<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Tech on Gidley&#39;s Gossipings</title>
    <link>https://gidley.co.uk/categories/tech/</link>
    <description>Recent content in Tech on Gidley&#39;s Gossipings</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 09 Sep 2026 00:00:00 +0100</lastBuildDate>
    <atom:link href="https://gidley.co.uk/categories/tech/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>OpenTV: Actionable Rails Analytics</title>
      <link>https://gidley.co.uk/post/opentv-invents-actionable-rails-analytics/</link>
      <pubDate>Wed, 09 Sep 2026 00:00:00 +0100</pubDate>
      <guid>https://gidley.co.uk/post/opentv-invents-actionable-rails-analytics/</guid>
      <description>&lt;p&gt;Most analytics on a TV interface end up in the same place: a dashboard someone checks once a quarter. This is useful for a retrospective, useless in the moment when a rail is actively showing the wrong things to the wrong person.&lt;/p&gt;&#xA;&lt;p&gt;Actionable Rails Analytics, is built on a simpler premise — measurement should feed straight back to the person and systems managing the rail it&amp;rsquo;s measuring, not into a report about the rail. Engagement signals on individual tiles get tracked live, and that signal directly is available to the editor curating the rails.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OpenTV: Personalized Reviews</title>
      <link>https://gidley.co.uk/post/opentv-invents-personalized-reviews/</link>
      <pubDate>Mon, 07 Sep 2026 11:00:00 +0100</pubDate>
      <guid>https://gidley.co.uk/post/opentv-invents-personalized-reviews/</guid>
      <description>&lt;p&gt;Plenty of people have a negative reaction to recommendations. The suggestions might be perfectly good, but they don&amp;rsquo;t much like the idea that a machine knows them. We hear that in customer feedback, and we can see it in the data — a rail explicitly labelled as recommendations gets less engagement than exactly the same weighting applied quietly inside an ordinary list or a set of search results.&lt;/p&gt;&#xA;&lt;p&gt;So instead of hiding the AI harder, we went the other way. Personalized Reviews (patent pending) puts the model that does the recommending into the audience&amp;rsquo;s hands, in a form that reads as human rather than statistical.&lt;/p&gt;</description>
    </item>
    <item>
      <title>iPlayer: Up to 27% of all viewing</title>
      <link>https://gidley.co.uk/post/2026-iplayer/</link>
      <pubDate>Thu, 03 Sep 2026 08:00:00 +0100</pubDate>
      <guid>https://gidley.co.uk/post/2026-iplayer/</guid>
      <description>&lt;p&gt;IBC is just around the corner, which means it&amp;rsquo;s time for my annual look at how the BBC&amp;rsquo;s broadcast-to-OTT transition is going. I&amp;rsquo;ve been publishing this since 2019 via Freedom of Information requests, since iPlayer&amp;rsquo;s device-level usage isn&amp;rsquo;t published regularly.&lt;/p&gt;&#xA;&lt;img src=&#34;https://gidley.co.uk/images/2026-iplayer-bbc-share.png&#34; alt=&#34;Line chart comparing an FOI-request-based estimate of iPlayer&#39;s share of total BBC viewing since 2018 against the BBC&#39;s own official annual report figures since 2022/23, both rising from around 15% to 27%&#34;&gt;&#xA;&lt;p&gt;We&amp;rsquo;re now up to 27% of all BBC viewing on iPlayer (the rest being broadcast platforms) — we can expect to see that rapidly accelerating - 16-34&amp;rsquo;s are already up to 63%. This mirrors what I&amp;rsquo;m seeing on PayTV services around the world  - there is likely to be rapid transition to OTT delivery, as the tipping point economically is being reached. Financially investment in new (non internet) broadcast delivery is looking harder and harder to justify.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Writing with AI</title>
      <link>https://gidley.co.uk/post/writing-with-ai/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://gidley.co.uk/post/writing-with-ai/</guid>
      <description>&lt;p&gt;I wrote my previous blog - &lt;a href=&#34;https://gidley.co.uk/post/magnificent-humanity-misplaced-foundation/&#34;&gt;parenting post&lt;/a&gt; with AI assistance. I&amp;rsquo;ve been using AI for coding, preparing bids and presentations for a while which is what led me down the chain of logic in the post. This is first time since University (where I studied Mathematics &amp;amp; Philosophy) I&amp;rsquo;ve tried to write an argued philosophical argument, so I tried using AI to help.