Friday, May 29, 2026

British Olympians Reject “Pointless” Offer To Meet Swim England Chair As Resignation Calls Grow Louder

---- Forwarded message ---------
From: J.Barry Healey <john.b.healey@gmail.com>
Date: Fri, May 29, 2026 at 10:04 AM
Subject: Fwd: Olympians Reject “Pointless” Offer To Meet Swim 


Swim England governors want to meet Olympians calling for resignations but swimmers, past and present, say 'no', one key reason stated like this: “Resignations will improve trust. And those associated with past failures are hardly likely to be the best future leaders."
 
Olympians Reject “Pointless” Offer To Meet Swim England Chair As Resignation Calls Grow Louder

Swim England governors want to meet Olympians calling for resignations but swimmers, past and present, say 'no', one key reason stated like this: “Resignations will improve trust. And those associated with past failures are hardly likely to be the best future leaders."

By Craig Lord • 29 May 2026 View in browser
View in browser
 
 

British Olympians have rejected a “pointless” offer to meet the Swim England Chair who is one of three governors they called on to resign in a letter last month focussed on three recent, damning reports into the association.

In their letter the Olympians expressed full confidence in the current CEO, Andy Salmon, but called for the resignation from governance positions of Chairman Richard Hookway, board safeguarding champion Neil Booth, and former Senior Independent Director Caroline Green, who still sits on the Aquatics GB board. 

State of Swimming understands that the three have not resigned, while a source said that they “had not been asked to do so” at an extraordinary Board meeting held to discuss the Olympians letter. 

When Swim England responded officially to SOS’s request for comment after it drew the board’s attention to the Olympians’ concerns, it noted in a statement:  

“We take the views expressed in the letter from the Olympians seriously. When people within our community take the time to share their perspectives, we want them to know they will be listened toWe're concerned that these individuals feel they need to remain anonymous to Swim England, but we absolutely respect their position.

We have invited the group, or some of its representatives, to meet with us so that we better understand their views, and we hope that invitation will be accepted.   

Swim England, including the Swim England Board, has undergone significant changes in recent years, with our stakeholders telling us that we’re making genuine progress, but we equally recognise how much more there is to do.”   

None of the Olympians has accepted a specific invitation to meet the Chairman that was transmitted through this author. Many replied to reiterate their strong fear of disclosing their identity, as well as suggesting that a meeting is pointless and will change nothing when the letter itself makes their position clear. In the words of one:

“Resignations will improve trust. And those associated with past failures are hardly likely to be the best future leaders. Those two simple messages are crystal clear in our letter. There’s no need for the board to meet us to be able to understand our views.  It is pointless for the Chair to offer us a meeting.

"If the Chair or others finally have something meaningful to say to us about why they refuse to resign, surely they can say it in public to all stakeholders? That way everyone who feels as we do will be able to see why they still believe that they are the best option for our sport.” 

As some also pointed out, it is not just about whether this group of athletes trust their governors, but about the very widespread lack of trust revealed in the Listening Report, for which they believe that only a change of personnel can provide an effective solution.

Concerns Over Apparent Current-Board Backing Of Status Quo

Since SOS revealed the concerns of the Olympians,  more swimming stakeholders, including other GB internationals, holders of key roles in the sport, and representatives of groups of stakeholders in both Britain and England, have been in touch to express their strong support for the call for resignations. 

They believe that accepting responsibility for what went wrong, and allowing the sport to move on under new management, would be a way for Swim England to show that it had understood why trust cannot be built if those in charge of reform are the same people who either oversaw events described in the damning reports, and/or defended those responsible. 

If anything, the situation is now all the more concerning because it would appear that recent arrivals on the board have chosen to support the status quo over joining Olympians in their call for a new start. 

