HN user

joshdotsmith

880 karma

I like to make things

Posts41
Comments218
View on HN
github.com 1y ago

Does the CISO of GitHub read her own GitHub issues alerting her of malware?

joshdotsmith
7pts5
news.ycombinator.com 1y ago

If you work at GitHub security, you are bad at your job

joshdotsmith
13pts0
news.ycombinator.com 1y ago

GitHub flooded with malware repos spoofing real projects–no response from GitHub

joshdotsmith
15pts4
hellosift.com 8y ago

Prioritize your features by customer need

joshdotsmith
5pts0
hellosift.com 8y ago

The remembering user vs. the experiencing user

joshdotsmith
1pts0
news.ycombinator.com 9y ago

Ask HN: Who needs contributors? (December 2016)

joshdotsmith
27pts5
blog.codecorps.org 9y ago

Lower your startup risk with this template

joshdotsmith
3pts0
news.ycombinator.com 9y ago

Ask HN: Who needs contributors? (November 2016)

joshdotsmith
80pts22
news.ycombinator.com 9y ago

Ask HN: Who needs contributors? (October 2016)

joshdotsmith
152pts74
news.ycombinator.com 9y ago

Ask HN: Who needs contributors?

joshdotsmith
107pts37
news.ycombinator.com 10y ago

Ask HN: Should you incorporate as a public benefit corporation from the start?

joshdotsmith
1pts0
fieldthebern.com 10y ago

Show HN: Field the Bern helps you canvass for Bernie with your phone

joshdotsmith
4pts1
talkingcode.com 11y ago

Building modern web applications with Tom Dale of Ember.js

joshdotsmith
3pts0
talkingcode.com 11y ago

How to catch errors quickly

joshdotsmith
6pts0
www.talkingcode.com 11y ago

When and how to outsource your software development

joshdotsmith
1pts0
blog.talkingcode.com 11y ago

Launch an app sooner without cornering yourself

joshdotsmith
7pts0
talkingcode.com 11y ago

Stop treating email like the web: Justine Jordan of Litmus

joshdotsmith
12pts0
www.talkingcode.com 11y ago

How to Do QA Testing with Fred at Rainforest (YC S12)

joshdotsmith
11pts3
www.talkingcode.com 11y ago

How do you find your technical co-founder?

joshdotsmith
16pts0
www.talkingcode.com 11y ago

Show HN: Talking Code – Technical podcast for nontechnical people

joshdotsmith
45pts9
news.ycombinator.com 11y ago

Ask HN: Do you document your development process?

joshdotsmith
2pts4
medium.com 12y ago

I don't know how to cook, but I'm going to teach you

joshdotsmith
1pts0
medium.com 12y ago

Don't ask me to sign your NDA

joshdotsmith
1pts0
news.ycombinator.com 12y ago

Ask HN: Duolingo or Treehouse for cooking?

joshdotsmith
1pts0
www.usv.com 12y ago

"Union Square Ventures' new website is an HN clone"

joshdotsmith
2pts0
news.ycombinator.com 12y ago

Ask HN: Is there an RFC for weights and measures?

joshdotsmith
2pts1
news.ycombinator.com 12y ago

Ask HN: How do you create high quality how-to videos?

joshdotsmith
14pts9
blogs.wsj.com 13y ago

4 Ways to Lose VC Interest Fast

joshdotsmith
1pts0
news.ycombinator.com 13y ago

Tell HN: My first protest

joshdotsmith
50pts1
niftylettuce.com 13y ago

Micro-Projects for Fun and Profit

joshdotsmith
15pts6

As I wrote in this issue, I am exhausted. Microsoft has plenty of money to handle issues like this and chooses not to do so. I have spent hours now reaching out to GitHub in vain, tracking down people affected, and trying to figure out how to get someone to give one single flying fuck.

So what the hell. Let’s make the CISO’s slideshow intro to GitHub popular.

Thanks, I just find it wild that Microsoft appears wholly uninterested in policing what seems like a huge legal liability to their business. I’ll start reaching out to as many journalists as I can with what I’ve got. They seem a little overwhelmed from the two I’ve already reached out to.

Edited to add: I’ve also been hoping that I could avoid giving the attackers too much of a heads up, but at this point the risk is higher that nothing gets done about it at all.

SEEKING WORK | REMOTE | Baltimore, MD, US

Product-focused full stack developer with 14 years of experience. Hired on "Seeking freelancer" before – happy to provide the reference!

Work with early stage startups, often seed or pre-Series A. Recent experience in enterprise on various teams at Credit Karma.

Recent work: https://keyhero.io - designed / built everything

--

Skills:

- Ruby / Rails, Elixir / Phoenix, Node.js

- React, Next.js, some Vue + Elm

- React Native / Expo, Swift

- CSS, HTML, Tailwind

- Design, UI, UX, Figma

- Postgres, MySQL, Redis

- AWS, DO, Fly.io, Render

- TDD / BDD

- SaaS + consumer metrics and conversion rate optimization

--

Email: josh@coderly.com

GitHub: https://github.com/joshsmith

Does this mean you're also hoping to expand into Delaware PBCs, too? Lots of open source projects are considering this approach due to a combination of poor response to open source nonprofits from the IRS and flexibility in figuring out their funding sources. There's only trivial differences to a C Corp in terms of filing.

I'd been planning to reach out to Stripe about this when it made sense; I probably should've just emailed you! We're advising folks we're bringing onto our Stripe Connect platform as managed accounts to go use Stripe Atlas where possible, but plenty have voiced support for having B Corps be part of that happy path.

