HN user

christiansmith

220 karma
Posts11
Comments63
View on HN

Harvard Library Innovation Lab | Senior Software Engineer - Full Stack | Remote (some US states) or hybrid | Full-Time | https://lil.law.harvard.edu/

The Harvard Library Innovation Lab is a software product studio and research lab embedded in the Harvard Law School Library, with a mission of bringing library principles to tech. We are currently working on projects including web archiving, remixable education resources, and AI as a new way of accessing knowledge. As a member of our engineering team, the Senior Software Engineer will work across our various tools, applications, and experiments. The ideal candidate will have experience building performant, testable, maintainable, and fault-tolerant products and tools at scale, for audiences both technical and non-technical.

You can apply here: https://lil.law.harvard.edu/jobs/#sse-fs. Please include a short cover letter explaining how your career trajectory and interests align with our work and mission.

Harvard eligibility is weird: we can hire hybrid near Cambridge, MA, or remote only if you live in the states of CA, CT, GA, IL, MA, MD, ME, NH, NJ, NY, RI, VA, VT and WA.

Harvard Library Innovation Lab | Senior Software Engineer - Full Stack | Remote (some US states) or hybrid | Full-Time | https://lil.law.harvard.edu/

The Harvard Library Innovation Lab is a software product studio and research lab embedded in the Harvard Law School Library, with a mission of bringing library principles to tech. We are currently working on projects including web archiving, remixable education resources, and AI as a new way of accessing knowledge. As a member of our engineering team, the Senior Software Engineer will work across our various tools, applications, and experiments. The ideal candidate will have experience building performant, testable, maintainable, and fault-tolerant products and tools at scale, for audiences both technical and non-technical.

You can apply here: https://lil.law.harvard.edu/jobs/#sse-fs. Please include a short cover letter explaining how your career trajectory and interests align with our work and mission.

Harvard eligibility is weird: we can hire hybrid near Cambridge, MA, or remote only if you live in the states of CA, CT, GA, IL, MA, MD, ME, NH, NJ, NY, RI, VA, VT and WA.

Lack of physical escape key with vi is not a problem for me. An old trick is to remap caps lock (never used) to Ctrl (constantly used), which is easier to reach from "asdfhjkl" hand positioning. Then Ctrl-C is mapped to escape, and I never have to reach up to the fn row from the home row. Makes working with vi a bit more seamless and this lack of fn row is a moot point. So maybe we have to change few key bindings for ancient but still useful software. Really not a deal killer.

Location: Oregon/South Dakota

Remote: Yes

Willing to relocate: No; willing to travel

Technologies: OpenID Connect, JWT, OAuth, SSO, LDAP, SAML, FIDO, RBAC, ABAC

Résumé/CV: https://www.linkedin.com/in/christianmsmith | https://github.com/christiansmith | https://github.com/anvilresearch

Email: smith@anvil.io

We've been working on identity and access management infrastructure software for a few years now. We're committed to keeping our projects free and open source (MIT), and we've been fortunate to sustain the effort by working for users that need specific features implemented or help with integration. Our primary project is an authorization server called Anvil Connect:

https://github.com/anvilresearch/connect

There's an explosion of change happening in this field right now, both from within and from new frontiers like IoT and blockchain. We have plans for things we'd like to build, and we're looking for forward thinking users that need them built.

Little late to the party but have you considered using something like an authorization server?

We created Anvil Connect (based on OAuth 2.0 and OpenID Connect) to solve a bundle of auth-related problems all at once. It's a separate server instead of a library, because once you need to share user accounts between several apps (think different platforms) the complexity increases dramatically. There are (third party) client libraries available for a number of languages.

https://github.com/anvilresearch/connect

In fact, unlike previous OpenID protocols, OpenID Connect is a profile of OAuth 2.0.

The conflation of authorization with authentication is an accident and a mistake. They are still quite separate concepts. Authentication is about verifying identity. Authorization is about privileges afforded a given identity. Access control models usually depend on some form of upstream authentication.

The third-party authorization flows provided by OAuth are not intended to establish or verify a user's identity. Their purpose is to extend a user's access to a third-party in a limited way without sharing passwords.

Social Sign-in is an accident of 3-Legged OAuth and its use for this purpose is considered a very weak form of authentication.

OpenID Connect takes the best ideas from preceding identity protocols and incorporates them into OAuth flows, giving the best of both worlds.

More information on all of the above here: https://github.com/christiansmith/anvil-connect/wiki/Referen...

Understood, and I'm glad to live and let live in general, but this one is too close in subject matter to my own work and may eventually lead to confusion about who's doing what. That seems like a reasonable cause for concern.

