HN user

andygambles

1,465 karma

www.andygambles.com

twitter: @andygambles

Posts151
Comments66
View on HN
appvoice.io 7y ago

Appvoice.io – Communicate Product Updates and News

andygambles
1pts0
baymard.com 7y ago

Drop-Down Usability: When You Should (and Shouldn't) Use Them

andygambles
2pts0
www.webbyawards.com 7y ago

It's Pronounced 'Jif' Not 'Gif' Inventor Confirms

andygambles
2pts0
sploit.io 7y ago

Browser Exploit Finder

andygambles
1pts0
security.ticketmaster.co.uk 8y ago

INFORMATION ABOUT DATA SECURITY INCIDENT BY THIRD-PARTY SUPPLIER

andygambles
5pts0
medium.com 8y ago

Accessing Google’s Private Key

andygambles
7pts2
twitter.com 8y ago

Google Private Key Compromise

andygambles
18pts1
www.blog.google 8y ago

Introducing the security center for G Suite–security analytics and best practice

andygambles
1pts0
www.bbc.co.uk 8y ago

Morrisons data leak: Supermarket liable for staff details breach

andygambles
2pts0
www.vice.com 8y ago

UK Porn Is About to Change in a Way You're Not Going to Like – VICE

andygambles
22pts6
www.inc.com 8y ago

Microsoft Browser Fails During Microsoft Demo Presenter Downloads Google Chrome

andygambles
4pts0
blog.ircmaxell.com 8y ago

Disclosure: WordPress WPDB SQL Injection – Technical – Ircmaxell's Blog

andygambles
4pts0
support.google.com 8y ago

Google Payments Center

andygambles
2pts1
productforums.google.com 8y ago

Chrome Full Screen is no longer showing tabs in windows on Mac OS

andygambles
1pts0
markets.businessinsider.com 8y ago

A $96B fund firm created a AI hedge fund, but didn’t know how it worked

andygambles
1pts0
hackertyper.com 8y ago

Hacker Typer

andygambles
1pts0
www.ncsc.gov.uk 8y ago

EUD Security Guidance: Chrome OS 56 – NCSC Site

andygambles
1pts0
investor.symantec.com 8y ago

DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions

andygambles
81pts52
www.google.co.uk 8y ago

Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”

andygambles
172pts56
www.bbc.co.uk 9y ago

Man trapped in Texas cash machine sends 'help me' notes

andygambles
15pts0
www.youtube.com 9y ago

Mosul: Fight against ISIS from the sky in 360 video

andygambles
2pts0
docs.google.com 9y ago

Mozilla Proposal re: Symantec

andygambles
3pts1
cheeseposties.com 9y ago

Cheese Posties – Subscription Cheese Toasties

andygambles
1pts0
twitter.com 9y ago

US immigration policy changes prevent stripe employee flying to SF

andygambles
2pts0
www.symantec.com 9y ago

Symantec Backs Its CA

andygambles
153pts104
duckduckgo.com 9y ago

DuckDuckGo Search Box

andygambles
3pts0
medium.com 9y ago

Modern Software Over-Engineering Mistakes – Medium

andygambles
3pts0
uk.businessinsider.com 9y ago

Sliding airline seats speed up boarding and departing planes

andygambles
1pts1
support.google.com 9y ago

G Suite Enterprise

andygambles
1pts0
www.bloomberg.com 9y ago

Who Will Pay for San Francisco's Tilting, Sinking Millennium Tower?

andygambles
2pts0

One of the things that I wish we had across browsers was a consistent UI so we could reliably inform users of the indicators to look for.

The UI was consistent with a green address bar as agreed in the cab forum. It was Chrome that broke away from this consistency.

There needs to be a mechanism where a site can provide its verified identity to allow the user to know exactly who they are.

Not every site will need or want this but the ability should exist.

At the moment EV provides this ability. If EV is not seen as the answer then we need to have something else instead. We could decouple this from HTTPS but identity is also a valid purpose of signed certificates.

Have I got this right in lay-mans terms.

The client is forcibly disconnected from the WiFi network and reconnects to the attackers network instead.

The attacker doesn't need to know the WPA2 password but it accepts the connection setting the encryption to zeros.

The client thinks it is connected to the original wifi network and continues as normal.

Wifi traffic is intercepted and unencrypted.

Bad SSL 9 years ago

Regularly used to test client configurations and also as a training aid when teaching users about web security.

In the UK a solid green light means proceed if safe to do so but you may not have right of way and there may be intersecting traffic.

But a Green arrow means you can proceed in the direction of the arrow and you have right of way with no other intersecting traffic.

NeverSSL 10 years ago

Captive portal craziness.

"Click the confirmation link in the email we sent you to get online"

"Enter the code we sent you via SMS to confirm your number"

"Login via Facebook - provide permission to post on your behalf"

"Share on FaceBook for internet access"

"Confirm acceptance of our 6000 word terms and conditions"

Some people who publish on Medium (me included) have a commercial arm which is trying to gain recognition from publishing.

Better known examples would be 37Signals and Buffer.

Increasing sales via the commercial arm is the aim and so being rewarded for publishing is not completely necessary. In fact I would consider paying for more premium features. Such as ability to restrict read next to particular publications or even pay for greater reach in other publishers "read next" areas which could then compensate them.

I also use Medium to publish personally with no real need for financial reward. I use Medium because it is easy and I don't get distracted playing with navigation or sidebar or thinking "I could stick Adsense on this and earn $2.00 a month".

iMac 27inch i5 mid-2011. Upgraded to 32GB of RAM. Just added a 1TB SSD drive and boot from this and it is now like a brand new machine. The existing 1TB drive is used for cold storage.

To load dev environments I use vagrant.