This makes me wish there was a <love> button on HN. I have shared your request with Les.
HN user
chunsaker
I run marketing and BD at Stormpath. Github, Twitter, Linkedin: all @chunsaker.
While we are not porting the SDKs, we are targeting end of April for framework integrations, so most Stormpath users can migrate with a pretty simple version upgrade. Most users are working with these and not our base SDKs. We are prioritizing: Java Spring Java Spring Boot Node Express ASP.NET 4.x ASP.NET Core
One question: How are you securing the Oauth connection? Oauth2 is nervous-making.
Ok, one more question: If I deprovision someone in GApps, will they automatically deprovision elsewhere? Vice versa? Where's the source of truth?
One thing missing here: Ask the "target" person before lobbing an introduction into their inbox.
Intros aren't always welcome - the target could be busy, traveling or have a conflict of interest. They may not be in a position to give that person time, however helpful they would like to be. When the supplier assumes the introduction is okay, they can put both sides of the intro in a tough spot.
Thanks! The website is shiny new, and I added this to our list of bugs to squash. Any and all bugs/suggestions welcome --> claire@stormpath.com
Yes, my read was that its a joke.
The tone of this post is yet another reason to love team Watsi. Really fun for an early stage company (for-profit or non) to be spending time and money on this instead of on more interesting things like building their business.
The upshot for us is that we can let customers know not just that we're having an issue, but also details about the issue that might impact the service. As a SaaS API, its important that we give good transparency into even minor blips in the service. Statuspage.io isn't as customizable as I would like it to be, but it makes it really easy for someone not on the dev team to manage communication while others fix the problem. Also, its hella straightforward to set up and use. http://status.stormpath.com/
I agree with the direction of the industry, and your abbreviated rant, except I think they are trying to get attention with... anything at their disposal.
For me what is interesting is how magnetically opposed developers can be to a perceived outsider. And how that works against the recruiter, etc. in question. E.g. We're really lucky with our outside recruiter and she has a lot of credibility, but when she hung out at our booth at OSCON with her lovely female assistant, they clearly stood out and attendees cut a wide swath. Same thing at a different con with one of our investors: extremely technical guy, but you can spot his BD/VC uniform from across the room. I shuffle their conversations away from my booth.
Conversely, I had an interesting conversation in a booth at a different con, where after 20 minutes of talking to me (messy ponytail, company tshirt, jeans, tigers) about our stack, a guy said to me, "Wait a sec, you smell like marketing." By which he meant that I was coming across as non-technical as we got deeper into the technical details (totally fair - I am not a professional developer). I think he felt bamboozled by my lack of shininess.
The shiny girl probably like being shiny, and don't care for the tshirt/jeans/ponytail uniform. There's actually a lot of cool ways technical women subvert the uniform without freaking anyone out (I have hot pink lipstick). I would venture they feel uncomfortable about standing out more than they are plotting to lure you.
David - you are one of my favorites, but what does Recruiters being pretty have to do with finding/not finding a good one? This is a great article, but is there a tie-in I'm missing here?
I wish I could double-upvote this post. There are a lot of resonant topics for women in technology.
I applaud you, sir. And your website, which is very elegant.
This is an awesome improvement. I agree with BPatrianakos that hashing has not been easy enough for the average PHP dev - we hear that a lot.
As another option, you can also just not build any password infrastructure. We do all the hashing and authorization as a secure service and there are PHP devs of all levels using it... http://www.stormpath.com/docs/php/quickstart
HN isn't in German. Not everyone works/learns/wants to spend all day in English
I received and posted the email, and many others on twitter have also received it.
Also, not sure we should take blog comments for the gospel before all the facts are out.
I think you're right on both these points - your point about commitment is our CEO's lead hypothesis, which I definitely did not capture as articulately as this.
Good question. The manual login ensures that a session is started with the correct authentication credentials. Its a good default way to protect against session hijacking attacks.
I suspect we will automate the first authentication down the road, but with such a small drop-off in the new workflow, we're focusing on more core product features first. There's still lots in the new workflow, website, etc. to improve.
That's a good suggestion - will see if we can add a para about it. We use digest authentication, fwiw.
I'm particularly glad you highlighted that marketers often underestimate how social developers are. Analogous: tech marketers and BD people often overlook the fact that developers do a lot of business and share knowledge in social settings...just like people in every other industry. I think its important we get away from dumb tchotkes and focus on meaningful conversations.
Re the marketing systems - I think its less about marketers using the right system, and more about using those systems correctly. There are at least a dozen email automation platforms that can delivery responsive messaging, and most companies of any size have one in place. Speaking from experience, they are just a massive beast to manage - the more complicated and responsive your email set up, the more complicated and time-consuming it is to manage (and more likely you are to accidentally spam everyone). Marketing teams have the right systems, they just don't invest the time to do it right.
Switched from Dropbox to Google Drive a few months ago. the UIs are very similar, and Drive is much cheaper. My only complaint has been syncing:
1) After a week of repeated attempts, I gave up trying to get video from Dropbox to Drive. Maybe the files were too large?
2) Also, syncs are faster and more seamless across devices with Dropbox. There are noticeable lags for most syncs with Drive, even small, single files.
3) Event when Drive thinks it has synced, it hasn't and I have to restart the app.
There are other benefits to Drive, but I never had any sync issues with Dropbox.
Helpful!
I know this is a serious issue re the problems with inflated and systemic agricultural bureaucracy per the thoughtful comments below...but: raisins.org.
Amazeballs as government URLs go.
Stormpath (http://www.stormpath.com) * We have roles open for core Java engineers, a Data Guru and a Developer Evangelist (Python, Ruby, PHP, Haskell...)
Stormpath is the first easy and secure user management and authentication service for developers. Fast and intuitive to use, it offers an easy API, open source SDKs, and an active community.By offloading user management and authentication to Stormpath, developers can bring new applications to market faster, reduce development and operations costs, and protect their users with best-in-class security.
We're well-funded, friendly and located in gorgeous downtown San Mateo near the Caltrain. Drop us a note if you think what APIs - even if there isn't a job listed that fits your bill. Jobs@stormpath.com
Please tell me this is an April Fools article. Please.
Redwood City FTW? We've had two of our interns find good housing there, near the Caltrain.
...Dramatically.
Stormpath (San Mateo, CA)
Stormpath is an easy, secure user management and authentication service for developers. We're looking for - Core Java developers - Front-end engineers - DevOps - Developer Advocates
It's a bonus if you love security, if password breaches make you angry, and if want to help developers get busy with API-based architecture. The team is smart, fun and friendly, and we've got some great announcements coming up.
Check out the jobs page at http://www.stormpath.com/ or email your jobs@stormpath.com
This is a great synopsis. There are so many examples of how companies have handles sexist snafus well, compounding the gaffe like this is inexcusable.
Way to go, Chase and team. This has tremendous vision and I hope you come out of YC with a ton of velocity.
Profile updated. Thanks, didn't mean to be disingenuous. Its okay to call me tacky - I actually think this stuff matters.
Yes, it certainly mitigates the scale of a potential breach and I like that the reduced scale/potential value makes it a less attractive target to hackers (assuming the server side is also built in a secure way). I havent investigated, but it makes me nervous to think that if my phone is stolen, the thief gets my data too.