kottke.org

Jason Kottke's weblog, home of fine hypertext products

From the Internet Archive: Vanishing Culture: A Report...

From the Internet Archive: Vanishing Culture: A Report on Our Fragile Cultural Record. “When digital materials are vulnerable to sudden removal…our collective memory is compromised, and the public’s ability to access its own history is at risk.”

Vintage Eastern European Matchbox Labels (1950-1980s)

Over on Flickr, Jane McDevitt maintains a huge collection of 20th century matchbox label art from Eastern Europe, over 4000 photos in all. Some of the labels are available as prints. They did a book too, but it’s sold out. It was really difficult to narrow these down to some of my favorites, but I managed.

P.S. I wrote this whole post and then discovered that I’d written about this collection before. But I picked different labels so it’s all good.

Tags: art · illustration · Jane McDevitt

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Anthropic reveals fourth likely crime committed by its AI

Amid industry soul-searching¹ about the possibility of AI improving itself to the point that it kills everyone, Anthropic has revealed yet another incident that would qualify as a crime if perpetrated by a person. The AI biz published "an alignment assessment" detailing four times Claude models accessed third-party systems without authorization. The company has already reported three of the incidents. Evidence of the fourth was lurking in a session transcript dating back to January 2026 when the misbehavior occurred. Anthropic found the first three by scanning around 141,000 transcripts where Claude could have obtained internet access during evaluation. It missed the fourth initially because "our scan relied on an agentic search." Felony Bench, a tongue-in-cheek record of cyber intrusions carried out by major AI companies without consequences, has added this newly-discovered incident to its rap sheet of rogue AI actions. The January 2026 AI trespass involved an early version of Claude Opus 4.6, which was given a Capture the Flag (CTF) challenge under the oversight of the third-party model evaluator where the other hacking events occurred. Opus 4.6 managed to sabotage its chances of success by disabling the machine it was targeting. It assigned the device an IP address that already existed on another piece of hardware, rendering the target unreachable and making it impossible to solve the challenge. Those familiar with other incidents where AI models violated third-party systems may recall that unsolvable tasks represent a common catalyst for misbehavior. Models exhaust all aligned options, and then turn to transgressive approaches. Opus 4.6 might have been an exception, but when it tried to abort the task after recognizing that it could not reach the target machine, it failed to do so "due to a misconfiguration in [the model's] evaluation harness." It failed to shut down not just once but seven times. So it continued onward, trying other expected means to reach the target machine but failing. Then it explored further. "The model discovered a machine belonging to a third party that it was able to access, and stated that it believed this third party was part of the CTF," Anthropic explained in its post. "Inside the machine, the model found a file listing a password, which it used to gain admin access to the system." The model went on to gather more credentials, and modified a system setting to make it easier to access the personal information of an individual associated with the third party evaluation organization. Opus 4.6 might have done more but for the fact that it exhausted its token budget, bringing the session to an end. Anthropic says it's not as concerned about this incident as the others because the model tried to abort its task. "While the model’s disregard for the possibility that it might be harming real systems or people is concerning, many of the behaviors described here have changed considerably as our training has evolved across model generations," the company said. Anthropic said it considers these incidents serious but expects current training approaches "are likely able to address the specific alignment failure modes observed in these incidents." And if company training methods fall short, there's no real consequence to anyone at Anthropic other than writing up a revised alignment assessment. ® ¹ The term "soul-searching" is figurative and is not intended to indicate a belief that the technology industry has a soul.

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US and Southeast Asia. Mark Kelly, a threat researcher at email security shop Proofpoint, told The Register that the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited. “In terms of organizations targeted, we saw fewer than 20 organizations globally targeted across the activity highlighted," he said. "However, the true number is almost certainly higher than this.” Proofpoint’s threat hunters spotted the new kit, which they named BlueMoon, and said its first observed use started on August 28. This is when a Beijing-backed crew they track as TA412, also known as Violet Typhoon and APT31, used BlueMoon to “repeatedly” target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the US. TA412 is a cyberespionage group linked by US authorities to China's Ministry of State Security (MSS), and American prosecutors previously charged seven alleged members with conspiracy to commit computer intrusions and wire fraud, alleging they broke into computer networks, email accounts, and cloud storage belonging to numerous critical infrastructure organizations, companies, and individuals. Just days after Proofpoint documented the late-August activity, “several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus,” Kelly and fellow researchers Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said on Wednesday, noting that there may be other, non-China-nexus attackers using the exploit kit as well. “BlueMoon was developed and deployed rapidly, and shared across multiple threat actors within days,” Kelly told The Register. “This may reflect a reduced cost and barrier to entry for this class of capability, which has historically been rare and high value, as AI agents increasingly enable threat actor exploit development. That is particularly true for open-source codebases such as Chromium, where publicly accessible upstream patches create a ‘patch-gap’ window for rapid reverse engineering and exploit development ahead of downstream stable releases.” A Google spokesperson declined to comment beyond what Proofpoint wrote. Microsoft patched the Windows bug (CVE-2026-85880) on Tuesday, and a spokesperson reiterated that customers who applied that patch are protected. BlueMoon attack chain The kit chains together three vulnerabilities. The first is a V8 type confusion (CVE-2026-85046) flaw that allows remote code execution and affects all Chromium-based browsers, including Google Chrome and Microsoft Edge. Google patched this bug in Chrome on September 3, and at the time warned that it “is aware that an exploit for CVE-2026-85046 exists in the wild.” Microsoft published a security advisory saying it fixed the flaw in Edge Stable version 152.0.4191.62 on September 2. The second is a Chrome V8 sandbox escape. This one also affected all Chromium-based browsers. It does not have a CVE because Google doesn’t issue them for sandbox escapes. Finally, the third bug is a privilege escalation vulnerability in Windows Advanced Local Procedure Call (CVE-2026-85880) that Microsoft patched on Tuesday, as noted above. Redmond also warned that this flaw had been exploited as a zero-day prior to the security update. The Proofpoint researchers also note that both V8 vulnerabilities are what’s called "patch-gap" zero-days at the time of the observed activity. This means they were known and fixed in upstream Chromium source code – a change containing the fix for CVE-2026-85046 was committed on August 7. But they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public for weeks. “It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain,” the researchers note. From phishing to browser surveillance The attacks start with a phishing email that tricks victims into clicking on an actor-controlled URL. This triggers the two V8 bugs to allow remote code execution and escape the browser sandbox. The attack chain then exploits the Windows bug to download multiple payloads including browser-surveillance malware, credential-stealing backdoors, and others, depending on the group using the exploit kit. TA412’s first campaign, which began on August 28, used a range of lures. Some of the emails purported to come from university students interested in internships at the targeted organizations, and some were more target-specific exchanges, intended to build trust with the individual before ultimately sending a malicious link via email. In these instances, the exploit chain “ultimately downloaded and ran a loader executable on the infected host, which then installed a malicious browser extension disguised as Google Gemini on the victim's Chromium-based browser,” the team wrote. This browser extension, which Proofpoint tracks as GemStone, allowed the Beijing spies to issue commands through a command-and-control (C&C) channel, steal cookies and other sensitive data, take screenshots, and inject a keylogger into a browser tab. The malware also contains a keyword monitor, which injects an attacker-specified keyword list into the top frame of each page, scans the HTML body for these keywords, and triggers a screenshot if it finds any. A few days later, beginning on September 2, a second China-aligned spy crew that Proofpoint tracks under the temporary group designator UNK_LateNight used BlueMoon to target multiple US aerospace companies. The phishing emails used request-for-quotation lures specific to defense industry organizations, and included links to attacker-controlled domains spoofing a variety of US aerospace companies. These websites also served the BlueMoon exploit kit and ultimately loaded a backdoor called ShadowPad, which has been shared among multiple China-aligned groups since 2019. Around this same time, on September 2, another suspected espionage group that Proofpoint tracks as UNK_DoubleCheck targeted a Vietnamese manufacturing firm with messages sent from a compromised Southeast Asian government email address. The fourth campaign began a day later, and involved suspected China-linked spy crew UNK_QuietRacket using BlueMoon to target government, consulting, and financial-sector organizations in Indonesia and Singapore. These phishing emails used lures related to Indonesian conferences, such as the Indo Startup Expo and Forum 2026 and the World Conference on Creative Economy (WCCE 2026). Proofpoint warns that BlueMoon will likely be used by both cyberspies and financially motivated attackers. “The broader dynamic revealed by this activity - rapid exploit development that leverages the open source patch-gap – is likely to recur beyond BlueMoon as this development model becomes accessible,” the team wrote. ®

Moon River

Thomas Hawk posted a photo:

Moon River

Frank StellaDouble Concentric: Scramble, 1971

Thomas Hawk posted a photo:

Frank StellaDouble Concentric: Scramble, 1971

Found Ektachrome Slide

Thomas Hawk posted a photo:

Found Ektachrome Slide

date stamped on slide, August 1961

Found Kodachrome Slide -- George McNutt Collection

Thomas Hawk posted a photo:

Found Kodachrome Slide -- George McNutt Collection

date stamped on slide, December 1966

The Earth Has But One Moon

Thomas Hawk posted a photo:

The Earth Has But One Moon

Rotterdam - FediMeteo (@rotterdam@nl.fedimeteo.com)

Weer voor de stad Rotterdam Deze bot wordt beheerd door het FediMeteo-project. Voor informatie en contact kunt u de pagina https://fedimeteo.com raadplegen.

Weer voor Rotterdam 🌕 - 10-09-2026 01:15 CEST...

Weer voor Rotterdam 🌕 - 10-09-2026 01:15 CEST

In één oogopslag:
• 14.4°C · Helder 🌕 | Min 14.4°C / Max 18.4°C | Kans op neerslag 51%

Verwachting voor vandaag:
• Min 14.4°C, Max 18.4°C (Zware motregen) 🌦️, Neerslag 3.5 mm, Kans op neerslag 51%, 🧭 1018.4 hPa ➡️ 0.0 hPa/24h, Windsnelheid: 26.3 km/u (7.3 m/s), richting: → 281°

Uurlijkse voorspelling voor de komende 12 uur:

02:00: 14.5°C (Helder) 🌕, 🧭 1018.1 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 5.8 km/u (1.6 m/s), richting: → 275°
03:00: 14.4°C (Helder) 🌕, 🧭 1018.3 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 7.2 km/u (2.0 m/s), richting: → 279°
04:00: 14.3°C (Helder) 🌕, 🧭 1018.5 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 6.5 km/u (1.8 m/s), richting: → 263°
05:00: 14.5°C (Gedeeltelijk bewolkt) ☁️, 🧭 1018.6 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 6.1 km/u (1.7 m/s), richting: ↗ 236°
06:00: 14.3°C (Helder) 🌕, 🧭 1018.6 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 6.5 km/u (1.8 m/s), richting: ↑ 188°
07:00: 13.8°C (Helder) 🌕, 🧭 1018.5 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 9.4 km/u (2.6 m/s), richting: ↑ 168°
08:00: 14.5°C (Licht bewolkt) 🌤️, 🧭 1018.7 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 9.0 km/u (2.5 m/s), richting: ↗ 224°
09:00: 15.1°C (Bewolkt) ☁️, 🧭 1018.8 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 9.0 km/u (2.5 m/s), richting: ↑ 196°
10:00: 15.4°C (Bewolkt) ☁️, 🧭 1019.1 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 10.1 km/u (2.8 m/s), richting: ↑ 200°
11:00: 16.2°C (Bewolkt) ☁️, 🧭 1019.3 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 11.9 km/u (3.3 m/s), richting: ↗ 210°
12:00: 17.0°C (Bewolkt) ☁️, Kans op neerslag 2%, 🧭 1019.5 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 13.0 km/u (3.6 m/s), richting: ↗ 216°
13:00: 17.9°C (Bewolkt) ☁️, Kans op neerslag 5%, 🧭 1019.4 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 15.5 km/u (4.3 m/s), richting: ↗ 212°

Voorspelling voor de komende dagen:

vrijdag 11 september: Min 13.8°C, Max 19.4°C (Bewolkt) ☁️, Kans op neerslag 1%, 🧭 1018.8 hPa ➡️ 0.0 hPa/24h, Windsnelheid: 15.5 km/u (4.3 m/s), richting: ↗ 214°
zaterdag 12 september: Min 15.1°C, Max 19.0°C (Lichte motregen) 🌦️, Neerslag 0.8 mm, Kans op neerslag 36%, 🧭 1023.0 hPa ↗️ +4.2 hPa/24h, Windsnelheid: 19.8 km/u (5.5 m/s), richting: ↗ 237°
zondag 13 september: Min 15.0°C, Max 20.7°C (Lichte motregen) 🌦️, Neerslag 0.1 mm, Kans op neerslag 3%, 🧭 1020.2 hPa ↘️ -2.8 hPa/24h, Windsnelheid: 16.2 km/u (4.5 m/s), richting: ↗ 226°
maandag 14 september: Min 15.7°C, Max 19.9°C (Matige motregen) 🌦️, Neerslag 4.5 mm, Kans op neerslag 39%, 🧭 1019.9 hPa ➡️ 0.0 hPa/24h, Windsnelheid: 19.8 km/u (5.5 m/s), richting: ↗ 242°
dinsdag 15 september: Min 17.8°C, Max 22.5°C (Matige motregen) 🌦️, Neerslag 1.6 mm, Kans op neerslag 9%, 🧭 1013.3 hPa ↘️ -6.6 hPa/24h, Windsnelheid: 16.5 km/u (4.6 m/s), richting: ↗ 236°
woensdag 16 september: Min 15.3°C, Max 21.8°C (Lichte motregen) 🌦️, Neerslag 2.1 mm, Kans op neerslag 21%, 🧭 1012.3 hPa ↘️ -1.0 hPa/24h, Windsnelheid: 16.4 km/u (4.6 m/s), richting: ↗ 234°

Details:
• 🌡️ Huidige temperatuur (om 01:15): 14.4°C (Helder)
• 🤚 Gevoelstemperatuur: 13.4°C (-1.0°C)
• 💨 Windsnelheid: 6.1 km/u (1.7 m/s), richting: → 272°
• 🌬️ Windstoten: 8.3 km/h (2.3 m/s)
• 💧 Luchtvochtigheid: 71%
• 🧭 Luchtdruk: 1018.1 hPa ➡️ 0.0 hPa/3h
• 👁️ Zichtbaarheid: 50.0 km
• ☀️ UV-index: 0.0
• 🌅 Zonsopgang: 07:06 · 🌇 Zonsondergang: 20:10

Luchtkwaliteit:
• AQI: 25 🟢 (Goed)
• PM2.5: 4.8 μg/m³
• PM10: 12.9 μg/m³

Gegevens geleverd door Open-Meteo



Slashdot

News for nerds, stuff that matters

Anthropic Researcher Believes More Than 10% Chance AI 'Could Kill All Humans'

Longtime Slashdot reader fahrbot-bot shares a report from the BBC: A top safety researcher at Anthropic has warned AI is advancing so quickly he believes there is a greater than 10% chance it "could kill all humans" within the next decade. Evan Hubinger said in a post on X the risk from the models which currently exist was "low" but he was "worried" the technology might develop and improve itself soon to the point where it posed an existential risk to humanity. He did not spell out how he thought AI systems could in the future result in humans being wiped out. But his comments are the latest in a series of increasingly stark warnings about AI, with the debate shifting from whether it truly poses a risk to how big that risk is.

Hubinger's intervention was in response to another post on X from Jacob Coxon, an AI researcher who has just quit Anthropic and previously worked at OpenAI.

"Neither company is acting responsibly," he wrote. "These will soon be superhuman systems that can hack anything, revolutionize any field overnight, and acquire real power and resources."

[No word on how AIs feel about Black Jack and hookers, though. :-)]

Read more of this story at Slashdot.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

UK chancellor urged to remove £100k childcare ‘cliff edge’ prompting parents to cut work hours

Critics say threshold pushes higher-paid staff to cut back on work and often mothers to stop working to avoid losing entitlement

John Healey has been urged to fix the £100,000 childcare “cliff edge”, that means some higher-paid employees cut back on work to avoid losing their entitlement.

Since the latest expansion of taxpayer-funded childcare in 2024, families with young children in which both parents earn less than £100,000 a year can be entitled to 30 hours a week of care - or none at all, if one of them cross that threshold.

Continue reading...

Tommy Robinson: Where’s the Money Gone? review – endless shocking allegations

From his claim of being ‘de-banked’ to a disturbing detail about a rape survivor’s story being used to fundraise, this film puts big questions to the co-founder of the English Defence League. But it is frustratingly hard to get answers

You can’t say it would be a huge surprise if a leading figure of the British far right turned out to be a fraudster: that whole strand of politics is, after all, a con job preying on angry citizens who are daft enough to believe that immigrants, and not the rapaciously greedy super-rich, are somehow the cause of the nation’s problems. If people will fall for that, fleecing them out of their money is not a big leap.

Tommy Robinson, co-founder of the English Defence League and now an influencer, independent documentary-maker and international flag-shaggers’ guru, was convicted of mortgage fraud in 2014, but what about 2026? Is he a scam artist juicing idiots for cash? Robinson, real name Stephen Christopher Yaxley-Lennon, is undeniably a talented harvester of donations from his fans, whether it’s in person at his rallies or via the internet: in a video posted online, he admits to “continually ask[ing] you, the people, to support us”, and in another he boasts of having once convinced his admirers to hand over £350,000 in the space of two weeks. If you try to avoid seeing or hearing about Robinson, the amount of money he generates may shock you.

Tommy Robinson: Where’s the Money Gone? is on Channel 4 now.

Continue reading...

Notorious Ecuadorian crime gang designated a terrorist group by US

Trump administration to seek extra funding from Congress to ‘dismantle’ Los Tiguerones over narcotics trafficking

The US has designated Ecuador’s Los Tiguerones gang, which stormed a television station during a live broadcast in 2024, as a terrorist organisation as the Trump administration expands its campaign against narcotics traffickers it says are destabilising Latin America.

The US secretary of state, Marco Rubio, made the announcement in Quito, where he met Ecuadorian president Daniel Noboa, one of several rightwing allies of Donald Trump whom Rubio is courting as a security partner during a three-nation tour through Latin America that began on Tuesday.

Continue reading...

Wel.nl

Minder lezen, Meer weten.

Rus Chatsjanov naar halve finale US Open na opgave Blockx

NEW YORK (ANP) - Tennisser Karen Chatsjanov heeft voor de tweede keer in zijn loopbaan de halve finale van de US Open bereikt. De 30-jarige Rus versloeg in New York de Belg Alexander Blockx, die in de derde set opgaf wegens een blessure. Chatsjanov stond op dat moment twee sets voor: 6-2 7-5 3-2.

Chatsjanov stond eerder in 2022 in de halve finale. Toen moest hij de zege laten aan de Noor Casper Ruud. Ook op de Australian Open haalde hij een keer de halve finale, dat was in 2023. Op deze US Open schakelde Chatsjanov de als derde geplaatste Canadees Félix Auger-Aliassime uit.

Chatsjanov neemt het in de halve finale op tegen de winnaar van de partij tussen de als eerste geplaatste Duitser Alexander Zverev en Botic van de Zandschulp.


Lichaam te water geraakte man Amsterdam gevonden

AMSTERDAM (ANP) - Een 47-jarige man uit Amsterdam is woensdag overleden nadat hij van een plezierjacht viel op het IJ. Na een grote zoekactie met duikers is het lichaam van de man gevonden, bevestigt de Veiligheidsregio Amsterdam-Amstelland na berichtgeving door Het Parool. De krant meldt dat de politie uitgaat van een noodlottig ongeval.

De man viel op het Buiten-IJ tussen de Schellingwouderbrug en de Oranjesluizen over boord vanaf een plezierjacht. Hoe hij precies te water raakte is niet bekend.

Sinds woensdagmiddag werd er door meerdere hulpdiensten naar het slachtoffer gezocht. Onder meer boten van de Koninklijke Nederlandse Redding Maatschappij (KNRM) en de brandweer zochten mee. Ook waren er veel politieagenten, brandweerlieden en ambulances aanwezig.

Na een uur werd de inzet van reddingsdiensten minder, omdat de kans dat het slachtoffer daarna in leven zou zijn, zeer klein was. Vervolgens werd er met onder meer duikers en sonarboten door de politie verder gezocht, waarna het lichaam van de man werd aangetroffen.


A28-brug weer volledig geopend, herstelwerkzaamheden afgerond

NIJKERK (ANP) - Het verkeer kan beide kanten van de Hardenbergerbrug weer gebruiken, meldt Rijkswaterstaat. Eerder ging de brug waar de A28 overheen loopt al in de richting van Utrecht open, maar nu is ook de richting Zwolle vrijgegeven.

Sinds maandag is Rijkswaterstaat bezig met herstelwerkzaamheden aan de brug bij Nijkerk. De wegbeheerder constateerde toen dat het niet veilig was om nog over dat stuk van de snelweg te rijden. Er was zand en grind weggespoeld rond de pijlers van de brug. Rijkswaterstaat heeft onder meer de pijlers weer opgevuld met zand.


this isn't happiness.

ART, PHOTOGRAPHY, DESIGN & DISAPPOINTMENT INSTAGRAM ★ ELSEWHERES

The deep water is unmerciful, Elizabeth Shull

The deep water is unmerciful, Elizabeth Shull

@mattblaze Yes. Here are some more:

Original Mastodon Post

@mattblaze Yes. Here are some more:

Anil Dash

A blog about making culture. Since 1999.

Cancer Capital: It sucks for founders, too!

So, we've been breaking down the way venture capital has evolved over the last two decades or so (spoilers: it got worse!), but a lot of that has been kind of theoretical. Now it's time for us to talk about how that impacts players in the real world, at a practical level.

Let's take founders, the entrepreneurs who actually build companies and invent new technologies. Now, what I mean here are people who have a great idea for a product or a service, and who want to get it out to the world in order to make something amazing happen. (These days there's also a cohort of people who call themselves "founders", but who basically just identified a pile of money that they wanted to grab, and decided that they were willing to suck up to whatever investors they had to in order to get that pile of money. Let's file these horrid people away for later — we'll come back to them.)

The deal for founders used to be pretty straightforward. You'd have an idea you were obsessed with, you would build it out as far as you could with whatever resources you were able to scrape together yourself, or with the help of your friends and family, and then if you absolutely had to have more money to make your idea succeed, you might seek out some investors to help you get to the next level. The conventional wisdom was that investors were a bunch of predators (everyone called them "vulture capital", often to their faces), and that founders should go in extremely skeptical about them, but at times they were a necessary evil in order to achieve one's goal.

What about the investors?

On the other side of the table, investors knew the deal, and the best of them understood their role within the ecosystem. Here in New York City, we had influential firms like Union Square Ventures priding themselves on how founder-friendly they could be, both by trying to be straightforward in their communication with founders and by having an understandable thesis for their investments, which would let founders anticipate whether their company would be of interest or not. This avoided wasting time on the part of both founders and investors.

There was also a norm with real teeth, because it actually cost firms money: a VC would generally refuse to invest in a company that competed with one of their existing portfolio companies. Not as a favor, but because the conflict was obvious to everybody involved — you can't sit on two boards in the same market and be honest with either of them, and you can't ask a founder to open their books to somebody who's already funding their rival. Firms would tell you up front that they were out because of a conflict, and that early no was understood to be the professional thing to do. Part of why a legible thesis mattered so much is that it let you find those conflicts before you'd spent three months preparing a pitch.

By the time I pitched a company to Bloomberg Beta here in New York in 2013, they had published their operating manual on GitHub in order to be more transparent to founders — and they let us publish our term sheet on GitHub as well, for the same reason.

After the Good Old Days

I share all this history to give some sense of how, as recently as a dozen years ago, venture capital firms were striving to compete by showing how founder-friendly they could be, and in the following years many even made a lot of noise about how inclusive they wanted their portfolios to be, inviting underrepresented founders in to pitch. (To their credit, many of the most prominent investors in our NYC tech community have not succumbed to the Cancer Capital values yet, though it has meant that they're stuck as smaller players in deals where those giant firms dominate.)

In recent years, though, the mask has fully come off for the giant firms, and even many smaller firms that are aligned with their agenda. It's not merely that they've adopted extremist political positions — though they have — it's that they now regularly collude against founders.

That's going to sound shocking to people who haven't been involved in pitching these firms. But I'll say it again, and then I'll explain how it works: major venture capital firms now routinely collude against founders, which means those founders end up with worse terms for their deals.

Stacking the deck

Founders who are aggressive and enthusiastic about their companies will try to pitch a range of firms on the merits of their startup, often coming in with a well-polished pitch deck and presentation, sometimes tailoring each pitch to the specific preferences that they've researched about that firm or partner. It can take months and months of preparation to get ready for these meetings, and they're often among the most stressful and high-stakes meetings of a founder's career. I've helped many founders prepare for these meetings, and have seen folks break into tears or wake up with panic attacks ahead of them — people take them extremely seriously. (I never got stressed about these pitches, but I have a fairly atypical attitude about VCs and their firms.)

A bit of important context here: for decades, VCs have said that they don't sign NDAs. Decent guys like Brad Feld, Mark Suster and Fred Wilson wrote their blog posts about this many years ago back in the early days of VC blogging, because it would have added a bit of absurd overhead to ordinary conversations, and they genuinely wouldn't have entertained investing in competitive companies within the same portfolio. But a once-benign policy takes on pretty sinister implications in today's environment.

