3 ms·
Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-article/ https://tldv.io/blog/our-thoughts-on-the-darkreadin
by yellow_lead 2mo ago
Seems like they fixed this a few days ago:
https://tldv.io/blog/our-thoughts-on-the-darkreading-com-article/ https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art...
But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
[1] https://tldv.io/features/security-commitment/ https://tldv.io/features/security-commitment/
- stellamariesays 2mo ago[flagged]
- cyberge99 2mo agoIs there an entity that can validate they are not SOC2 compliant outside of their claim?
- maebert 2mo agoYes, SOC2 require an audit by an independent auditor, and in principle you can request their audit report from them. Just email the CTO about it ;)
- cube00 2mo agoOn a personal note, I recognize that I should have kept the researcher updated after his initial outreach earlier this year, and I take full responsibility for that communication gap. They make it sound like it was a single email. What about all the other outreaches the researcher made to the CEO over a six month period? Interesting how the CEO didn't contribute any explanation to the blog post and left the CTO out to dry.
- Trasmatta 2mo agoOnce again proof that SOC2 is nothing but a marketing tactic, and busywork
- maxrev17 2mo agoVC runway afterburners, engage!!!
- fg137 2mo agoI used a product with SOC2 certification, which uploads all your chatbot conversations to a server they control (mandatory), potentially including source code and other proprietary data, which can be made visible to public with a single click. Doesn't matter if you are an individual or enterprise user. They do have enterprise level controls that let admins turn this off. Unfortunately, it is on by default, and some of those basic security controls require a higher tier of service. It is absolutely wild that these companies treat security like an afterthought. And I also realized SOC2 Compliant meant absolutely nothing.
- SAI_Peregrinus 2mo agoSOC2 requires a company to write policies in a large number of areas, and to demonstrate that they're complying with the policies they wrote. AFAIK SOC2 does not require anything meaningful about the actual contents of the policies, nor does it require the policies to remain constant.
- briHass 2mo agoThis is true. They (the auditors) usually have guidance or areas they need to see policy address, but not specific implementation details. Using common, overbearing MDM or endpoint tools make providing evidence of adherence to policies easier, however.
- deleted 2mo ago[deleted]
- varispeed 2mo agoReminds me of ISO certification. Where all it does is that your complaints are called non-conformance.
- laserlight 2mo agoI used to work for a company seeking SOC2 compliance. They told me that I had to install corporate malware because of the compliance. I didn't want to install it on my personal computer, which I had been using for work. They sent me a company computer. I installed the corporate malware on that one. I set the company computer aside and continued working on my personal computer. No SOC2 compliance was harmed in the process.
- thih9 2mo agoThe company computer typically comes with some data protection agreement, where you agree to only access confidential data via the company computer, or at least to never copy confidential company data to personal devices.
- gchamonlive 2mo agoOn the one side you are liable because you are accessing company data on your personal computer. On the other you are liable because the company is forcing you to use insecure devices to access company data because of compliance. I think we need to check the contracts to see which liability to choose that will give you the least amount of headache.
- ranger207 2mo agoYou're not liable for using company devices to access company data, regardless of if it's insecure or not. Don't use personal devices for work
- gchamonlive 2mo agoI know, I was being coy, but if I'm being honest using company devices makes me really anxious, it's always in the back of my head that someone is going to abuse that outdated and opaque VPN stack from Fortinet or that Kaspersky Daemon I needed to install using a script some guy from security sent me with a Google Docs link over DM, and I'll have a really hard time explaining there was no mishandling of data from my part
- antoniojtorres 2mo agoBesides the downplaying and obfuscation about the timeline on the first half, I find the inclusion of anthropic and zoom examples to be wild. Just spraying in all directions.