Like most of the Olympians, others who contacted SOS did not generally want to be identified for fear of repercussions. One willing to be named, however, is Professor Sue Arrowsmith, Professor Emerita of the University of Nottingham. The professor, an honorary KC, governance specialist and Masters swimmer, has worked on sport governance with the OECD and United Nations, among others.

She has battled for nearly a decade to improve aquatics governance, lobbying successfully for reform and helping numerous stakeholders with successful complaints and legal processes.

She summed up many of the sentiments expressed to SOS when she commented: 

“Swim England has a fantastic CEO in Andy Salmon. There is a real chance to turn the culture around and create an organisation that is trusted and admired. But the work he is doing to build trust is surely going to be undermined if those at the very top of the sport don’t inspire the same trust.”

“The Listening Report mentioned concerns that those responsible for the problems were themselves overseeing reforms. To me that remains a major problem. But most disappointing of all is that by continuing to support its fellow members from the “old guard” the current board sends out a depressing message about the board as a whole.

"I think many of us hoped that with some recent membership changes the board would take a different approach. The fact that it hasn’t will surely just perpetuate the lack of trust in the board and the concerns in the Listening report about protecting those with power and influence. It’s all very dispiriting for the future of the sport.” 

Change “drastically needed” 

Another leading figure in aquatics who did not wish to be named commented: 

“I hear the views of participants from all areas of the sport and have never known such a level of dissatisfaction with the National Governing Body…… A change in Board management is what is drastically needed to restore confidence.” 

Some of those who approached SOS also say that, in the absence of any meaningful response to the Olympians letter, they intend now to take up complaints and actions over board leadership elsewhere. 

SOS will continue to report on any developments.

More like this

More like this

Less like this

Less like this

Comment

Comment




 


 


SOS+ Contact for Enquiries: craig.lord@stateofswimming.com



 

We Found a Backdoor: Lessons From a WordPress Intrusion

Website security is one of those topics that most people ignore until the moment they can't.

This week, I found myself deep inside a WordPress security incident that unfolded across several websites hosted on the same account. What began as a routine investigation of strange activity eventually revealed unauthorized administrator accounts, hidden files, malicious code, and a site that appeared determined to resurrect itself after deletion.

The experience reinforced several lessons that every website owner should know.

The First Signs

The initial clues were subtle.

Wordfence security scans began reporting unusual activity. Login attempts were pouring in from around the world. Some sites became difficult to access. Administrator accounts appeared that nobody remembered creating.

At first, it was tempting to believe this was merely a configuration problem. After all, security plugins can sometimes lock out legitimate users. Wordfence itself was causing some confusion as settings were adjusted and security measures were tightened.

But then came the discovery that changed the story.

Unauthorized administrator accounts appeared.

Not one.

More than one.

Deleting them did not immediately restore confidence because the obvious question remained:

How did they get there?

Following the Trail

The investigation quickly moved beyond WordPress settings.

Files that did not belong inside WordPress core directories began appearing in security scans.

Examples included:

  • outbound.php
  • wp-olite.php
  • mjc0.php
  • dwn2.php
  • perl.haxor
  • py.haxor

These files were located inside directories where WordPress core files normally reside.

That was a major warning sign.

WordPress core directories should contain WordPress files. They should not contain mysterious PHP scripts with odd names.

Wordfence identified twenty-three such files.

They were deleted.

The Site That Would Not Die

One website in particular, waterpolo.cloh.org, became the center of the investigation.

The infected site was renamed so it could no longer function normally.

The directory was moved out of service.

The malicious files were removed.

And yet parts of the directory structure appeared again.

A hidden .htaccess file surfaced inside a deep WordPress directory. Its purpose was clear: permit PHP execution in places where it normally should not occur.

That was a significant discovery because many malware families attempt to hide inside legitimate-looking folders and then use .htaccess files to bypass normal restrictions.

The site had effectively become untrustworthy.

At that point, the goal shifted from repair to containment.

Containment Steps

Several actions were taken immediately.

