Empty promises: No-Taboo Surprises…
There are some emails you just don’t expect. The kind that take you by surprise. They make your heart pound in your chest and your hands sweat with excitement. The day before yesterday, I received precisely such an email, which served up some truly absurd, no-taboo surprises.
A surprising email, or no-taboo surprises in the inbox
From the message, I learned that I had been assigned a new course in the Security Bez Tabu Academy. But wait, what? How? Where? What course? Why?? So many questions, zero answers. After being relegated from the list of students, such an email was truly a surprise for me. Because I don’t receive any newsletters or other information to this email address.
The invitation was in English, which thankfully I know 🙂 There’s no information anywhere about the course name, whether it’s paid or not; at first glance, it looks like some kind of scam or phishing attempt. So, I open the link in an isolated environment

Thrilled, I clicked the blue Start Course button. After all, blue is the color of hope, a good omen.
Login issues and a bizarre terms of service
A login page appears in Polish. Oh, wait… Forgot Password? that’s English, isn’t it?
I can figure out the course name from the URL – Podstawy CTI (CTI Fundamentals). Hmm, now it’s getting interesting.

But first, I checked the Store Regulations (the link to which appears at the bottom of the page). And I immediately realised it is the exact same set of terms and conditions as before, conspicuously missing §7 and §8, amongst other things. It still contains a clause stating that the training fees include a 23% VAT charge, even though the entity does not feature in the VAT register.So, nothing new, nothing has changed.
I entered the password I used to use, which had been changed by Wojciech Ciemski when he threw me off the course.

The password did not work. I clicked the Nie pamiętasz hasła? (Forgotten your password?) link. I haven’t forgotten it; rather, someone changed it for me.

It redirects me to a page with the URL: lost password.

And that’s where my access ends for now, because the Rejestracja (Registration) link leads to https://securitybeztabu.pl/akademia/moje-konto/lost-password/#. So, we have a classic loop.
Further no-taboo surprises and a permanent block
After one day, I was able to reset my password, and I also received an email assigning me to another course, the OWASP one, but when I tried to log in, it turned out I was “permanently blocked“. Nice, nice, awesome. Whatever this error means for the Academy owner, for me it means one thing: I can’t log in.
It reminds me of all those migrations in companies. We supposedly have a new, great environment, but the old problems remain. And all those “creators” who believe there’s no such thing as constructive and genuine criticism, only hate. Training is for EVERYONE, but…

In summary, I’m getting emails informing me I have access to courses, two of them even! But I can’t log in because I’m blocked. Adding to this the fact that a few days ago the owner of Security Bez Tabu wrote that he had lost access to the mailing list, I’m left wondering how Security Bez Tabu manages these lists and personal data. If I’m blocked, why am I still getting these emails? Who is managing my data now? Why send an email to someone who’s on the naughty list??
Is anyone else on such a list?