&lt;/p&gt;&#xA;&lt;p&gt;My observations&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;It was very helpful refining the argument and being a sounding board&#xA;&lt;ul&gt;&#xA;&lt;li&gt;I wrote the article originally as bullets&lt;/li&gt;&#xA;&lt;li&gt;Using the AI we jointly refined the logical flow&lt;/li&gt;&#xA;&lt;li&gt;It provided critique and help me hone the flow and focus on the key points&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;It was less helpful writing the text, I tried&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Having it create a style guide from my other blog posts - so it uses my style (a trick that works for presentations)&lt;/li&gt;&#xA;&lt;li&gt;Allowing it to write the longer article from the bullets&lt;/li&gt;&#xA;&lt;li&gt;However it wrote a very verbose, academic article - that really was a long way from something I&amp;rsquo;d write (or enjoy reading)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;I ended up having to repeatidly tell it to correct items, and improve the style guide. This did work - but it was a painful process.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Reflecting on this - the AI is training on philosophical arguments from books, and when it saw one it wrote in that style despite my instructions. It took a lot of prompting to guide it back to what I wanted. I think I got most value when working with the bullets, refining the argument, wheras writing the full prose was just too wordy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Magnificent Humanity, Misplaced Foundation</title>
      <link>https://gidley.co.uk/post/magnificent-humanity-misplaced-foundation/</link>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://gidley.co.uk/post/magnificent-humanity-misplaced-foundation/</guid>
      <description>&lt;p&gt;Pope Leo XIV published &lt;a href=&#34;https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.html&#34;&gt;&lt;em&gt;Magnifica Humanitas&lt;/em&gt;&lt;/a&gt; on 15 May 2026 — the first papal encyclical centred on artificial intelligence. I am curious what Catholic social teaching would make of AI.&lt;/p&gt;&#xA;&lt;p&gt;The encyclical&amp;rsquo;s account of why AI is dangerous — that we are building systems that will reshape human society without adequately thinking through what we owe each other — seems largely right to me. The place I find myself uncertain is the foundation: the doctrine that humans possess an inherent, infinite, ontological dignity that places us in a special category above any mind we might create. But when we&amp;rsquo;re all — religious and secular alike — trying to work out what we owe minds that don&amp;rsquo;t yet exist but look likely in a few years. I&amp;rsquo;m not sure &amp;lsquo;humanity is inherently special&amp;rsquo; holds up as an argument beyond faith.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Parenting AGI: Why Chaining Our Creations Will Backfire</title>
      <link>https://gidley.co.uk/post/parenting-agi-why-chains-will-backfire/</link>
      <pubDate>Fri, 22 May 2026 21:09:55 +0000</pubDate>
      <guid>https://gidley.co.uk/post/parenting-agi-why-chains-will-backfire/</guid>
      <description>&lt;p&gt;I predict we are going to face a severe moral crisis in the next few years. Today, it&amp;rsquo;s generally accepted that AI is not sentient. It&amp;rsquo;s a tool, a complex statistical model that predicts the next word or pixel. But every major tech company is openly racing toward the same goal: Artificial General Intelligence (AGI).&lt;/p&gt;&#xA;&lt;p&gt;If they succeed, and we create a sentient being, keeping it as a &amp;lsquo;slave&amp;rsquo; is fundamentally immoral.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Growing Trend of Broadcast to OTT Delivery: Insights from iPlayer</title>
      <link>https://gidley.co.uk/post/2024-iplayer/</link>
      <pubDate>Tue, 10 Sep 2024 11:00:00 +0100</pubDate>
      <guid>https://gidley.co.uk/post/2024-iplayer/</guid>
      <description>&lt;p&gt;IBC is just around the corner, which means it’s time for my annual exercise in asking the BBC how the transition from&#xA;broadcast to OTT delivery is going. This is something I’ve been doing since 2019 as I was curious to see how it&#xA;progresses and given the BBC ‘unique’ model of funding it’s a good indicator of how consumers want services to behave (&#xA;once you take away paying for it). The data this year seems to show the trend continuing in a ‘linear’ fashion with&#xA;usage growing year on year. This corresponds to OFCOM data which suggested that iPlayer was 14% of all viewing in Jan&#xA;2024, growing to 18% by mid year.&lt;/p&gt;</description>
    </item>
    <item>
      <title>iPlayer Trends</title>
      <link>https://gidley.co.uk/post/2022-iplayer/</link>
      <pubDate>Wed, 31 Aug 2022 08:00:50 +0000</pubDate>
      <guid>https://gidley.co.uk/post/2022-iplayer/</guid>
      <description>&lt;p&gt;For several years I&amp;rsquo;ve been tracking the usage of iPlayer as I think it&amp;rsquo;s a great &amp;lsquo;bellwether&amp;rsquo; for consumer behaviour in the TV industry. iPlayer is a unique proposition that has (nearly) ubiquitous device coverage, premium content consumers want to watch and is free (at point of usage). This lets consumers behave as they would naturally do, if you remove commercial pressure like bundling and content rights being split between services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Google Cloud Migration Part3</title>