Remove Unauthorized Administrators

Every WordPress site was reviewed.

Unknown administrator accounts were deleted.

Known administrator accounts were reviewed.

Passwords were changed.

Enable Two-Factor Authentication

Administrators gained two-factor authentication.

A stolen password becomes far less useful when a second factor is required.

Rotate WordPress SALT Keys

WordPress security keys were replaced.

This forced existing login sessions to become invalid.

Anyone who had obtained a session cookie suddenly found that cookie worthless.

Change Database Passwords

Database credentials were rotated.

Fresh credentials were stored in Bitwarden.

Harden .htaccess

Additional protections were added.

Directory browsing was disabled.

XML-RPC access was blocked.

Direct comment posting was blocked.

The resulting additions looked like this:

These protections now form part of my standard WordPress hardening process.

Review Unknown Files

Security scans identified files that did not belong.

Rather than ignoring warnings, each item was investigated.

Unknown files inside WordPress core locations should never be dismissed casually.

What the Attackers Were Doing

The Wordfence live traffic screen provided a fascinating view into the reality of operating a public website.

Login attempts arrived from:

  • Vietnam
  • Turkey
  • Lithuania
  • Spain
  • Brazil
  • The Netherlands
  • The United States

The attackers probed:

  • wp-login.php
  • xmlrpc.php
  • wp-plain.php

They searched for known vulnerable plugins.

They tested common backdoor locations.

This activity was not targeted specifically at me.

It was automated.

Every exposed WordPress site on the internet receives similar attention.

The difference is whether the defenses hold.

An Important Realization

One of the most useful lessons from this experience was recognizing the difference between noise and evidence.

The internet is noisy.

Bots hammer login pages constantly.

Wordfence blocks many attacks every day.

Most of that activity is routine.

What changed this case was the appearance of unauthorized administrator accounts and malicious files in WordPress core directories.

Those are not normal events.

Those are evidence.

The Human Side

The process was frustrating.

Files appeared, disappeared, and reappeared.

FTP and hosting control panel views sometimes disagreed.

Security tools occasionally became obstacles themselves.

At several points it felt impossible to determine whether the problem was malware, caching, configuration mistakes, or all three.

That uncertainty may be the hardest part of dealing with a website intrusion.

You rarely receive a flashing sign that says:

"Here is the exact problem."

Instead, you collect clues.

You test theories.

You eliminate possibilities.

Eventually a picture emerges.

The Final Lesson

The biggest takeaway from this experience is simple.

Security is not a product.

It is a process.

No plugin can completely protect a website whose passwords are weak.

No password can completely protect a site running vulnerable software.

No scan can protect a site that nobody reviews.

Security comes from layers:

  • Strong passwords
  • Password managers
  • Two-factor authentication
  • Software updates
  • Security monitoring
  • Regular reviews of administrator accounts
  • Backups
  • Healthy skepticism

Most website owners will never face a major compromise.

But if they do, preparation matters.

The best time to improve security is before you need it.

The second-best time is tonight.

Thursday, May 28, 2026

Old Paper Wars

Paper Wars on Grant Street

There was a season in Pittsburgh politics when democracy felt like paperwork.

Not speeches.

Not television ads.

Not viral videos.

Paper.

Petitions.
Signatures.
Affidavits.
Notaries.
Court filings.
Election codes.
Deadlines.
Technicalities.
Challenges.
Objections.

The entire machinery of local democracy often came down to who filed what, when, with which signatures, under which party designation, before which clerk, in which room of the City-County Building.

And for a brief moment in the mid-2000s, I found myself wandering directly into that machinery.

Not as a lawyer.

Not as a party insider.

Not as a wealthy donor.

But as a citizen candidate armed with petitions, election law printouts, handwritten notes, and an increasing fascination with how fragile the system actually was.

Looking back now, these court filings read almost like artifacts from another civilization.

A slower political era.

A more procedural era.

A more local era.