This is an interesting looking project, but I have to say I'm not crazy about the author's use of the name Anvil. I've owned the domain anvil.io going back several years, I've been actively using variations on the name Anvil for security related software that's in production for a period of time as well. If the authors of the project read this, please consider renaming it.

Why should we own cars?

In the city, I couldn't possibly agree with this more. When I lived in Boston I sold my car after the first two years because it was a ridiculous expense and hassle for the utility. Taking a cab a few times a week turned out to be cheaper than parking tickets alone.

Given a choice though, I much prefer to live in less densely populated areas (e.g., northwest Montana), and owning a vehicle is really unavoidable. In these places that also means a 4x4 SUV or truck, not a Prius, or else you'd be calling a tow truck every 5 minutes in the winter.

This Google Hangout starts in about 30 minutes:

"ICE Code Editor is the JavaScript 3D visualization programming environment used throughout the book 3D Game Programming for Kids. It's written with Dart, the language for scalable web app engineering from Google. In this hangout, prolific blogger, author, and coder Chris Strom takes us on a deep dive into the ICE source code."

Watch it live, join the hangout, or check it out later on Youtube.

This may not be any indication. A Firebase competitor named GoInstant was bought by Salesforce, used to build a few things internally at that company, and very recently shut down and the team integrated into the parent company. Any outsiders that built anything with GoInstant were basically out of luck. I have no idea how many users they had, and Firebase has greater visible traction, so that may factor in as well.

I didn't take it personally at all and if you have the time and inclination I'd love to hear more about your experiences. Please feel free to email me. smith at anvil dot io.

Before making suggestions like this and getting the HN bandwagon to support this POV, perhaps we should put ourselves in the startup's shoes?

As a founder, I am in a startup's shoes, and my intention was not to provoke an angry mob, but merely to state my own opinion. I don't want to use Firebase for anything my own revenue will depend on, and that's a shame, because they have made an awesome product.

Forcing an open source on acquisition severely limits your exit options and lowers your acquisition value.

These acquisitions of 3 year old companies are always sort of disappointing to me. On the one hand, I'm truly inspired and encouraged see their measure of success. On the other hand, I'd really like to see more startups committed to building lasting companies that strive for win-win outcomes that include users, employees, investors and founders. This isn't supposed to be a zero sum game.

As much as the users feel like startup founders owe them something, startup founders are human like everyone else. They don't exist to be our slaves.

With a company like Firebase, there's a chain of trust that's really important. They are not responsible for just their own individual users. They are responsible for other companies' users. The effects of everything they do are multiplied accordingly.

Part of offering a platform is the guarantee that "this thing you depend on to serve your users will not go away unexpectedly without leaving a viable alternative." That's not an unreasonable thing for someone to demand when they're building their house on your foundation. Their use of your service also represents an investment of their own developer time. You go away, they lose that investment. If you as the operator of a platform don't want to take on that level of responsibility, don't go into that business.

Imposing rules like this on companies would result in fewer tools and companies overall as the companies themselves would no longer make economic sense.

Who said anything about imposing rules? You're putting words in my mouth.

There's a trend to throw VC money at open source force multipliers: http://words.steveklabnik.com/is-npm-worth-26mm

This isn't perfect and it contradicts my point about wanting to see sustainable companies, but I find it encouraging nonetheless. I think Firebase could have easily fallen into this category.

Don't forget about persistence. Creating a horizontally scalable database isn't likely to be a trivial matter. Somehow I don't think Twitter Bootstrap is going to be much help there.

Firebase has solved many harder problems than you and I are ever likely to have to deal with and they deserve full credit for that.

I'd like to take that devil by the horns and strongly suggest that companies like Firebase, who clearly deliver a critical infrastructure dependency for anyone using their service, should open source their platform as an act of good faith toward their customers.

No one wants to run yet another cluster, but anyone with an eye to business continuity ought to want the assurance that they can migrate to and from their own servers if that need should arise.

That might not be in the short term interests of Firebase, but it's definitely in the long term interests of their customers. Why would anyone ever base the future of their own business on the exit needs of another company's investors? It is a ridiculous risk. As much as I love what Firebase has built, I'd never use it for anything more than a toy project for that exact reason.

Basho, ElasticSearch and Docker(?) seem to be on a good path with commercial open source models. Is there any reason that a startup like Firebase couldn't do both? Offer their open source product as a service with non-critical value adds? GitHub is another example that comes to mind. If they were to get bought and shut down, it would be a pain in the ass to set up new remotes, but no one would have to stop using git.

About a year ago some friends and I started meeting up monthly in a Google hangout to explore the internals of open source software we use everyday. Our motivations were simple: know our tools inside and out, learn from the works of better hackers than ourselves, and hopefully get a jumpstart on contributing to the repos we love.