Honestly, I might even just pay a lawyer at some point to open up some standardized set of docs for this.

Do you hope to have any way for Connect platforms with managed accounts to more directly refer people into Atlas? Having an API for the application process would be amazing.

Code Corps is intended to be a place to find and volunteer for open source projects you think are worth whatever free time you have. For maintainers, we'd like to make scaling your community trivial: acquire and retain volunteers, onboard newcomers, recommend the right tasks to the right people, and fund your operations.

https://www.codecorps.org

As an aside, I'm kind of curious how others feel they fare on building new projects. Do you feel slow? I worry constantly about how quickly I'm moving relative to peers.

Does anyone have resources on how one should design their changes to run side-by-side? I have not been at large companies and don't have the advantage of institutional knowledge to help here. Book, articles, and practical examples would be fantastic.

And since it's often hard to generalize, I work today with Elixir and Postgres. Anything specific around this stack would be exceptional.

Do you mind sending me an email sometime? You can find one in my HN profile. I'm really curious to hear about what you've done to find maintainers and how you've thought about tackling the fundraising issue.

When doing design work I usually now start with Ryan Singer's shorthand for UI flows: https://signalvnoise.com/posts/1926-a-shorthand-for-designin...

From there I'll dive into hand drawings, perhaps a wireframe (although Balsamiq is a pain to use), and maybe some specific visual designs if needed in Sketch, which may then go into Invision. Basically every step is optional along the way to a fully implemented design, but the general flow can be adapted at length.

This is especially nice when doing client work because clients' needs and budgets are highly variable. If I can get away with just a UI flow and drawings and feel confident that we're on the same page in terms of how they describe the UX back to me, then we're good to go.

The biggest thing is to just get over your own insecurities about scribbling and drawing. I'm awful at it. But when my anxiety or my attention-deficit keeps me from going through the earlier (cheaper) motions, then invariably I suffer in terms of time lost later.

National Voter File (http://www.nationalvoterfile.org)

We’re building the first open source, publicly available national voter database in the United States to power grassroots campaigns, monitor voter suppression, and make door-to-door advocacy possible for anyone.

Monthly Goals:

- Create loaders for new states

- Enhance reliability of existing loaders

- Create Python geocoder to tag households with lat/long

- Develop queries to explore data quality

- Begin work on flash API

Skills needed: PostgreSQL, GIS, Python, Pentaho Data Integration (we can help you learn)

Slack Signup: http://goo.gl/forms/8SJRDlo7Lx2rUsan1

GitHub: https://github.com/getmovement/national-voter-file

Dimensional Data Model: https://docs.google.com/document/d/169mIkiIdl4OetbGvnbVCzq9S...

Information on state voter files to load: http://voterlist.electproject.org/home

Pentaho Data Integration: http://community.pentaho.com/projects/data-integration/

License: MIT

Code Corps (https://www.codecorps.org)

We're helping volunteers and donors contribute to software projects for social good.

Monthly Goals:

- Polish edge cases in Stripe integration for monthly donations

- Redesign task UI

- CSS work to move towards BEM, flex box, greater responsiveness

- Minor features in blog

Skills needed: Elixir, Phoenix, PostgreSQL, JavaScript, Ember.js, HTML, CSS, Sass, WordPress, UI and graphic design (Sketch a plus), dev ops (Docker, AWS)

Slack: http://slack.codecorps.org/

Elixir Phoenix API: https://github.com/code-corps/code-corps-api

Ember front-end: https://github.com/code-corps/code-corps-ember

WordPress blog: https://github.com/code-corps/blog.codecorps.org-site

License: MIT

I would also really like to hear stories like this. Was so enthralled by Leo's post I ended up making a template for derisking: https://blog.codecorps.org/lower-your-startup-risk-with-this...

These are learnings that doesn't just flit by me. They're not filler. They profoundly change the way I work precisely because of the depth and detail, along with their actionability. Applied learning is by far what I want to hear.

Also curious about this. For reasons that our team was personally against, we had to devote some serious upfront development work to building an integration with a WordPress backend and the rest of our Ember front-end (which consumed, thankfully, a JSON-API spec backend). We wrote custom adapter and serialization layers for this, which was trivial; the only exceptions to the ease of writing such code was when the WordPress developers would return bizarre status codes or missed root objects or some other such nonsense.

The People's Code 10 years ago

Those reasons, which surely place some non-negligible burden on the teams involved, do not seem to be so overwhelming as to ultimately dictate that 80% of projects are not made open source.

I'm definitely aware of the difficulties involved in open sourcing significant amounts of your work. The bigger burden is less, in my opinion, about cleaning up your code base. If you're committing potential security vulnerabilities into your code that are then tracked by your version control system – and you're a Federal agency – that's already a problem that's just going to be exacerbated by making it public; making that code private doesn't make the problem disappear.

The real meaty problems that all open source projects share is people: people like me who come in and overwhelm the project with support requests. I just opened four issues tonight just for this website, in the span of several minutes. (Sorry team!) If you already have poor project management practices in place, or your team is too small, this can quickly overload you.

Of course, with a vibrant community around your project, even the social and management problems could become trivial with time. Look at especially great examples like Hoodie. Given the number of technical people who have left cushy, high-paying jobs to serve in 18F, USDS, and the other alphabet agencies of late, I have to imagine the rallying cry to support truly useful code by compassionate people will be significant enough to justify the upfront expense here.

Not only is 20% not perfect, I don't think it's enough. I want 100%, and I think it's a fair request as a taxpayer, even if there is some burden. This country has fought two world wars and gone to the moon. We can always do better.