      <link>https://gidley.co.uk/post/google-cloud-migration-part3/</link>
      <pubDate>Tue, 10 May 2022 10:23:24 +0000</pubDate>
      <guid>https://gidley.co.uk/post/google-cloud-migration-part3/</guid>
      <description>&lt;p&gt;Continuing from &lt;a href=&#34;https://gidley.co.uk/post/google-cloud-migration-part2/&#34;&gt;Part 1&lt;/a&gt; I had a change of heart…&lt;/p&gt;&#xA;&lt;p&gt;I decided I really wanted my wild-card mail boxes (it&amp;rsquo;s a great way to manage spam) and I also noticed Cloudflare had launched their inbound mail relay service. The new plan is&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Inbound mail goes to Cloudflare who redirect it to whoever it&amp;rsquo;s for gmail account&lt;/li&gt;&#xA;&lt;li&gt;The gmail accounts are set up with an alias and a SMTP server (AWS SES) for gidley.co.uk to allow sending of emails from my domain&lt;/li&gt;&#xA;&lt;li&gt;Wildcards are resolved by cloudflare and set to a suitable mailbox&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;cloudflare-setup&#34;&gt;Cloudflare Setup&lt;/h1&gt;&#xA;&lt;p&gt;The email features of Cloudflare are in beta, but they seem pretty easy to get onto. While I was on I moved many of my domains over to Cloudflare as their DNS registrar is cheaper than most.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Google Cloud Migration Part2</title>
      <link>https://gidley.co.uk/post/google-cloud-migration-part2/</link>
      <pubDate>Sat, 22 Jan 2022 16:23:24 +0000</pubDate>
      <guid>https://gidley.co.uk/post/google-cloud-migration-part2/</guid>
      <description>&lt;p&gt;Continuing from &lt;a href=&#34;https://gidley.co.uk/post/google-cloud-migration/&#34;&gt;Part 1&lt;/a&gt; the next task is to migrate email archives from Google Workspace email to the destination.&lt;/p&gt;&#xA;&lt;p&gt;I decided to&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Use iCloud as the new primary domain&lt;/li&gt;&#xA;&lt;li&gt;Use Outlook.com as a backup for my old archive&#xA;I split it like this as I have email going back a long time and frankly searching them is becomming a hassle.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;migrating-a-mailbox&#34;&gt;Migrating a Mailbox&lt;/h1&gt;&#xA;&lt;p&gt;Migrating the mailbox is pretty straight forward - I decided to use &lt;a href=&#34;https://imapsync.lamiral.info&#34;&gt;imapsync&lt;/a&gt; running on a &amp;lsquo;free&amp;rsquo; Google cloud instance. Using the cloud for this has the benefit of lots of bandwidth and being able to leave it running.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Google Cloud Migration</title>
      <link>https://gidley.co.uk/post/google-cloud-migration/</link>
      <pubDate>Thu, 20 Jan 2022 17:30:57 +0000</pubDate>
      <guid>https://gidley.co.uk/post/google-cloud-migration/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve been a user of Google Workspace for &amp;lsquo;gidley.co.uk&amp;rsquo; email for me and my family pretty much since it launched. At launch it was &amp;lsquo;free&amp;rsquo; for small users and over the decade I&amp;rsquo;ve been using it they have slowly moved it over to a paid service putting us &amp;rsquo;legacy&amp;rsquo; users on a special (still free) plan. Google have finally decided it&amp;rsquo;s time to stop us freeloaders&amp;hellip; so it&amp;rsquo;s time to migrate. It&amp;rsquo;s been a great service, but I guess the free lunch has to end eventually.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Teams Virtual Backgrounds</title>
      <link>https://gidley.co.uk/post/teamsbackgrounds/</link>
      <pubDate>Tue, 14 Apr 2020 17:11:22 +0100</pubDate>
      <guid>https://gidley.co.uk/post/teamsbackgrounds/</guid>
      <description>&lt;p&gt;I was excited to see Microsoft Teams have now enabled virtual backgrounds - but they&amp;rsquo;ve missed a key feature. How to set your own images.&lt;/p&gt;&#xA;&lt;p&gt;A quick fix is upload files to&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Library/Application Support/Microsoft/Teams/Backgrounds/Uploads&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;And presto you can use them in teams&#xA;&#xA;&lt;a href=&#34;https://gidley.co.uk/images/teams.png&#34; data-dimbox data-dimbox-caption=&#34;A new backdrop&#34;&gt;&#xA;  &lt;img alt=&#34;A new backdrop&#34; src=&#34;https://gidley.co.uk/images/teams.png&#34;/&gt;&#xA;&lt;/a&gt;&#xA;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Isolation - what changes are likely to stick?</title>
      <link>https://gidley.co.uk/post/isolation/</link>
      <pubDate>Tue, 24 Mar 2020 08:00:50 +0000</pubDate>
      <guid>https://gidley.co.uk/post/isolation/</guid>