An era before social media swallowed politics whole.

At the center of these filings were challenges to nomination petitions involving candidates for Pittsburgh City Council District 3, including Bruce Kraus and Bruce Krane.
The legal arguments themselves now feel wonderfully specific and almost antique.

Could candidates gather signatures while aligned with a major political party and then pivot into an “independent” or political-body candidacy?

Could someone simultaneously navigate both tracks of the election system?

Did the timing of party changes matter?

Did the signatures remain valid?

Did the paperwork comply precisely with election law?

Was the Bureau of Elections properly enforcing standards?

These were not abstract philosophical questions.

These were ballot-access knife fights.

The filings argued that election law existed for reasons larger than mere technical compliance. They cited court decisions warning against “splintered parties,” “voter confusion,” “frivolous candidacies,” and manipulations of the political process.

At the time, Pittsburgh politics still carried strong traces of old machine culture.

Party endorsements mattered enormously.

Committee structures mattered.

Relationships mattered.

Who got frozen out mattered.

Who had institutional support mattered.

And perhaps most importantly, who understood the procedural rulebook mattered.

Outsiders rarely won.

But outsiders could disrupt.

That was part of the energy of the moment.

The filings themselves were intensely pro se. Citizen-driven. Improvised. Long before ChatGPT, legal templates, or modern digital organizing tools, ordinary people pieced together court challenges using photocopies, law library research, election code citations, conversations, rumor, persistence, and stubbornness.

There is something beautifully chaotic about that now.

One section argued that candidates could not legally ride both horses at once: pursuing Democratic primary legitimacy while simultaneously maneuvering toward independent ballot status.

Another section drilled into the signatures themselves.

Who signed?

When?

Under what party understanding?

Which names were registered voters?

Which handwriting appeared suspiciously similar?

Which notary relationships raised concerns?

One filing bluntly claimed that an entire page appeared to be written “with the same pen and hand.”

Today, some readers may laugh at the hyper-focus on signatures and filing mechanics.

But ballot access is power.

Election procedure is power.

Administrative interpretation is power.

Democracy is not merely ideology. It is process.

And process determines who even reaches the ballot.

That reality remains true today, even if modern politics now performs itself through podcasts, cable news clips, fundraising emails, influencer culture, and algorithmic outrage.

Behind every election still sits a quieter world of filings, deadlines, certifications, technical disputes, and procedural leverage.

The old filings also reveal something deeper about Pittsburgh political culture during that period.

There was distrust everywhere.

Distrust of insiders.
Distrust of party structures.
Distrust of endorsements.
Distrust of city government.
Distrust of overlapping relationships.
Distrust of political maneuvering.

The ethics complaints from that same era carried similar themes.

Who belongs to what organization?
Who watches whom?
Who owes favors?
Who can actually act independently?
Who gets protected?
Who gets excluded?

The election petitions were another front in the same larger civic argument.

Maybe all of it stemmed from a city trying to reinvent itself while still carrying the DNA of old industrial political culture.

Pittsburgh was shrinking in population but exploding with institutional complexity.

Nonprofits were rising.
Foundations were rising.
Universities were rising.
Development authorities were rising.
Political consultants were rising.
Public-private partnerships were rising.

Yet ordinary citizens often still felt locked outside the machinery.

So some citizens fought through procedure instead.

Through hearings.
Through filings.
Through technical challenges.
Through the courts.

Was that democratic accountability?

Or procedural trench warfare?

Maybe both.

One thing becomes very clear rereading these petitions now:

Local democracy used to require physical endurance.

People drove downtown.

Waited in offices.

Hand-delivered paperwork.

Made photocopies.

Read actual election law books.

Tracked filing deadlines manually.

Visited courtrooms.

Talked directly to election officials.

There was friction everywhere.

And strangely enough, that friction may have produced more civic literacy than today’s instant-comment politics.

Modern political participation is often emotional but shallow.

