HNHacker News
TopNewBestAskShowJobs

ttol

1,052 karma · joined April 29, 2007

Co-founder, LLM Shield, Digits, Crashlytics

Twitter: @Wayne Web: chang.com

submissionscomments
ttol··on Knowing When Your Baby is Ugly
I chase high-impact projects. They don't need to be lottery-style, but they do need to have degrees of widespread use. In this case, the market was premature. No matter how much "time, effort, and little patience" wasn't going to change the world overnight to use smart TV's! (Otherwise I would have stuck with it :)
ttol··on Knowing When Your Baby is Ugly
phew I thought I was going to get flamed for using Delphi!
ttol··on Knowing When Your Baby is Ugly
Chuck, thanks for the comments. At the time I was enthralled by the possibilities of the iPad and wanted to hack together something that was both useful for me and others. I intended it as a side project (instead of a full blown startup).

I don't regret doing it and I'm happy that I spent that month exploring (and brushing up on my Delphi skills!). I'm thinking about open sourcing the project but would need to clean it up some. It's all spaghetti right now.

Oh, and would love to get your feedback on my next project :-)

(And yea, that spam thing at the bottom is kinda lame)

ttol··on How I Discovered a Security Vulnerability in Twitter That Impacted 1.5M Users
Yea -- it's hard to find because the twitter.com/about/security page is about a week old. When google updates their indexes, it should be easier to find.
ttol··on How I Discovered a Security Vulnerability in Twitter That Impacted 1.5M Users
No, the security pages were put up after I talked to Bob. (Those are new pages and are about a week old. They were put up precisely because it wasn't easy for people to report security issues.). Also the headline wasn't written by me. Boston Innovation editors modified it. My original headline is on my website at waynechang.com. And yes, it was hard to get a hold of someone -- I spent two days. Emailing security@twitter.com was less obvious then, since emailing support@twitter.com sends back a form rejection letter (try it).
ttol··on How I Discovered a Security Vulnerability in Twitter That Impacted 1.5M Users
Former. Also App developers posting their API keys and Consumer Secret keys. So, theoretically, this would allow a malicious person to control all the authorized accounts with that app (and these were big name apps). Autotweeting, DMing, access private messages, etc.
ttol··on How I Discovered a Security Vulnerability in Twitter That Impacted 1.5M Users
Most were actually legit. I asked one of the support guys how he and his team handles the volume. He responded with his secret: http://twitter.com/#!/Charles/status/32971715290210304

"@Charles Your team does a great job. 100-200 tickets per hour. How do you do it?"

"@Wayne My secret is keyboard macros and Text Expander. Some days can be pretty overwhelming though!"