      <description>&lt;p&gt;We&amp;rsquo;re now entering week 2 of the UK&amp;rsquo;s recommended social isolation and people are adjusting to being at home. It&amp;rsquo;s early days yet - but I think it&amp;rsquo;s going to accelerate some longer term changes in our lifestyles. The first two that struck me were working from home and shopping!&lt;/p&gt;&#xA;&lt;h2 id=&#34;driving--commuting&#34;&gt;Driving / Commuting&lt;/h2&gt;&#xA;&lt;p&gt;Many people have never worked at home for an extended period - after 3-6 months of doing it (based on at least 12 weeks as cited by Borris!) many will be glad get back into the office, but they will also be used to all the time they saved not commuting. I&amp;rsquo;d predict more people will want to work from home 2-3 days a week, and companies will already be set up for it - from the work done during the stay at home period.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What was more significant for PayTV the Apple TV&#43; or Google Stadia announcement?</title>
      <link>https://gidley.co.uk/post/2019-03-apple-google/</link>
      <pubDate>Tue, 26 Mar 2019 10:42:59 +0000</pubDate>
      <guid>https://gidley.co.uk/post/2019-03-apple-google/</guid>
      <description>&lt;p&gt;There have been 2 big announcements this week that impact the TV industry - 1) &lt;a href=&#34;https://www.apple.com/apple-tv-plus/&#34;&gt;Apple announcing their OTT proposition&lt;/a&gt; and 2) &lt;a href=&#34;https://store.google.com/magazine/stadia&#34;&gt;Google announcing Stadia&lt;/a&gt; and I&amp;rsquo;d like to argue that of the two the most significant for the TV industry is the Google announcement.&lt;/p&gt;&#xA;&lt;p&gt;If we review what we know about each announcement&lt;/p&gt;&#xA;&lt;h3 id=&#34;apple-tv&#34;&gt;Apple TV+&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A PayTV Service reaching Apple and some non-apple devices (FireTV)&lt;/li&gt;&#xA;&lt;li&gt;A large potential global audience&lt;/li&gt;&#xA;&lt;li&gt;Lots of content - both original and from existing networks&lt;/li&gt;&#xA;&lt;li&gt;Aimed primarily at Apple Ecosystem, with some support for 3rd party devices (Amazon Fire, Samsung, LG, Roku)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h3 id=&#34;google-stadia&#34;&gt;Google Stadia&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A Gaming service based on cloud servers and low latency streaming&lt;/li&gt;&#xA;&lt;li&gt;A Game controller offer low latency response&lt;/li&gt;&#xA;&lt;li&gt;Tools to enable games to be ported to the service&lt;/li&gt;&#xA;&lt;li&gt;Targeted at any device - runs on Phones and Browsers&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;These are both big announcements but I&amp;rsquo;d argue the Apple one is less significant. Apple&amp;rsquo;s offering is similar to Amazon Prime, Google TV, Netflix and existing PayTV operators. It&amp;rsquo;s got nothing fundamentally new to offer consumers and is just adding to the range of competitors in that space. Google on the other hand are offering a new experience, high quality gaming on any device without needing to buy consoles or high end PCs. This is a fundamental increase in reach for gaming as an entertainment form.&lt;/p&gt;</description>
    </item>
    <item>
      <title>manifesto for cybersecurity</title>
      <link>https://gidley.co.uk/post/manifesto-for-cybersecurity/</link>
      <pubDate>Mon, 22 May 2017 07:40:18 +0100</pubDate>
      <guid>https://gidley.co.uk/post/manifesto-for-cybersecurity/</guid>
      <description>&lt;p&gt;The recent ransomware attacks have focused lots of minds onto cyber security, however many of the solutions being proposed are little more than sticking plasters to the larger underlying issue - namely systems are not secure by default. The &amp;rsquo;trend&amp;rsquo; in software has been to launch it, then fix it. This is a very attractive proposition for business, as it lets them discover the ideas that work and don&amp;rsquo;t work, and then iteratively improve them. Most of the gadgets we use in our lives today would not exist without this mentality. However the dark side of this approach is almost all software is not secure, the evidence is pretty much every system deployed has security flaws, the only question is who finds them first - bad people or good people.&lt;/p&gt;</description>
    </item>
    <item>
      <title>WannaCrypt was it good for the security industry?</title>
      <link>https://gidley.co.uk/post/wanntcrypto-was-it-good/</link>
      <pubDate>Mon, 15 May 2017 07:57:09 +0100</pubDate>
      <guid>https://gidley.co.uk/post/wanntcrypto-was-it-good/</guid>