At first we treated the hangouts like a study group, but the sessions quickly evolved into one person preparing in advance and guiding the rest of the group through what they had discovered. Then one day, the authors of PolymerJS showed up to take part as we were dissecting their code (thank you, Twitter!). Around the same time, we had been getting requests to record the sessions for folks who couldn't make it.

Eventually, we put two and two together and realized we ought to invite open source authors to read us their own works, broadcast live and recorded for posterity. What a great way to learn to write kick-ass code, pave the way for new contributors to a given project, and spread our enthusiasm for all things FOSS!

We're now promoting and archiving these hangouts at http://readthesource.io. Last week we had Scott Corgan guide us through Superstatic, the static file server behind Divshot.com. On October 16th at 12:30 Pacific, Chris Matthieu and the Octoblu team will give us an inside look at Meshblu, a machine-to-machine instant messaging network and API that powers the Internet of Things (formerly known as SkyNet.im).

We have a few more unannounced hangouts in the pipeline and we're actively looking for more guests. Our intention is to continue covering both popular projects and not-so-well-known, but uniquely interesting ones. In the mean time, we'd love to get your take on the general concept as well as our execution.

Thanks HN!

If Moniker's customer service is any indication of the way their operations are managed, this doesn't surprise me at all.

The company was an absolute nightmare to deal with when I was a customer. Three years in a row they caused me enormous grief just trying to renew a .io domain. For example, shutting it down and throwing away DNS records roughly two weeks before the actual expiration with no warning. Their communication about the special rules and requirements for .io was just horribly inconsistent. At one point I had to complain to BBB just to get a response. Took well over a week to get my email for that domain working again! And they held the fix hostage demanding a ridiculous amount of money to bother making it right.

Hopefully the new CEO has been able to get this kind of bs under control, but in the mean time I moved all my domains to namecheap.com and now gandi.net and it's been perfectly smooth sailing.

The entire history of the human species is an inspiration and motivation, depending on what you choose to read into it. We are practically an infinite collection of case studies in creativity, innovation, perseverance, adaptability, beating the odds... your question is actually very hard to answer because so many great examples come to mind.

As for reading, a few things popped into my head in no particular order:

The Greatest Salesman in the World, by Og Mandino

Emerson's Essays, particularly "Self Reliance"

Biographies of people like James Clerk Maxwell and Tesla

If, by Kipling

Any of Bucky Fuller's books

And really, just look around at what people are doing in our industry. Our peers are a constant source of inspiration. I see what some of my friends are doing the field of IoT and it makes me want to get up every day at 4am and hack until my fingers fall off.

I agree with your sentiment. As an industry we spend way too much time rediscovering principles that are well known to previous generations of programmers. That said, I'm grateful to see these ideas showing up where they're desperately needed.

Can't speak to your specific health issues, but moving to the mountains and getting a German Shepherd worked wonders for me in lowering stress, improving health and fitness, increasing my creative output and minimizing financial worries.

Living in the country is good for the mind, body, soul, and budget. Having a big dog that's with you all day long will improve your mood and motivate you to exercise (because you won't get a damn thing done with an energetic critter that needs attention). And while you're out walking, running or hiking with your new best friend (sans mobile device), you'll stimulate your creative faculties and solve problems you've been "stuck" on in your head.

Internet in Montana is nearly as good as any major city I've ever lived. Sometimes better. What else do you need in order to be productive?

For those that might pass by this link without clicking, it's worth noting that it's a paper by Sergey Brin and Larry Page titled "The Anatomy of a Large-Scale Hypertextual Web Search Engine."

Looks like a great read. Thanks for posting!

The Dropout Fallacy 12 years ago

You might be looking at it from the wrong angle. What if we're all intrinsically autodidacts and 12-16+ years of compulsory education successfully trains that quality out of most people?

It's probably not a coincidence that those willing to go against the grain with respect to education seem to be disproportionately represented among the successful entrepreneurial class.

This entire discussion reminds me of the "mappers" vs "packers" theory. It's a bit long winded but a good read:

http://the-programmers-stone.com/the-original-talks/day-1-th...

#24 caught my attention with the poem/song about the algorithm behind the Spanning Tree Protocol: https://www.youtube.com/watch?v=iE_AbM8ZykI

Somewhere in between music school and programming for a living, I had the superficially nonsensical epiphany that algorithms and data structures were essentially music... just another language for expressing ideas about combinations and time. It's interesting to see this other perspective... an algorithm expressed as a song for the purpose of clearly communicating how it works.

The interview with Radia Perlman is a good read too: http://www.theatlantic.com/technology/archive/2014/03/radia-...