Everyone lies on SOC2. Auditors don't understand the technologies and just take peoples word for it. It's a shit practice

Citation needed. This is not my experience at all, after participating in such efforts at three different companies.

I'll just cite my 30 years in IT/InfoSec. Believe it or not, I really don't give a damn. It's common knowledge int he field regardless of what your experience is.

Can you name the names of SOC auditors that are rubber stamping?

Or point me to some public critiques within the industry?

Wasn’t that YC startup Delve doing exactly this?

https://www.iansresearch.com/resources/all-blogs/post/securi...

That I'm familiar with. Is it part of a trend or just one bad apple?

I wouldn't put it the way they did but they're directionally sane about this. I would worry a lot more about someone repping their SOC2 as important or meaningful than I would worry about someone who was cynical about SOC2.

(I don't mean Apple; Apple spends more on security than almost any firm in the world.)

https://fly.io/blog/soc2-the-screenshots-will-continue-until...

My experience with pen tests that you put above or on par with SOC2 Type 2 security mirrors the discussion here. It all comes down to the reputation of the firm doing the testing.