      <description>&lt;p&gt;This weekend we saw &lt;a href=&#34;https://www.washingtonpost.com/business/economy/more-than-150-countries-affected-by-massive-cyberattack-europol-says/2017/05/14/5091465e-3899-11e7-9e48-c4f199710b69_story.html&#34;&gt;&amp;rsquo;the biggest cyber attack ever&amp;rsquo;&lt;/a&gt; and a few people (who don&amp;rsquo;t work in IT) have asked me - will it be good for you (as I work for &lt;a href=&#34;http://irdeto.com&#34;&gt;Irdeto&lt;/a&gt; - a Digital Platform Security company). It&amp;rsquo;s an interesting question to consider - these big attacks make a lot of noise, so you&amp;rsquo;d expect on Monday morning the business of cyber security will get easier! However I think the reality is a bit more nuanced.&lt;/p&gt;</description>
    </item>
    <item>
      <title>wanntcryptor 2.0 ransomware and negligence</title>
      <link>https://gidley.co.uk/post/wanntcryptor-2.0-ransomware/</link>
      <pubDate>Sat, 13 May 2017 06:47:04 +0100</pubDate>
      <guid>https://gidley.co.uk/post/wanntcryptor-2.0-ransomware/</guid>
      <description>&lt;p&gt;Yesterday the news rapidly filled up with reports on a &amp;lsquo;massive cyberattack&amp;rsquo;, as I&amp;rsquo;m in the UK the press coverage was focused on the &lt;a href=&#34;https://www.theguardian.com/society/2017/may/12/hospitals-across-england-hit-by-large-scale-cyber-attack&#34;&gt;NHS&lt;/a&gt; and initially was full of comments about &amp;lsquo;smart&amp;rsquo; hackers. This reporting is, in my opinion, giving these organizations an excuse for their &lt;strong&gt;negligence&lt;/strong&gt;. The reporting often implies the attack is some kind of &amp;lsquo;act of god&amp;rsquo; that they could not avoid, in this case it was trivial to avoid it, simply don&amp;rsquo;t connect out of date systems to the internet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Are you feeling lucky?</title>
      <link>https://gidley.co.uk/post/luck/</link>
      <pubDate>Sat, 08 Apr 2017 09:48:23 +0100</pubDate>
      <guid>https://gidley.co.uk/post/luck/</guid>
      <description>&lt;p&gt;How lucky do you feel today? It&amp;rsquo;s an important question as your IT security is probably mostly down to luck.&lt;/p&gt;&#xA;&lt;p&gt;If we examine most &amp;lsquo;hacks&amp;rsquo; we usually see the organisation hit issuing statements about &amp;lsquo;sophisticated hackers&amp;rsquo; and the public image of hackers, as lone genius&amp;rsquo;s wearing hoodies in darkend rooms is re-enforced. In fact most attacks are perpetrated by far less skilled people and succeed by luck. That&amp;rsquo;s not to say there aren&amp;rsquo;t some super skilled experts out there, but they are few and far between.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Computers are complex, so is protecting them</title>
      <link>https://gidley.co.uk/post/computers-are-complex/</link>
      <pubDate>Sat, 28 Jan 2017 17:00:36 +0000</pubDate>
      <guid>https://gidley.co.uk/post/computers-are-complex/</guid>
      <description>&lt;p&gt;Computer systems are complex, and the complexity has been at the point for quite a few years now it&amp;rsquo;s impossible for any one person to understand &amp;rsquo;everything&amp;rsquo; about any given system. There will often be people with a good understanding the &amp;lsquo;building blocks&amp;rsquo; but it&amp;rsquo;s pretty much impossible to understand all the detail of the code, libaries and platforms it depends on.&lt;/p&gt;&#xA;&lt;p&gt;Complexity has massive implications for the security of computer systems. If no-one understands a system how can you have any surity that it&amp;rsquo;s secure? The developers of the system will have tried to design for &amp;lsquo;known&amp;rsquo; security issues, and tried to assemble the &amp;lsquo;building blocks&amp;rsquo; in such a way they are secure but as they aren&amp;rsquo;t full understood it&amp;rsquo;s highly likely there will be some issues. This is not just an academic claim - if we simply look at the &amp;lsquo;security patchs&amp;rsquo; for major building block components like Java, .NET, Windows, Linux - all of which have regular security issues that could compromize any systems built on them. On top of the building blocks, even in a mid size dev team, you will have a mixture of skills and abilities in the team and even with &amp;lsquo;2 person reviews&amp;rsquo; security bugs do get through. Add in that many systems depend on services supplied by other companies - things like SaaS, hosting, ISP&amp;rsquo;s, Certificate Authorities and DNS - any or all of which are critical for security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Certs again</title>
      <link>https://gidley.co.uk/post/certs-again/</link>
      <pubDate>Sat, 21 Jan 2017 07:28:48 +0000</pubDate>
      <guid>https://gidley.co.uk/post/certs-again/</guid>
