know the auditor personally).


What would it mean if someone were to successfully exploit these? Most or all L2 ecosystems or the magic components that let them speak to each other would need a hard reset?


It's a "this transaction is valid even though the signatures, amounts, potentially everything is wrong about it" vuln.

Every node that uses this library to validate would lose synchronization with every other node (if we take them at their word that it's not a monoculture), the bigger half would be considered "correct" according to how blockchains work, if it's the non-exploitable half - just lots of wasted resources and longer settlement times, if it's the exploitable half - illegal transactions would need to be reverted by agreement of the community, which is some sort of reset.


I wonder about this technique vs simple SVM classifiers: https://x.com/rosmine/status/2056406399471558872?s=20


This article is about training a classifier to detect synthetic text.

The link you sent is for generating text which attempts to defeat those classifiers.


He’s busy with MathAcademy earning XP-SEC


export CLAUDE_CODE_DISABLE_1M_CONTEXT=1


Anthropic is not building good will as a consumer brand. They've got the best product right now but there's a spring charging behind me ready to launch me into OpenCode as soon as the time is right.


Would you use Opus if you switched to OpenCode?


I'd like to use Opus with OpenCode right now to combine the best TUI agent app with the best LLM. But my understanding is Anthropic will nuke me from orbit if I try that.


You can use Opus with OpenCode anytime you want, just not with the Claude plan. You can use it via API with any provider, including Anthropic's API. You can use it with Github Copilot's plan. The only thing you can't do without getting banned is use OpenCode with one of Claude's plans.


I keep seeing this "you can use the inconvenient and unpredictably costly way all you want" pedantic kneejerk response so often lately.

It's like saying well humans can fly with a paraglider. It is correct and useless. Most here won't have cash to burn with unbounded opus api usage.


If you want to use Opus with a different coding harness along with a coding plan, you can use Github CoPilot. It even has built in authentication with OpenCode.


OpenCode with a Copilot Business sub and Opus 4.6 as the model works well


I'm looking at their plans (https://github.com/features/copilot/plans) it seems like the limits might be pretty low, even with the Pro+ plan which is 2x the cost of Claude Pro. It seems like Claude Pro might be 10-20x the Opus tokens for only twice the price.


Copilot has a totally different billing model. It's request based rather than token based. Counter-intuitively, in our case at least, it is way cheaper than token based pricing. One request can sometimes consume 2-4 million tokens but is billed as a single request (or it's multiplier if using a premium model like opus).


UpCloud


I'm really hoping this means GCP Security Command Center quickly gets subsumed by Wiz


you mean there will now be three products instead of two

Google Security Center Wiz Google Agentic Wiz Security


"the remaining 2% were large batch requests", [which made up 50% of the work] .. who really watches that many shows on Netflix? What was in those batches, if someone is watching that much, why bother with serendipity at all? Most serendipitous thing you could do is shut off their subscription.


Note that they likely mean the list of candidates is large not the user history. This is for an API so perhaps 2% of client requests implemented batch requests, providing the opportunity for batch processing of that request.


Claude Cowork grabs local DNS resolution on macOS which conflicts with secure web gateway aka ZTNA aka SASE products such as Cloudflare Warp which do similar. The work-around is to close Cowork, let Warp grab mDNSResponder's attention first, then restart Claude Desktop, or some similar special ordering sequence. It's annoying, but you could say that about everything having to do with MITM middleboxes.


Wow, you have to try claude code with Opus-4.6..


I agree, but I don't have a subscription.

The remaining technical challenge I have is related to stage positioning- in my system, it's important that all the image frames we collect are tagged with the correct positions. Due to some technical challenges, right now the stage positions are slightly out of sync with the frames, which will be a fairly tricky problem to solve. It's certainly worth trying all the major systems to see what they propose.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: