i never browse forums or most websites anymore. my AI has all of my api keys and credentials, and i just ask it to search for whatever info i'm interested in. saves a lot of time but it's kind of funny to watch entire scripts being built to crawl across the application because i'm too lazy to click through myself
Grey-market peptides are better than you’ve been led to believe.
One academic study produced a "41% to 71% peptide failure” headline from one voluntary testing program.
We reanalyzed 64,787 public laboratory reports.
Here’s what the larger record shows:
→ 99.31% contained the peptide named on the label.
→ 93.08% were no more than 10% below the labelled dose—or were at/above it.
→ 98.99% were not severely short-filled, meaning 40% or more below the labelled dose.
And the failures were heavily concentrated.
Depending on the problem measured, just 0.53%–2.43% of vendors accounted for half of the results where:
• the labelled peptide was not found
• purity was below 95%
• the vial contained 40%+ less than labelled
That does not look like one uniformly unsafe market.
It looks like a largely high-performing market with a small, identifiable tail of poor suppliers.
The grey market’s greatest strength is community testing:
Buyers fund independent laboratory tests.
COAs are shared publicly.
Bad batches become visible.
Vendors can be compared.
Communities can react in real time.
In major testing sources, low-purity and underfill rates fell as this surveillance network expanded.
Pharma has mandatory manufacturing controls.
The grey market has a different strength: public, sample-level evidence that buyers can actually inspect.
The answer is more testing, more shared reports and faster visibility into the vendors that fail.
See the complete 64,787-record analysis:
https://t.co/xfb2N09om8
Whitesox vs Yankees, the broadcasters have weirdly zoomed in on a young fan hysterically crying at least 3 different times. Why? Strange #yankees#nyy#MLBTwitter
@TalkinYanks rice's base running has been questionable all year. i can recall at least 2 instances where he held up at 3rd in near obvious scoring scenarios. ivy league brain overthinking, and with the current state of the team, i'm sure he's feeling the pressure to really perform.
@GoogleVRP@Google@TeamYouTube
Google/the Family Link team need to step in. For over a year Google has sat idle while low level criminals weaponize their Parental Link services to steal and destroy people’s digital lives.
Google built Family Link as a protective feature, yet it is now being actively weaponized at scale. Attackers are baking this technique into exploit kits and stealers distributed across underground forums. Once they gain initial access, usually via trivial stealers, they change the account’s date of birth to under 13 and add themselves as a Family Link parent with zero step-up authentication, no 2FA, and no human oversight. The real owner then loses all control and recovery options while the attacker maintains persistent access. People are having their digital lives disrupted, ruined, and extorted through a feature that was supposed to protect them. This is bad engineering at its most obvious.
Reports of this exploitation are now surfacing by dozens daily. This is no longer a fringe issue. It has become a reliable method for account takeover because Google left a high-impact, irreversible action completely ungated. Basic security standards require strong controls and verification on anything this destructive. Google has applied none of them, and the result is widespread abuse that continues to grow.
This has been going on for well over a year with no meaningful response. Treating these cases as normal support tickets while more and more people lose years of email, photos, money, and accounts is negligent. The Kids & Families team and Trust & Safety need to act now. Proper authentication and human review must be added to these changes immediately before even more damage is done.
Shame on you, Google.
Update - 13 July 2026
My 20-Year Google Account is Now Gone
The hacker has now deleted my 20-year-old Google account.
It is completely non-recoverable due to the Family Link exploit.
Here’s what happened:
1. 20-year Google account hacked
2. 65yo Aussie turned into a “child under 13”
3. Hacker adds himself as “parent” via Family Link
4. Password changed
5. 2FA removed
6. Security question removed
7. Hacker takes full control of entire Google suite
8. TeamYouTube confirmed my account hacked
8. Account now permanently deleted by the hacker
Google has known about this Family Link exploit for over 2 years and still allows anyone to change the DOB on a 20-year-old account.
This can happen to you too!
Six official Australian Government reports → zero help
TeamYouTube admits it was hijacked… then tells me to “recover it myself” while the hacker controls it, nice one! They give users false hope of recovery as they won't EVER remove the fake parent.
This isn’t a recovery problem, it's a known security flaw and exploit you allow to occur on your platform with impunity to those who take advantage of it. Could this be considered complicity in crimes against your users?