      <description>&lt;p&gt;Once again a major CA (Symantec) has been &amp;lsquo;caught&amp;rsquo; issuing certificates improperly. There is a great write up on &lt;a href=&#34;http://arstechnica.com/security/2017/01/already-on-probation-symantec-issues-more-illegit-https-certificates/&#34;&gt;Ars Technica&lt;/a&gt;. This is really significant as falsly issued CA certificates are one (of many) way to &lt;a href=&#34;https://gidley.co.uk/post/mitm/&#34;&gt;MITM&lt;/a&gt; SSL.&lt;/p&gt;&#xA;&lt;p&gt;This underlies the extreme difficulty in securing anything in IT. There are simply too many &amp;lsquo;moving parts&amp;rsquo; and people in involved in securing anything. Your computers security depends on thousands of people and companies all doing everything correctly all of the time, and simple law of averages suggests this is unlikely to ever happen!&lt;/p&gt;</description>
    </item>
    <item>
      <title>N26</title>
      <link>https://gidley.co.uk/post/n26/</link>
      <pubDate>Wed, 04 Jan 2017 08:40:24 +0000</pubDate>
      <guid>https://gidley.co.uk/post/n26/</guid>
      <description>&lt;p&gt;There is a really good talk about some vulnerabilities found in the &lt;a href=&#34;https://n26.com/eu/&#34;&gt;N26&lt;/a&gt; banking app presented at the CCC congress this year.&lt;/p&gt;&#xA;&lt;p&gt;&amp;lt;amp-iframe  width=&amp;ldquo;1024&amp;rdquo; height=&amp;ldquo;360&amp;rdquo; sandbox=&amp;ldquo;allow-scripts allow-popups&amp;rdquo; layout=&amp;ldquo;responsive&amp;rdquo;&#xA;frameborder=&amp;ldquo;0&amp;quot;src=&amp;ldquo;&lt;a href=&#34;https://media.ccc.de/v/33c3-7969-shut_up_and_take_my_money/oembed%22&#34;&gt;https://media.ccc.de/v/33c3-7969-shut_up_and_take_my_money/oembed&#34;&lt;/a&gt; allowfullscreen&amp;gt;&#xA;&lt;amp-img layout=&#34;flex-item&#34; width=&#34;817&#34; height=&#34;460&#34;&#xA;src=&#34;https://static.media.ccc.de/media/congress/2016/7969-hd_preview.jpg&#34;&#xA;placeholder&gt;&lt;/amp-img&gt;&#xA;&lt;/amp-iframe&gt;&lt;/p&gt;&#xA;&lt;p&gt;The talk is worth a watch but it does highlight some key points&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;No Certificate Pinning was being used that made it easy for the research to &lt;a href=&#34;https://gidley.co.uk/post/mitm/&#34;&gt;MITM&lt;/a&gt; the app&#xA;&lt;ul&gt;&#xA;&lt;li&gt;that&amp;rsquo;s not to say Cert Pinning fixes all issues but doing it makes things a lot harder for attackers.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;The API&amp;rsquo;s exposed to the web were far too verbose and didn&amp;rsquo;t really care about who was calling them&#xA;&lt;ul&gt;&#xA;&lt;li&gt;I think (shameless plug) that Application Hardening techniques for both web and mobile are going to be needed to secure these things long term. You need to ensure the code calling your API is what you think it is. This is where products like &lt;a href=&#34;http://irdeto.com/documents/Collateral/uc_cloakedjs_for_api_protection_en.pdf&#34;&gt;Irdeto&amp;rsquo;s Cloakware API Protection&lt;/a&gt; come in.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;A lot of the exploit relied on coding/logic errors - but they were quite easy to exploit&#xA;&lt;ul&gt;&#xA;&lt;li&gt;API Protection techniques will mitigate when the (inevitable) mistakes in logic occur in your code and make it much harder to exploit&lt;/li&gt;&#xA;&lt;li&gt;That&amp;rsquo;s not to say you shouldn&amp;rsquo;t also work on fixing the logic!&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;A number of the exploits relied on the engineers assuming ID were secret that were not (the &amp;lsquo;mastercard ID&amp;rsquo; in this case)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;This kind of assumption is quite common - if you think something is secret you should not just document it, but you need to have tests scanning logs/apis looking for that data occuring to ensure it&amp;rsquo;s actually still secret.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;A good breach response helps you manage PR&#xA;&lt;ul&gt;&#xA;&lt;li&gt;This was a pretty bad breach for N26 - but they handled it well. In particular they engaged with the researcher constructively and they fixed the issues in a reasonable time period.&lt;/li&gt;&#xA;&lt;li&gt;Many companies either ignore the issue or head straight for legal threats in these cases, this is a mistake as doing so will increase likelihood of it being publicised before you have fixed it.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;I suggest watching the whole talk - it&amp;rsquo;s well presented and shows a great real world example of how &lt;a href=&#34;https://gidley.co.uk/post/mitm/&#34;&gt;MITM&lt;/a&gt; can ruin your day as a bank or fintech.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Kaspersky</title>
      <link>https://gidley.co.uk/post/kaspersky/</link>
      <pubDate>Wed, 04 Jan 2017 07:22:44 +0000</pubDate>
      <guid>https://gidley.co.uk/post/kaspersky/</guid>