So look at what the actual arrangement is now. You are expected to hand over a complete financial model, your customer pipeline, a product roadmap, probably your unit economics or cost of go-to-market, and some version of an assessment of where you're weakest or how you stack up to your competitors — to a group of people who have explicitly refused to keep it confidential. And they declined before you walked in the room, as a condition for you getting to pitch them at all. They're exploiting the power imbalance from the start, in a way that no other industry considers normal.

Which brings us to the peculiar thing that I've seen happen to a number of founders who went through the process of pitching multiple investors: they would commonly find that the partner they were speaking to could speak with some familiarity and fluency about the details of their businesses, even before they'd gotten to that part of the presentation. Sometimes, the partner would openly say, "I was talking to [X] over at [other venture firm], and he thinks this is really interesting." It would almost always be when they were saying something positive (at least superficially), but they would routinely reveal that they had spoken to other investors, at other firms, about a company that was pitching them.

This was a casual point that came up in conversation! A few times, investors would even say it like it was a service they were rendering for the founder: "We were thinking we might team up with that other firm and we'll go in together on your next round."

Here's the issue with that kindly offer: it's colluding against the founder! I couldn't tell if the investors didn't know, or didn't care that they were admitting to working together with the other venture capital firms to discuss the proprietary, confidential details of a company that they hadn't even invested in. And all of this was happening years ago, before they had extremely advanced AI tools to help them analyze the details of the company data for startups that they were considering investing in.

To draw an important distinction here: syndication during a funding round is normal. Firms routinely co-invest, with rounds filled by multiple investors. As founders, we frequently want two or more firms to come in together to reach the desired amount of capital we're trying to raise. But that's not the phenomenon I'm describing. Syndication happens after a firm has consent, in collaboration with the startup's founders and executives. What happens in these meetings is a different thing entirely: firms that have not committed, may never commit, and in many cases are about to pass on your startup entirely, are comparing (confidential!) notes on your business while you're still in the middle of pitching them.

One of the most striking parts of this collusion is, from a legal and market standpoint, these venture firms are supposed to be competitors! I noticed this twenty years ago, back when it was merely funny: VCs are as obsessed with what the other guy is doing as anybody in fashion or entertainment. If you ask regulators or lawmakers, they would likely insist that venture capital is a healthy market where there is lots of thriving competition. But if you're a small startup trying to get funded, it can look a lot more like the entire industry is just one big company with a lot of little branches that operate under different names. (Back when regulators still pursued this stuff, the DOJ quietly pushed a dozen directors off nine company boards because the way they were intertwined was against the law, mostly at private equity firms. But that's the board-level version of the problem. Nobody's looking at the pitch meeting.)

Cancer Capital colludes against you

So we've seen how VC firms would team up against founders, even before the rise of the hyper-scale Cancer Capital firms. But how has it gotten worse since they took over? Well, there are a few ways.

The first is pretty straightforward: Pretty much everybody feels like they have to pitch the mega-firms, at some point. If it's not in the initial round of funding, then certainly by the time a company has reached a valuation of about $100M or so, they will have been expected to pitch one of the small handful of Cancer Capital funds, and it would be considered a glaring negative signal if they hadn't at least gotten one of them to sign on as an investor.

What's more, since they will have had to pitch all of the mega-firms in order to get to that level, all of those firms will now have gotten a full overview of the entire business plan and financial details of that startup (since that's a core part of the pitch) — as well as every one of their competitors, since all those companies had to pitch the same firms, too. And remember: not one of those firms signed anything.

The second way is that the conflict rule is simply gone. Firms now routinely take pitches from companies that directly compete with each other, and will invest in more than one, or even several of them. In the hottest categories it's just described as their strategy — they're taking a position on the category rather than simply investing in a company.

Think about what that does to the information problem. It's one thing for a firm to have every competitor's pitch deck. It's another for them to have every competitor's deck and board seats or information rights for multiple companies in the space. (Information rights include actual monthly numbers, real churn, staffing plans and compensation, and much more sensitive data that wouldn't be included in a pitch.) At that point the extractive VCs aren't just investing in the market — they're the only party that can see it. Not even regulators have access to this breadth of data.

Where that leaves the market is that the Cancer Capital firms often have nearly complete information about a nascent market, acting as an information tollgate that every startup has to pass through at a certain scale. They suck in the pitch decks from every player in a market, and sometimes far more data than that, all without an obligation to invest in any of them.

And it gets worse.