Back then, participation could become obsessive and procedural.

You learned how systems actually worked.

Or failed to work.

The petitions themselves repeatedly invoke “the integrity and stability of the political system.”

That phrase now feels almost haunting.

Because twenty years later, Americans trust institutions even less.

Trust in elections is weaker.
Trust in government is weaker.
Trust in media is weaker.
Trust in expertise is weaker.

And yet most citizens remain far less connected to the procedural mechanics underneath public systems.

Few people know how ballot access works.

Few people understand nomination petitions.

Few people know how local election boards function.

Few people have ever filed a formal challenge.

Few people know where power actually lives.

That ignorance creates openings for insiders.

Always.

Perhaps that is one lesson hidden inside these dusty filings.

Democracy belongs not only to charismatic candidates or wealthy donors or political parties.

It also belongs to citizens willing to read the fine print.

Citizens willing to ask annoying questions.

Citizens willing to challenge assumptions.

Citizens willing to stand in hallways holding paperwork.

Even when they lose.

Even when the system barely notices.

Even when history forgets the moment entirely.

These documents now feel less like attacks on individuals and more like attempts to stress-test democratic process itself.

Could the rules survive scrutiny?

Could election systems withstand citizen examination?

Could ordinary people meaningfully challenge institutional momentum?

Or were the outcomes largely predetermined by political gravity?

That question still matters.

Especially now.

Because modern politics increasingly trains citizens to become spectators instead of participants.

Consumers instead of investigators.

Cheerleaders instead of challengers.

The old paper wars on Grant Street remind us that democracy can still be touched physically.

Stamped.
Filed.
Questioned.
Objected to.
Argued over.
Verified.

Messy democracy may actually be healthier than passive democracy.

And perhaps the deeper point was never whether a particular petition succeeded or failed.

The deeper point was that citizens still believed the system could be confronted directly.

That belief may be rarer today than many people realize.

Ethics complaints from back in the day




PDFs of the three complaints sent to the Ethics Hearing Board in its infancy: 










Bonus reads:






Thursday, May 21, 2026

Fwd: ❇️ LifeguardEye Webinar Recording: A Rare Discussion with Aquatic Operators Using AI





--
Ta.
 
 
Mark Rauterkus       Mark.Rauterkus@gmail.com
Mark@Rauterkus.com    <--- causing lots of missed messages, sadly.
Webmaster, International Swim Coaches Association, SwimISCA.org
Coach at The Ellis School for Varsity & Middle School Swimming

412 298 3432 = cell


---------- Forwarded message ---------
From: LifeguardEye <mark@lifeguardeye.com>
Date: Thu, May 21, 2026 at 7:29 AM
Subject: ❇️ LifeguardEye Webinar Recording: A Rare Discussion with Aquatic Operators Using AI
To: <mark.rauterkus@gmail.com>


Click here to unsubscribe from this campaign.

Wednesday, May 20, 2026

Fwd: Speak out against the 'Future Ready Plan'

---------- Forwarded message ---------
From: ppscommunityproposal <ppscommunityproposal@gmail.com>
To: <sarahzangle@gmail.com>
Cc: Michael T. Cummins Jr. <mtcummins@gmail.com>


Hi Everyone, 

Thank you for all your continued efforts over the past year to hold the administration accountable for current and proposed actions. Over the past 6 months, the Community Proposal Team has concentrated their efforts on advocating against the 'Future Ready Plan' rather than advancing the Community Proposal.  

We are writing to you now at a pivotal time in this process. PPS School Board votes on the 'Future Ready Plan' and school closures next Wednesday, May 27th. 

In advance of this decision, The Community Proposal Team is urging the board to Vote No to the 'Future Ready Plan' in its current iteration. We are joining our voice with Black Women for a Better Education, Pennsylvania Interfaith Impact Network, 412 Justice and Equity, and many other organizations uniting and collaborating to implore the board to reject this plan. 
 