@Google@sundarpichai@TeamYouTube
Answer me this please! How do you allow a 20-year account to be turned into a child account and then deleted? SHAME ON YOU!
You provide a security flaw that enabled unauthorised users to take control of my personal information, use it for whatever purpose they want to and discard it once the value is extracted from it.
Remove the fake Family Link parent ([email protected]) and return my account to it's full pre-hijack state.
Any activity on [email protected] after 23 April 2026, 9:46 AM AEST was NOT ME.
#GoogleHijack #FamilyLinkExploit #PrivacyBreach
Warning: Google’s Broken Support System & Irresponsibly Designed Family Link Parental Feature is Enabling a New Wave of Ransomware Attacks
tl;dr - Google created a feature capable of transferring near-total control of an account, failed to place meaningful guardrails, verification, or intelligent abuse detection around it, and provides virtually no effective recovery support once it is weaponized. That combination has created a prolific new form of consumer account ransomware: attackers steal an authenticated session, convert the victim’s account into a supervised child account, install themselves as the controlling parent, and then extort the victim using the threat of permanent account loss and mass identity theft.
This just happened to a family member. He used the same Gmail account for nearly his entire adult life, and it became the central identity behind almost everything he did online. His email history, Google Photos, Drive files, gaming accounts, password resets, subscriptions, and years of personal information were all connected to it. He is not temporarily “locked out.” Unless Google intervenes, the account is permanently lost and now controlled by someone else.
The initial compromise appears to have started with common information stealing malware, A/K/A "Stealers". Stealers extract browser data such as cookies, saved credentials, and active session tokens. A stolen session is especially dangerous because the attacker may not need to know the password or defeat two-factor authentication. They are operating through a browser session that Google already considers authenticated.
The attacker then abuses Google’s own account management features. They change the victim’s date of birth, so the adult account appears to belong to a child, trigger the Family Link supervision process, and add an attacker-controlled Google account as the parent. From there, they can reset the password, terminate the victim’s sessions, and establish themselves as the trusted authority over the account.
That abuse is serious on its own, but Google’s support and recovery failures are what make this vector exceptionally dangerous. In a functioning recovery system, the legitimate owner would be able to report the compromise, verify years of account ownership, reverse the fraudulent supervision change, and remove the attacker. Instead, victims are pushed into automated recovery flows that often defer to the attacker-controlled “parent” account. There is frequently no meaningful escalation path, no competent human review, and no practical way to challenge the fraudulent change.
In other words, this is not merely an account takeover technique. It is a permanent account-destruction technique made possible by Google’s inability or unwillingness to support its own users. The attacker exploits the feature, but Google’s recovery model completes the attack. Without that failure, this would be a recoverable security incident rather than the permanent loss of someone’s digital identity.
Google's lack of underlying controls is also difficult to defend. An account that has used the same adult birthdate for ten years should not suddenly be converted into a supervised child account without extensive verification. A new Family Link parent should not be able to immediately reset credentials and displace the established owner. Changes with this level of impact should require step-up authentication, confirmation through long-standing recovery channels, delayed activation, prominent alerts, and a rollback mechanism that the newly added parent cannot override.
The consequences extend far beyond Gmail. Once the attacker controls the primary email address, they can reset passwords for other services, impersonate the victim, access private files and photos, target contacts, distribute malware, and recover accounts across the victim’s digital life. Any passwords, payment data, or notes stolen during the original infostealer infection may create additional losses.
AI is making the surrounding ecosystem worse by lowering the cost of creating convincing fake applications, download pages, advertisements, support sites, and social-engineering material. Less capable criminals can now launch higher-volume campaigns against ordinary users rather than focusing only on large corporate targets. Smaller ransom demands and individual account theft can still be highly profitable when repeated at scale.
The most disturbing part is that this could happen to almost anyone. Google has spent years encouraging people to use one account as their email provider, cloud archive, photo library, identity provider, and recovery mechanism for the rest of their online lives. When a company creates that level of dependence, it also assumes a responsibility to provide competent recovery when its own features are abused.
Right now, Google is failing that responsibility. Until it adds stronger controls and a real human escalation process, Family Link remains an extraordinarily high-impact account-takeover vector capable of permanently separating people from their entire digital lives.
Please fix this
@Google@TeamYouTube