Google Play Won't Accept PayPal


Hey kids! Did you know that the best way to report bugs to Google is via passive-aggressive blog posts? Yup, s'true. They don't offer support for any of their products*, so your only hope is getting your complaint to the top of Reddit / HackerNews / Cool Site of the Day and hoping that particular Google Product Manager is taking note. So - here's my rant :-) Google now let you pay for apps and games using PayPal. Well, I've got a bunch of credit left over in an old PayPal account, so I…

Continue reading →

ASCII Art in QR Codes


There are plenty of QR generators which will render the code in ASCII, but I wanted to try something a little different. Is it possible to hide ASCII Art into QR Codes? Errr.... yes... It's pretty damn simple! I was surprised I couldn't find anyone else doing this. (_/) (='.'=) (")_(") Becomes: Which, when scanned, renders as: Now, there are limits as to what you can put into a QR code - about 4,000 characters. Different devices have different screen widths, which limits the…

Continue reading →

Putting UK Flooding Alerts Onto Twitter #UKBLC14


As part of BlueLightCamp '14, a group of civil servants, hackers, and emergency service workers got together for a weekend of furious creation. I decided to look at flooding data. The recent floods in the UK are a brutal remember of the realities of climate change and our poor stewardship of the nation's waterways. The UK Government has a large collection of Flooding Data online - including some very detailed river-by-river data. Initially, we thought it would be a great idea if every river …

Continue reading →

Cosmetic Changes to the Microsoft 4000 Keyboard


I've written before about my love for the MS 4000 Ergonomic Keyboard. It's the only keyboard I'm comfortable typing on for extended periods of time. Sadly, one of mine has started to get a bit old and frail - the letters are rubbing off and the keys are getting a bit spongy - so I sprang for a new one. On getting the new one out of its box, I couldn't help but notice that it had undergone some fairly substantial cosmetic changes. All the keys are in the same position, and the functionality…

Continue reading →

Review - Wooden Phone Case for Galaxy Note 3


VWTech Co Ltd are yet another company out of Shenzen, China, selling weird and wonderful gadgets at knockdown prices. I decided to treat myself to one of their "Unique Real Handmade Natural Wood Wooden Hard Bamboo Shockproof Case For Samsung Galaxy Note 3" It promised to be a laser-cut and engraved, bamboo case for my Note 3. For £10, I thought it was worth a punt. After waiting a week for delivery, it arrived smothered in bubble wrap and looking gorgeous! The case comes in two halves - …

Continue reading →

Minor Privacy Flaw in iTunes API (Disclosed)


A (very minor) privacy issue I found with the iTunes API - disclosed on 7th April. Apple provide an API to allow users to search the iTunes store. Let's suppose that a user wishes to search for Music Videos from The Beatles. The search itself is performed over HTTPS. https://itunes.apple.com/search?entity=musicVideo&term=beatles This means that anyone sniffing the connection won't see what the user searched for - nor will they see the response from Apple. The only fly in the ointment is…

Continue reading →

Hack Da Police (and other emergency services) #UKBLC14


Big banner for Blue Light Camp 2014.

This is a necropost - resurrected from the now defunct blog of a previous employer. I've just come back from an amazing BlueLightCamp 2014 - held in the splendid offices of the Ordnance Survey. Themed unconferences are nothing new - but I think this was one of the first that I've been to focussed on such a vital topic - the Emergency Services. You can read a full write up of all the sessions on the official blog, or you can read Ben Proctor's take on the day. Here are my scattered thoughts, …

Continue reading →

XSS at Food.gov.uk - disclosed and fixed


A few months ago, I was attending the National Hack The Government event. I was showing off some of the work I had been doing on "The Unsecured State" - looking at *.gov.uk website security. I was chatting to an envoy from the Food Standards Agency who was eager to hear more about what I'd discovered. "Oh," I said, "It's pretty easy. Let's take a look at your website. If I were to type some HTML into your search box, you would expect that the site would recognise it as dangerous content…

Continue reading →