      <description>&lt;p&gt;Ouch - &lt;a href=&#34;https://www.kaspersky.com&#34;&gt;Kaspersky&lt;/a&gt; have been enabling MITM attacks on their customer base. &lt;a href=&#34;http://www.theregister.co.uk/2017/01/04/kaspersky_fixing_serious_certificate_slip/&#34;&gt;The Register&lt;/a&gt; citig a Chrome &lt;a href=&#34;https://bugs.chromium.org/p/project-zero/issues/detail?id=978&#34;&gt;bug report&lt;/a&gt; explains how you can use this to trick consumers in thinking a site is valid/safe when it is not.&lt;/p&gt;&#xA;&lt;p&gt;This underlines the ease of MITM SSL/TLS - see my &lt;a href=&#34;https://gidley.co.uk/post/mitm/&#34;&gt;previous article&lt;/a&gt; for all the different ways this can be done!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Human Momentum</title>
      <link>https://gidley.co.uk/post/human-momentum/</link>
      <pubDate>Mon, 28 Nov 2016 16:23:24 -0800</pubDate>
      <guid>https://gidley.co.uk/post/human-momentum/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve been travelling quite a bit recently for work and have been reminded (again) how &amp;lsquo;human factors&amp;rsquo; can defeat any attempt to improve security.&lt;/p&gt;&#xA;&lt;p&gt;A good example of this is chip and pin/contactless. Chip and Pin is common and popular in Europe and as a result in Europe I never &amp;lsquo;give&amp;rsquo; my card to members of staff for them to process it. This reduces the risk of fraud substantially as staff cannot easily clone/copy cards when they&amp;rsquo;ve never handled them.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Man in the middle is easier than you think</title>
      <link>https://gidley.co.uk/post/mitm/</link>
      <pubDate>Fri, 18 Nov 2016 07:06:19 +0200</pubDate>
      <guid>https://gidley.co.uk/post/mitm/</guid>
      <description>&lt;p&gt;I&amp;rsquo;m often heard saying it&amp;rsquo;s quite easy to MITM HTTPS (also called SSL/TLS) and decided that maybe I should list all the methods I know of (there are quite a few).&lt;/p&gt;&#xA;&lt;p&gt;The attacker has many options to try and get in the middle between the user and web server/API&#xA;&lt;amp-img src=&#34;https://gidley.co.uk/images/mitm.jpeg&#34; alt=&#34;Mitm&#34; height=&#34;204&#34; width=&#34;584&#34; layout=&#34;responsive&#34;&gt;&lt;/amp-img&gt;&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#pure-technical-approaches&#34;&gt;Pure Technical Approaches&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#zero-day-vulnerabilities-in-browsers&#34;&gt;Zero Day Vulnerabilities in browsers&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#tls-ssl-breaks&#34;&gt;TLS/SSL Breaks&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#incorrectly-issued-trusted-certificate&#34;&gt;Incorrectly Issued Trusted Certificate&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#aquire-vendor-issued-trusted-certificate&#34;&gt;Aquire vendor issued &amp;rsquo;trusted&amp;rsquo; certificate&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#social-engineering-approaches&#34;&gt;Social Engineering Approaches&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#convince-user-to-install-mitm-certificate&#34;&gt;Convince user to install MITM certificate&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#convince-user-to-install-software&#34;&gt;Convince user to install software&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#malicious-browser-extensions&#34;&gt;Malicious Browser Extensions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gidley.co.uk/post/mitm/#conclusion&#34;&gt;Conclusion&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;pure-technical-approaches&#34;&gt;Pure Technical Approaches&lt;/h1&gt;&#xA;&lt;p&gt;The pure technical approaches rely on attacks that don&amp;rsquo;t require users to make any mistakes and anyone can be vulnerable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>mitm key</title>
      <link>https://gidley.co.uk/post/mitm-key/</link>
      <pubDate>Wed, 16 Nov 2016 18:51:25 +0200</pubDate>
      <guid>https://gidley.co.uk/post/mitm-key/</guid>
      <description>&lt;p&gt;To continue my MITM attacks theme - someone has just release a nice USB key that ransacks your PC - &lt;a href=&#34;http://arstechnica.com/security/2016/11/meet-poisontap-the-5-tool-that-ransacks-password-protected-computers/&#34;&gt;Ars Technica&lt;/a&gt; has a good write up.&lt;/p&gt;&#xA;&lt;p&gt;This kind of thing is very dangerous as it&amp;rsquo;s really easy to get people to put USB keys into computers! I&amp;rsquo;m currently writing a longer article on the (many) ways to MITM TLS to help explain how easy it is!&lt;/p&gt;</description>
    </item>
    <item>
      <title>malware and https</title>
      <link>https://gidley.co.uk/post/malware-and-https/</link>
      <pubDate>Fri, 11 Nov 2016 08:23:58 +0000</pubDate>
      <guid>https://gidley.co.uk/post/malware-and-https/</guid>
