HN user

chunsaker

276 karma

I run marketing and BD at Stormpath. Github, Twitter, Linkedin: all @chunsaker.

Posts35
Comments38
View on HN
stormpath.com 11y ago

Show HN: Five-minute Authentication with Lumen

chunsaker
4pts0
stormpath.com 11y ago

The Ultimate Guide to Mobile API Security

chunsaker
1pts0
stormpath.com 11y ago

Build a Node API Client: Queries, Caching and Authentication

chunsaker
1pts0
stormpath.com 11y ago

Single Sign-On vs. Centralized Authentication

chunsaker
2pts0
stormpath.com 12y ago

Cloud-Mirrored Active Directory with Stormpath Now Live

chunsaker
1pts0
www.bitbanter.com 12y ago

Bankrupt Mt. Gox Reveals Location of Lost Private Keys

chunsaker
4pts5
planetcassandra.org 12y ago

Stormpath Pumps 50,000 Accounts in Under 200ms into Cassandra

chunsaker
5pts0
support.zendesk.com 12y ago

Zendesk beefs up password and device security

chunsaker
1pts0
stormpath.com 13y ago

Don’t Pull a Farmville: Social Login Best Practices

chunsaker
4pts0
www.stormpath.com 13y ago

Linking and Resource Expansion: REST API Tips

chunsaker
9pts0
www.stormpath.com 13y ago

Stormpath Community Roundup: Python Login Guide and CAS Integration

chunsaker
4pts0
www.emedia.com 13y ago

Trends in Tech Collateral: Survey Results

chunsaker
1pts0
www.stormpath.com 13y ago

Reputation.com Loses User Passwords, Emails, and Addresses

chunsaker
63pts37
www.stormpath.com 13y ago

To PUT or POST?

chunsaker
5pts0
www.stormpath.com 13y ago

How We Increased New User Registration 27%

chunsaker
14pts5
www.stormpath.com 13y ago

Secure Your REST API

chunsaker
115pts74
www.deviousfox.com 13y ago

Adventures in Caffeine Addiction

chunsaker
1pts0
blog.programmableweb.com 13y ago

Stormpath Identity API Solves Security Problem With Sleek Answer, Gets Fat Check

chunsaker
1pts0
www.stormpath.com 13y ago

Long Live The Password

chunsaker
4pts0
www.deviousfox.com 13y ago

Startup Lessons from Kickboxing Class

chunsaker
1pts0
www.stormpath.com 13y ago

Password Breach? That'll Be $172,000,000 Please

chunsaker
30pts19
www.cnbc.com 13y ago

How Lack of Immigration Reform Harms Startups, US Economy

chunsaker
3pts0
www.stormpath.com 13y ago

Password Security The Right Way

chunsaker
40pts47
www.stormpath.com 13y ago

Five Steps to Password Security - Developer Best Practices

chunsaker
1pts1
www.stormpath.com 13y ago

Stormpath Launches PHP Support for User Management

chunsaker
1pts0
www.stormpath.com 13y ago

Stormpath Named "Hot Cloud Company" by NetworkWorld

chunsaker
1pts0
github.com 13y ago

ShowHN: Stormpath Releases SDK to Power User Security in Ruby

chunsaker
2pts0
www.stormpath.com 13y ago

Stormpath IAM and Apache Shiro Java Security Integration

chunsaker
2pts0
github.com 13y ago

BeanPole, A Java library that simplifies app deployment on Elastic Beanstalk

chunsaker
1pts0
www.stormpath.com 14y ago

Yahoo Hacked; How to Secure Passwords from SQL Injections

chunsaker
2pts0

While we are not porting the SDKs, we are targeting end of April for framework integrations, so most Stormpath users can migrate with a pretty simple version upgrade. Most users are working with these and not our base SDKs. We are prioritizing: Java Spring Java Spring Boot Node Express ASP.NET 4.x ASP.NET Core

Intro Etiquette 12 years ago

One thing missing here: Ask the "target" person before lobbing an introduction into their inbox.

Intros aren't always welcome - the target could be busy, traveling or have a conflict of interest. They may not be in a position to give that person time, however helpful they would like to be. When the supplier assumes the introduction is okay, they can put both sides of the intro in a tough spot.

Thanks! The website is shiny new, and I added this to our list of bugs to squash. Any and all bugs/suggestions welcome --> claire@stormpath.com

An Early Retirement 12 years ago

The tone of this post is yet another reason to love team Watsi. Really fun for an early stage company (for-profit or non) to be spending time and money on this instead of on more interesting things like building their business.