ttol··on How I Discovered a Security Vulnerability in Twitter That Impacted 1.5M Users
I asked the same thing but was told that Twitter couldn't disclose this to me because of their NDA and other confidentiality agreements. Who is actually at fault is unclear. I wasn't able to reproduce this on Groupon or Rackspace Cloud's Zendesk though, but that doesn't say anything definitive.
ttol··on How I Discovered a Security Vulnerability in Twitter That Impacted 1.5M Users
These were users. I wrote 1-1.5 to set a wide range in case for duplicates, but I rarely saw any. From my observation, the number is closer to 1.5 million than 1 million (and growing by 100-200 per hour).
ttol··on How I Discovered a Security Vulnerability in Twitter
Yea, it's crazy that twitter actually has staff to respond to all support tickets. 100-200 per hour gets submitted.
ttol··on How I Discovered a Security Vulnerability in Twitter
Once I got a hold of someone at Twitter, it was very easy to work with them to solve this issue. +1 for twitter staff
ttol··on LivingSocial: We're set to overtake Groupon
"We think it might have actually been the largest single day sales of a product in the history of the Web." - LivingSocial CEO on the Amazon Gift Card deal
ttol··on (Literally) Drawing the HTML 5 Logo in Canvas with Javascript
Increasing the sloppiness makes this way cooler. +1
ttol··on Ask HN: Review RentPost.com
Found it confusing too. Easy fix would be to add a new row in the table with the numbers so it appears in both the table and the graphic.
ttol··on Hacking side projects: Napkin to $1000 per day
This blog post would be a very poor and inefficient page view generator -- putting up pictures of cats would be a lot easier than writing and documenting my side project! :-) I just wanted to share the process I went through; I hope it helps some people.
ttol··on Hacking side projects: Napkin to $1000 per day
Thanks for reading. The product I chose is not all that important to the article. I believe the value lies in the process related to executing around it, and wanted to share with others.
ttol··on OnSwipe Raises, Like, A Million Dollars
Congrats jason! I Believe.
ttol··on Man Sued Winklevoss Twins in 2009, Saying They Stole Company Stake From Him
Why am I getting downvoted?
ttol··on Man Sued Winklevoss Twins in 2009, Saying They Stole Company Stake From Him
Very thorough research. -Wayne Chang
ttol··on What kind of traffic is driven by a single mention of a domain on network TV?
That's amazing data. I'm writing this comment so I can effectively bookmark this in my profile and reference it again at some later point in time. Thanks for sharing!
ttol··on How Startups Can Use Patron's Formula for Building a Successful Online Community
That sounds really interesting. Are there photos/videos of this somewhere?
ttol··on How Startups Can Use Patron's Formula for Building a Successful Online Community
Thanks Kleinman. I don't have any relationship with Patron (except on some Saturday nights ;-), but I wanted to share my thoughts on their initiatives.

They put on a damn good event, and they're generating buzz about it -- which results in more people signing up on their site.

ttol··on How Startups Can Use Patron's Formula for Building a Successful Online Community
What you just said is 100% true for the diamond industry. Their slogan "A Diamond is Forever" is created because there is very little resale value in a diamond, so they want/need their customers to keep them.

DeBeers has giant warehouses full of diamonds and trickle releases them over time.

ttol··on How Startups Can Use Patron's Formula for Building a Successful Online Community
There was a lot of staff on hand so I'm sure if someone got rowdy... "man overboard!". In all seriousness, we got lucky -- everyone enjoyed the event. Food was amazing delicious. I wish they put the recipes online for the food instead of just the cocktail ones..
ttol··on Seaswarm: we can clean up the Gulf in a month
This is still very much untested. From the project website http://senseable.mit.edu/seaswarm/ss_prototype.html

"The first Seaswarm prototype was tested in the Charles River in mid-August 2010. The vehicle’s flexible conveyor belt easily adapted to surface waves and succesfully propelled itself through the water. Stay tuned for future prototype updates."

ttol··on Hey, Guys, It's Totally Okay If You Don't Get Rich
An interesting article that talks about an entire nation's views on marriage, status, and success is: http://www.chinadaily.com.cn/life/2010-06/25/content_1001855...

It is so ingrained that one of the women described her marital vision: "I'd rather be miserable sitting in a BMW than be happy riding a bicycle."

It's no surprise that an extension of this is that the most desirable man, and bachelor, in China is the founder of Baidu, the largest search engine in China, due to his wealth.

ttol··on Jailbreak for ios 4.0 and iphone4 just released
That doesn't answer parent poster's question.

iPhone 4 unlock will come in next 24 hours. It's in last round of testing. You can use ultrasn0w 0.93 to unlock 3GS or 3G right now though.

ttol··on Jailbreak for ios 4.0 and iphone4 just released
The installer works by exploiting a bug in the way Safari handles PDF files.

A couple years ago, jailbreakme.com was also live but used a TIFF exploit.

If you want to see the actual exploit files, go to: http://jailbreakme.modmyi.com/_/ and you will see a list of PDF files by device and OS version.

ttol··on Jailbreak for ios 4.0 and iphone4 just released
People on twitter are saying if you jailbreak from jailbreakme.com, and then do a full restore, you will get FaceTime/MMS functionality back. Unconfirmed
ttol··on Jailbreak for ios 4.0 and iphone4 just released
confirmed. wonder what else is broken.
← PreviousPage 2 of 5Next →