What can you do? 

- Join the Rally prior to the Public Hearing at 5 pm on Tuesday, May 26th in front of the PPS administration building. 

- Speak up at the Hearing on Tuesday, May 26th and tell the board to vote against agenda item 17.01. Sign up here: https://pghboe.az1.qualtrics.com/jfe/form/SV_3t2rKx6cJ1tqT1Y or use the QR code below. 

Thank you in advance for your support! 

Sarah Zangle, Community Proposal Lead Coordinator 

image.png

I’m putting out a quiet call to other website owners, developers, hosting admins, and WordPress people.

I’m dealing with a brutal website security mess across several small WordPress sites, and I’m trying to compare notes with others who manage hosting accounts, WordPress installs, cPanel-style environments, or Google Search Console properties.

The pattern is ugly: under-the-hood malware, fake AMP pages, Google Search Console “AMP page domain mismatch” warnings, surprise ownership verification attempts, changed index.php files, rewritten robots.txt files, strange PHP loaders, and remote scripts aimed mostly at search bots rather than normal visitors.

I am not claiming I know the root cause yet. It could be compromised WordPress installs, bad plugins, stolen credentials, web shells, hosting-layer exposure, or something farther upstream. But the symptoms are repeating across enough places that I want to ask plainly:

Are other webmasters seeing this too?

Especially:

  • Fake AMP pages tied to domains you control
  • Google Search Console ownership you did not add
  • index.php files altered to serve different content to Googlebot
  • robots.txt or sitemap files rewritten
  • PHP files calling strange outside domains
  • Malware recurring after local cleanup

Security people often do not want to discuss details in public, and I respect that. But if you are seeing similar patterns, I’d like to compare notes privately.

This is the kind of thing that makes you want to scream because the public-facing site may look normal while the damage is happening underneath.

Photo from a past CodeFest event -- where we won an award. I'm on the far left. 


Friday, May 15, 2026

Fwd: It's race week — and we're bringing Dual Boards to the pool 🏊‍♂️


-- Forwarded message ---
From: Jose Gallagher <josegallagher@ripcurrentsports.com>
Date: Fri, May 15, 2026 at 11:07 AM
Subject: It's race week — and we're bringing Dual Boards to the pool 🏊‍♂️



A Masters swim meet, a free demo, and why I still get butterflies before a race.  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
RACE WEEK
It's shave and taper time — and Dual Boards training will represent.
Hi everyone,
I'll be honest with you — there's a specific kind of nervous energy that only race week brings. The taper is on. The shave is coming. And no matter how many times you've stood on that block, you still feel it.
This weekend I'm competing at a Masters Swim Meet at Somerset Hills YMCA in Basking Ridge, NJ. Six events over two days. 
Image item
Here's what's on my schedule:
 
1650 Free Saturday · 66 lengths
400 IM Sunday · all four strokes, four lengths each
200 Back Sunday
200 IM Sunday
100 Back Sunday
100 Free Sunday
 
Masters swimming is something I'd recommend to any competitive swimmer who thinks their racing days are behind them. They're not. The water doesn't care how old you areit just asks if you're willing to show up.
 
But before the meet, something I'm equally excited about: tomorrow afternoon, a local swim program reached out and asked if I'd come demo Dual Boards with their athletes. For free. No pitch, no pressurejust put the product in the water and let it speak for itself.
 
That's always been my belief about Dual Boards: when a swimmer tries it, the Boards do the selling. I'm just there to watch.
 
I'll share how it goes on social — and I'll be back next week with results from the meet. Until then, if you've been curious about what Dual Boards actually look like in the water, here's your chance to see it.
Thanks for being on this list. It means more than you know.
- Jose
 Founder - Rip Current Sports
Follow along: Click Images Below for our Instagram
11160 Viers Mill Rd. Ste Llh-18 #172
Wheaton, MD 20902, United States