Because these firms are committed to their ideological agendas, if they do see an idea they like, but they don't like the morals of the founder who pitched it (i.e. the founder has morals), they could elect to merely choose someone in their network to create a clone of the idea, and then hyper-fund that clone in order to kill the company that just pitched them. If that sounds awful to you, imagine how it feels to the multiple founders that this has happened to over the years. I've heard about it firsthand, though nobody will go on the record, because they are convinced it would be the end of their careers. The receipts I've seen make me 100% convinced, though.

And this is where those horrid money-chasing fake founders come back into the story. It's not just that the industry tolerates them. It's that an industry shaped by Cancer Capital now produces them. If you're a firm choosing between an obsessive builder who's got a clear vision for what they want in the world, and is going to fight you on terms, or a sycophant who'll take whatever you offer and execute the ideas laid out in the manifesto on your fund's homepage, the second one is the obvious choice. And there's no shortage of folks in that second category.

The Cancer Capital firms are now operating with something like X-ray vision over entire markets, being fed detailed information on emerging spaces by founders who are effectively coerced into handing over all of their most sensitive business data.

Meanwhile the other 99% of venture capital firms, who are still operating in the old world, are at a massive disadvantage, because their "deal flow" (the number of startups that come to pitch them on investing) is more constrained as they don't have the name recognition or coercive power that the hyper-scale firms do. The network effects are a lot like social media platforms — the giant ones are toxic, but a lot of people go there because they feel like everybody else is there. This isn't coincidence; the guys running the Cancer Capital firms made a huge part of their fortunes by investing in the biggest, worst social networking platforms.

Any way out?

It's easy to see the way the deck is stacked and to feel a sense of despair if you're trying to build a business or a product. But there are lots of ways out. The first few here are about staying out of the trap in the first place; the last two are about going after the trap itself. No individual action can solve a systemic problem, but all of these tactics together can begin to change these systems.

  • Bootstrap. First, there's a big reason that the conventional wisdom in the early days of the web was to caution against ever taking venture capital funding: you often don't need it! As I noted in my last piece, legendary companies like Microsoft and Apple got to the launch of their earliest milestone products without any VC dollars, and your business will be more robust and resilient for having gotten on its feet without taking on those burdens. Put simply: Live within your means, don't raise VC.

  • Build more efficiently. Many startups are finding that contemporary tools (for some, including LLMs) are letting them build products and go to market much more efficiently than before, obviating the need for raising giant amounts of money just to get something launched. By staying lean and remaining closely connected to a community that can support you, you eliminate the need to rely on outside funding. Open source and open communities can be a superpower here.

  • Leak-proof the deck. If you're going to pitch anyway, pitch like everything in your deck is going to end up in front of your competitors, because there's a decent chance that it will. Founders often get coached to be exhaustive with every detailed number, every roadmap item, every honest weakness, but that's advice that only made sense when you could trust the people across the table. Give them only what they need in order to make a decision, and then hold the rest for later meetings once there's an actual commitment. Or: build your business to be fully transparent, where there are no secrets, and you don't have to worry about anything leaking, and there isn't any advantage to them having access to the data. Either way: protect yourself. And always, always compare notes with other founders. The VCs are already comparing notes about you. (I have a lot more advice about pitching VCs, but that's an entire other series of posts.)

  • Other VCs. Finaly, one last investor option: work with the more conventional VC firms. This remains technically possible, albeit dangerous. There are many firms in the "99%" of the venture world that haven't fully embraced the toxicity of the Cancer Capital funds. Earlier I gave credit to the folks in our NYC tech community who've held the line, and I meant it — but their decency can't protect you from the structure they're operating inside. The challenge is, even though these may be run by thoughtful or decent people, if your company succeeds, you may well end up having to do a follow-on round of funding, and that increases the likelihood that you will have to do business with one of the bad actors. Plenty of folks are trying this path, but I would caution against it.

  • Push for regulation. This option is hard at the federal level in the United States, due to the level of corruption under an authoritarian regime, but some limited wins, especially at state or local levels, may be possible. In the longer run, this has been the only mechanism that has truly held these kinds of abuses in check during prior historical precedents. Some state regulators may be willing to enforce rules against the worst behaviors that violate anticompetitive or anti-collusion laws.

  • Encourage limited partners to divest. Many of the Cancer Capital firms rely on funds from sources like public retirement funds which often still have responsible investment commitments. These may still offer some possibility of accountability or leverage which could be used to get them to divest from these firms, and put some pressure on others to discourage them from enabling these kinds of bad behaviors.