The upshot for us is that we can let customers know not just that we're having an issue, but also details about the issue that might impact the service. As a SaaS API, its important that we give good transparency into even minor blips in the service. Statuspage.io isn't as customizable as I would like it to be, but it makes it really easy for someone not on the dev team to manage communication while others fix the problem. Also, its hella straightforward to set up and use. http://status.stormpath.com/

I agree with the direction of the industry, and your abbreviated rant, except I think they are trying to get attention with... anything at their disposal.

For me what is interesting is how magnetically opposed developers can be to a perceived outsider. And how that works against the recruiter, etc. in question. E.g. We're really lucky with our outside recruiter and she has a lot of credibility, but when she hung out at our booth at OSCON with her lovely female assistant, they clearly stood out and attendees cut a wide swath. Same thing at a different con with one of our investors: extremely technical guy, but you can spot his BD/VC uniform from across the room. I shuffle their conversations away from my booth.

Conversely, I had an interesting conversation in a booth at a different con, where after 20 minutes of talking to me (messy ponytail, company tshirt, jeans, tigers) about our stack, a guy said to me, "Wait a sec, you smell like marketing." By which he meant that I was coming across as non-technical as we got deeper into the technical details (totally fair - I am not a professional developer). I think he felt bamboozled by my lack of shininess.

The shiny girl probably like being shiny, and don't care for the tshirt/jeans/ponytail uniform. There's actually a lot of cool ways technical women subvert the uniform without freaking anyone out (I have hot pink lipstick). I would venture they feel uncomfortable about standing out more than they are plotting to lure you.

Good question. The manual login ensures that a session is started with the correct authentication credentials. Its a good default way to protect against session hijacking attacks.

I suspect we will automate the first authentication down the road, but with such a small drop-off in the new workflow, we're focusing on more core product features first. There's still lots in the new workflow, website, etc. to improve.

That's a good suggestion - will see if we can add a para about it. We use digest authentication, fwiw.

I'm particularly glad you highlighted that marketers often underestimate how social developers are. Analogous: tech marketers and BD people often overlook the fact that developers do a lot of business and share knowledge in social settings...just like people in every other industry. I think its important we get away from dumb tchotkes and focus on meaningful conversations.

Re the marketing systems - I think its less about marketers using the right system, and more about using those systems correctly. There are at least a dozen email automation platforms that can delivery responsive messaging, and most companies of any size have one in place. Speaking from experience, they are just a massive beast to manage - the more complicated and responsive your email set up, the more complicated and time-consuming it is to manage (and more likely you are to accidentally spam everyone). Marketing teams have the right systems, they just don't invest the time to do it right.

Switched from Dropbox to Google Drive a few months ago. the UIs are very similar, and Drive is much cheaper. My only complaint has been syncing:

1) After a week of repeated attempts, I gave up trying to get video from Dropbox to Drive. Maybe the files were too large?

2) Also, syncs are faster and more seamless across devices with Dropbox. There are noticeable lags for most syncs with Drive, even small, single files.

3) Event when Drive thinks it has synced, it hasn't and I have to restart the app.

There are other benefits to Drive, but I never had any sync issues with Dropbox.

Helpful!

I know this is a serious issue re the problems with inflated and systemic agricultural bureaucracy per the thoughtful comments below...but: raisins.org.

Amazeballs as government URLs go.

Stormpath (http://www.stormpath.com) * We have roles open for core Java engineers, a Data Guru and a Developer Evangelist (Python, Ruby, PHP, Haskell...)

Stormpath is the first easy and secure user management and authentication service for developers. Fast and intuitive to use, it offers an easy API, open source SDKs, and an active community.By offloading user management and authentication to Stormpath, developers can bring new applications to market faster, reduce development and operations costs, and protect their users with best-in-class security.

We're well-funded, friendly and located in gorgeous downtown San Mateo near the Caltrain. Drop us a note if you think what APIs - even if there isn't a job listed that fits your bill. Jobs@stormpath.com

Stormpath (San Mateo, CA)

Stormpath is an easy, secure user management and authentication service for developers. We're looking for - Core Java developers - Front-end engineers - DevOps - Developer Advocates

It's a bonus if you love security, if password breaches make you angry, and if want to help developers get busy with API-based architecture. The team is smart, fun and friendly, and we've got some great announcements coming up.

Check out the jobs page at http://www.stormpath.com/ or email your jobs@stormpath.com

Yes, it certainly mitigates the scale of a potential breach and I like that the reduced scale/potential value makes it a less attractive target to hackers (assuming the server side is also built in a secure way). I havent investigated, but it makes me nervous to think that if my phone is stolen, the thief gets my data too.