HNHacker News
TopNewBestAskShowJobs

andygambles

1,465 karma · joined November 22, 2012

www.andygambles.com

twitter: @andygambles

submissionscomments
andygambles··on Google Private Key Compromise
It isn’t real https://medium.com/@ECCTLS/how-to-sign-with-googles-private-...
andygambles··on Accessing Google’s Private Key
Cloudflare Key Compromise: https://twitter.com/ECCTLS/status/980661799539310592
andygambles··on Are EV certificates worth the paper they're written on?
> One of the things that I wish we had across browsers was a consistent UI so we could reliably inform users of the indicators to look for.

The UI was consistent with a green address bar as agreed in the cab forum. It was Chrome that broke away from this consistency.

andygambles··on Are EV certificates worth the paper they're written on?
There needs to be a mechanism where a site can provide its verified identity to allow the user to know exactly who they are.

Not every site will need or want this but the ability should exist.

At the moment EV provides this ability. If EV is not seen as the answer then we need to have something else instead. We could decouple this from HTTPS but identity is also a valid purpose of signed certificates.

andygambles··on Google Payments Center
Behind a Google Login but interface is at https://payments.google.com
andygambles··on Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
Have I got this right in lay-mans terms.

The client is forcibly disconnected from the WiFi network and reconnects to the attackers network instead.

The attacker doesn't need to know the WPA2 password but it accepts the connection setting the encryption to zeros.

The client thinks it is connected to the original wifi network and continues as normal.

Wifi traffic is intercepted and unencrypted.

andygambles··on Equifax website hacked again, this time to redirect to fake Flash update
Which is easy if you set preload header.
andygambles··on Ask HN: What is your preferred method of sending large files over the internet?
https://wetransfer.com

Often sending to non-technical people and this I have found is the easiest solution they understand. Click and download.

Would use Google Drive but it makes the download process rather complicated and non-obvious.

andygambles··on Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
I used inurl:server to restrict the results to mainly just server.key files so revealing the private keys of HTTPS websites.

Of course you can remove it. Just means more results to wade through.

andygambles··on Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
Some of the results are web servers leaking the private keys of the website or in some cases mail servers.
andygambles··on “Users will only be able to view patents via HTTP. HTTPS will no longer work”
Removal of HTTPS is on http://portal.uspto.gov/
andygambles··on Most Electronics Being Banned on Certain US-Bound Flights
Wipe devices before packing.

Arrive in country then restore backup remotely.

andygambles··on Bad SSL
Regularly used to test client configurations and also as a training aid when teaching users about web security.
andygambles··on German traffic light stays red for 28 years (2015)
In the UK a solid green light means proceed if safe to do so but you may not have right of way and there may be intersecting traffic.

But a Green arrow means you can proceed in the direction of the arrow and you have right of way with no other intersecting traffic.

andygambles··on Dropbox Paper
So is this essentially OneNote?
andygambles··on After 1 minute on my modem (2016)
Currently only have a 1.2M connection at home. Reveals how bandwidth intensive many website are that simply do not need to be.

Ad Blocker is a must.

andygambles··on Commission proposes updates data protection rules for EU institutions
Interesting part is EU have decided all these cookie accept banners are a PITA and so users should be allowed to set cookie permissions in "software applications enabling accessing to the internet"

Which was suggested when the original law came to pass in 2012.

andygambles··on The closest I've ever come to falling for a Gmail phishing attack
It is a much more visible change rather than a URL that could be spoofed or malformed.
andygambles··on The closest I've ever come to falling for a Gmail phishing attack
In general they should use EV site wide rather than just login pages just to help confirm it is the correct legitimate website.
andygambles··on The closest I've ever come to falling for a Gmail phishing attack
The aim of EV certificates is to reduce such risks and highlight to the user the legitimacy of such websites.

HTTPS alone only provides encryption. Google doesn't use EV anywhere but I feel it should on login pages especially given it is a high phishing target.

andygambles··on NeverSSL
Captive portal craziness.

"Click the confirmation link in the email we sent you to get online"

"Enter the code we sent you via SMS to confirm your number"

"Login via Facebook - provide permission to post on your behalf"

"Share on FaceBook for internet access"

"Confirm acceptance of our 6000 word terms and conditions"

andygambles··on Renewing Medium’s focus
Some people who publish on Medium (me included) have a commercial arm which is trying to gain recognition from publishing.

Better known examples would be 37Signals and Buffer.

Increasing sales via the commercial arm is the aim and so being rewarded for publishing is not completely necessary. In fact I would consider paying for more premium features. Such as ability to restrict read next to particular publications or even pay for greater reach in other publishers "read next" areas which could then compensate them.

I also use Medium to publish personally with no real need for financial reward. I use Medium because it is easy and I don't get distracted playing with navigation or sidebar or thinking "I could stick Adsense on this and earn $2.00 a month".

andygambles··on Use Maps in Lite mode
Would have thought Google got really clever and detected if bandwidth is low to load lite version.
andygambles··on Building Jarvis
Mildly amusing video by Zuckerberg to go with this: https://www.facebook.com/zuck/videos/vb.4/10103351034741311
andygambles··on Uber employees used the platform to stalk celebrities and their exes
We do not keep any card data.

We have to keep address details to prove we have charged VAT correctly.

andygambles··on Uber employees used the platform to stalk celebrities and their exes
HMRC (UK Tax Office) requires us to keep transactional information for 6 years.

Upon request we delete accounts but if they have transactional data this is still held in accordance with our legal requirements.

andygambles··on CloudRail: Easily integrate whole categories of providers
Why would you add an extra failure level and pay for the privilege?
andygambles··on Ask HN: What's your dev machine setup?
iMac 27inch i5 mid-2011. Upgraded to 32GB of RAM. Just added a 1TB SSD drive and boot from this and it is now like a brand new machine. The existing 1TB drive is used for cold storage.

To load dev environments I use vagrant.

andygambles··on Chrome 55 to start highlighting Not Secure websites
As per an earlier comment option to enable this feature is here: chrome://flags/#mark-non-secure-as

Occasionally in a build it flips on then another build off.

andygambles··on The DROWN Attack
I guess DROWN has a better ring to it than DROWE
Page 1 of 3Next →