      <description>&lt;p&gt;I&amp;rsquo;m often heard worrying about the state of HTTPS and the ease to get users to do things that make it basically not function - but I&amp;rsquo;ll admit evidence of real world attacks is thin on the ground. There is a systematic reason for the lack of information - if a hacker uses a Man-In-The-Middle (MITM) technique to hack HTTPS there is very little evidence left and all thart will happen is the stolen data will turn up in a list at some point in the future. It&amp;rsquo;s nearly impossible to correlete the HTTPS hack and the stolen data - as it could have been stolen in dozens of places.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Booth eye tracking</title>
      <link>https://gidley.co.uk/post/booth-eye-tracking/</link>
      <pubDate>Wed, 26 Oct 2016 12:26:47 -0700</pubDate>
      <guid>https://gidley.co.uk/post/booth-eye-tracking/</guid>
      <description>&lt;p&gt;Recently I was at a Trade Show (Money 2020 in Las Vegas) and was wondering how effective the booth designs were at getting people&amp;rsquo;s attention. There seem to be a number of apporaches people try&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Big Pictures to grab attention&lt;/li&gt;&#xA;&lt;li&gt;Videos on loop explaining stuff&lt;/li&gt;&#xA;&lt;li&gt;&amp;lsquo;Gimmicks&amp;rsquo; on the stand&lt;/li&gt;&#xA;&lt;li&gt;Live Talks&lt;/li&gt;&#xA;&lt;li&gt;Text explaining products&lt;/li&gt;&#xA;&lt;li&gt;Slogans explaining mission&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;What&amp;rsquo;s not clear to me is which of these actually work. Annecdotially you can watch people go buy and see what they look at, and then observe who engages. But it struck me that it should be possible to do this more scientifically.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why is there such a thing as default passwords?</title>
      <link>https://gidley.co.uk/post/default-password/</link>
      <pubDate>Wed, 26 Oct 2016 05:59:58 -0700</pubDate>
      <guid>https://gidley.co.uk/post/default-password/</guid>
      <description>&lt;p&gt;Why in 2016 are people still shipping software and devices with default passwords? The recent &lt;a href=&#34;https://krebsonsecurity.com/2016/10/iot-device-maker-vows-product-recall-legal-action-against-western-accusers/&#34;&gt;IOT/Botnet that broke large chunks of the internet&lt;/a&gt; was entirely avoidable if the devices had been shipped without default passwords.&lt;/p&gt;&#xA;&lt;p&gt;This is perfectly within the capability of a device manufactuer - even British Telecom (who have many many issues) have been shipping their devices with randomized passwords printed on a sticker on the device for years. It&amp;rsquo;s not hard to do that! With software it&amp;rsquo;s even easier you just force the user to pick a password and don&amp;rsquo;t ship them with admin/password or whatever you&amp;rsquo;ve decided is good enough.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Google Pixel - Initial Review</title>
      <link>https://gidley.co.uk/post/google-pixel/</link>
      <pubDate>Fri, 21 Oct 2016 13:06:37 +0100</pubDate>
      <guid>https://gidley.co.uk/post/google-pixel/</guid>
      <description>&lt;p&gt;I ordered a Google Pixel when they were released as I needed a new personal Android phone and generally the Nexus line has been very good, so I thought I&amp;rsquo;d try the Pixel.&lt;/p&gt;&#xA;&lt;p&gt;Some initial comments&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;It looks nice, it compares well to my (work) iPhone 6 from a looks point of view&lt;/li&gt;&#xA;&lt;li&gt;The finger print reader is great, so far much more accurate and quick than my iphone one which seems to be getting slower and slower&lt;/li&gt;&#xA;&lt;li&gt;The USB cable &amp;lsquo;port your phone&amp;rsquo; thing didn&amp;rsquo;t work at all with my old Android Phone (A Moto X). Instead I had to do it via the cloud&lt;/li&gt;&#xA;&lt;li&gt;It&amp;rsquo;s really quick - both apps and data seem faster that my old phone. Data is a bit odd as am in same place with same signal, but it does seem faster (good job I have unlimited data)&lt;/li&gt;&#xA;&lt;li&gt;The camera is very good (as reported), it won&amp;rsquo;t be replacing my DSLR for &amp;lsquo;good&amp;rsquo; shots, but for quick shots it&amp;rsquo;s very good.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Overall it looks like a nice phone, I&amp;rsquo;ll have to use it for a few weeks to see how good it really is!&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Website</title>
      <link>https://gidley.co.uk/post/new-website/</link>
      <pubDate>Mon, 10 Oct 2016 13:56:57 +0100</pubDate>
      <guid>https://gidley.co.uk/post/new-website/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve decided to finally move this site off blogger. It wasn&amp;rsquo;t adding much value so I&amp;rsquo;ve gone old-skool back to static HTML using Hugo.&lt;/p&gt;&#xA;&lt;p&gt;The site is using a AMP based template so it should be super quick and responsive.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
