13,368 karma · joined September 15, 2011
https://twitter.com/moo9000
1) how long the website was vulnerable
2) who else accessed data
3) why it was not fixed
4) who is responsible maintaining the website
Here is a story of Australian cybersecurity researcher who reported vulnerable website to the government 2022 and it is still not fixed today
https://x.com/adamlyttleapps/status/2102958488658104365?s=20
https://codamail.com/articles/privacy-law-directory/internat...
"EU surveillance co-operation"
1. Blocked Telegram with a court order, reinstituted after public backslash
2. Blocks Internet and Cloudflare during La Liga matches
3. Prime minister Pedro Sanchez from Spanish Socialist Workers’ Party (PSOE) has demanded the end of anonymity in Internet
They say it is to protect the kids, but likely it is to find out who watches La Liga without a premium subscription.
Because any AI company would be hit by hate and regulation derived from this, no VC invests in the EU. It's more state and large enterprise investments, good old East Germany style. And historically it has not been that efficient.
Or simply: lack of risk taking appetite.
https://www.cbr.com/paramount-dismantling-star-trek-9-year-s...
Symantec / Norton:
• Longstanding consumer complaints about aggressive upselling, scare-style scan warnings, auto-renewal, and hard-to-cancel billing
• Product often came preinstalled on PCs; many users treated it as unwanted bloatware
• Mixed reputation: lab detection scores often decent; customer-service and billing scores often poor
• 2011–2016 class action (Symantec and Digital River): alleged hidden “download insurance” / extended download service added at checkout; settled for about $60 million
• Canadian class action over alleged defects in an older Norton “decomposer” component (software sold roughly 2010–2016); later settled for tens of millions
• 2013–2022 Columbia University patent case: jury found willful infringement of malware-related patents and awarded $185 million; case later settled
• False Claims Act / GSA contracting: Symantec accused of hiding extra commercial discounts from the U.S. government; 2023 trial findings plus a 2024 Gen Digital payment of $55.1 million to satisfy the judgment LifeLock (bought by Symantec in 2016; later NortonLifeLock / Gen Digital)
• 2010 FTC settlement: about $12 million for deceptive identity-theft advertising
• 2015 FTC action: about $100 million after LifeLock violated the 2010 order (weak security program and more false claims)
• Recurring criticism that protection/reimbursement marketing overstated what the service actually did
• 2022–2023 credential-stuffing attacks on Norton Password Manager / LifeLock logins using reused passwords from other breaches; company said its own systems were not hacked; thousands of accounts had some personal data accessed and hundreds of thousands of logins were targeted
NortonLifeLock / Gen Digital
• 2021–2022 Norton Crypto: Ethereum miner bundled with Norton 360; company said it was opt-in and took a cut; users and researchers criticized it as inappropriate in a security product; later dropped
• Ongoing complaints about subscription renewals, refunds, and support after the Symantec → NortonLifeLock → Gen Digital rebrands
• Privacy/tracking investigations (alleged sharing of site/app data with third-party analytics such as Quantum Metric); not a final court finding
• Separate consumer suits alleging LifeLock failed to alert users or honor “dollar-for-dollar” identity-theft reimbursement promises
> But stop pretending you need anyone else’s permission. Stop pretending antitrust law has to be suspended so you can form a cartel. Stop pretending you need a regulatory approval process that supersedes product liability. Stop pretending METR is independent when it is intertwined with Anthropic’s investors and staff. Stop pretending you need those same evaluators to police competitors who aren’t even at the frontier.
It is not to protect the children.
https://www.amazon.com/dp/B0DVLLL1X3?lv=shuf&channelId=500&p...
Podcast if you do not want to buy the book:
https://www.bloomberg.com/news/videos/2026-09-08/odd-lots-wh...
> Government should require regular, mandatory reporting by technology service providers to document abuse of their systems including financial support of violence, harassment, and terrorism.This includes implementation of mandatory financial abuse reporting requirements for internet services operating in the United States, including social media services, infrastructure providers, banking institutions, cryptocurrency exchanges, crowdfunding sites, video streaming platforms, and the like.
> [These companies] should be required to investigate and report the details of harms and abuse of their service. There should be … penalties applied to services that refuse these tracking and reporting responsibilities.
https://www.bitsaboutmoney.com/archive/nonprofit-indicted-ba...