HN user

thegrif

19 karma

[ my public key: https://keybase.io/tomgriffin; my proof: https://keybase.io/tomgriffin/sigs/g8cPQACxSnsE4EY0VGbH9uf0xkO4Me1cT8gbPF_0W6I ]

www.linkedin.com/in/tomgriffin

Posts3
Comments46
View on HN

Originally posted to Twitter[1] after seeing @ghuntley's post - below is a method of building a database of SVB account holders using a cleverly crafted Google query:

(121140399 OR 121145145 OR SVBKUS6S) AND 33**** filetype:xls | pdf | doc | txt -site:svb.com

The query[2] pulls back documents containing an SVB routing or swift number + SVB account number.

The name of the business tied to the SVB account number is usually within 100 characters of the account number and typically labeled "beneficiary" or "for credit of" (or some close variation on those themes).

In edge cases where a company name is not found near the account number, the account holder is often the source/author of the document[3].

Google only returns 1000 results for any given query - so retrieving the entire results set would require narrowing each query's scope and then iterating through the targets at a finer granularity.

For example, the current query looks for account numbers matching 33****. Replacing that with 33*NN**, where NN is 01-99 would let you iterate through ranges of account numbers (33*01**, 33*02**, and so on...).

Other approaches include geographically scoping the queries by adding "AND NJ" to queries (and iterating through each two-byte state code) or tacking on partial zip codes, etc...

It takes tweaking - but the goal is to build a query with elements that you can loop over to get your results into buckets of < 1000. Another option would be to use the Bing Web Search API and paging through the json response.

These methods might complement the work you've already done on affectedbysvbornot.com - and help provide a more exhaustive list of companies impacted by the SVB collapse.

1: https://twitter.com/thegrif/status/1634841498876272641

2: https://bit.ly/svb-account-holders

3: http://bit.ly/svb-invoice-example

In the last 100 days, the MD Department of Information Technology (DoIT) has submitted $3,000,000 of ____emergency____ procurement requests for network monitoring, intrusion detection, and firewall assistance.

All have been approved and funded.

Sept 2021:

- Splunk Emergency Professional Services - $800k

- src: https://bpw.maryland.gov/MeetingDocs/2021-Sept-1-Agenda.pdf

Dec 2021:

- Splunk Emergency Professional Services - $1.6m

- Palo Alto Emergency Professional Services - $360k

- Ciena Emergency Professional Services - $240k

- src: https://bpw.maryland.gov/MeetingDocs/2021-Dec-1-Agenda.pdf

So...what do you think is going on at Maryland's Department of IT?

____TRULY SHAMEFUL INCIDENT COMMUNICATIONS____

Bad things happen in IT departments every day. Some can be anticipated, some even possibly prevented - but there will always exist the risk of data breach/attack.

“Public officials have no higher responsibility than keeping the American people safe, and there is no greater threat to their safety than the cyber vulnerabilities of the systems that support our daily lives,” said Governor Hogan in November 2021.

Secretary Leahy's commitment to the Governor and the people of Maryland is to lead the state's IT resources in taking all reasonable measures to protect against such risks.

I do not yet know if this situation could have been reasonably prevented or if it is due to MD DoIT negligence/oversight. The flurry of emergency procurement requests suggests awareness and good intentions. And yet - here we are...

What is clear to me, however, is that Secretary Leahy and his directs have ___failed to effectively manage communications___ throughout the response and remediation effort.

Most damning, in my opinion, is the use of the incident report as a venue for high-fiving and taking victory laps:

Because of the state’s aggressive cybersecurity strategy, and the use of MD THINK and other cloud-based services, many of the department’s core functions were not affected.

src: https://health.maryland.gov/incidentupdate/Pages/default.asp...

Are you serious? It's been over two weeks. And it's clear from your report that you're nowhere close to understanding what happened, let alone fixing it.

____FUNDAMENTAL MISUNDERSTANDING OF INCIDENT IMPACT____

Whoever approved this for publication is oblivious to the downstream, rippling effects this incident continues to have:

- At the time of writing, MD's local public health departments have been ___fighting a war blindfolded___ for 16 days.

- The impact has rippled ___beyond MD's state borders___, impacting CDC data feeds as well. Hospitalizations (which are reported by each hospital network directly to the CDC) are trending upward while new cases (reported by each state's IIS to the CDC) have flatlined: https://imgur.com/gallery/k2gG5GS.

____AND WHAT THE HECK IS MD THINK?____

MD Think is Maryland's cloud application platform. The state, along with Deloitte and an army of subcontractors, has been working on migrating legacy applications to this new infrastructure since 2017.

The report points to the success of MD THINK in isolating the impact away from core MD Health Department services.

Is MD Think really a success? Is this a case of what happens when legacy applications are left outside to rot in the sun?

No.

It turns out that MD Think has been a nightmare since it's inception. A series of program failures that jeopardized open enrollment for medicaid recipients led to a full audit of the MD DoIT in 2020.

Here is what they had to say about MD THINK:

"...for one project (MD THINK), the estimated $314.1 million cost of completion had increased by $141.1 million (81.5 percent)...an explanation was not provided for the increase..."

And on the topic of security:

"We identified 55 firewall rules that allowed traffic from any source to 71 unique network destinations as well as a small network segment within DoIT’s internal network without IDPS coverage..."

"...access to personally identifiable information (PII) for State vendors stored in the State’s Financial Management Information System (FMIS) was not adequately restricted, and the PII was accessible to thousands of State employees."

src: https://www.ola.state.md.us/umbraco/Api/ReportFile/GetReport...

____What About ImmuNET?____

A question that begs an answer is why ImmuNet, the state's immunization registry, is not included under this "titanium umbrella of protection?"

And while there is a ton of publicly available paperwork about the scope of MD THINK, including the RFP, Deloitte's response, and transcripts of hearings to explore the audit report's findings, ImmuNet is not mentioned. Not once.

Please keep in mind - ImmuNet is not some podunk, state government hobby project. It is __law__ that Maryland retain vaccination records for its residents. School systems, employers, health providers, and the CDC all rely on Immunization Information Systems (IIS) for ground truth vaccination records. It is the public health equivalent of DMV.

____PASSION DISCLAIMER____

The lion's share of my time this year has been spent working with state and local COVID vaccination programs within upstate New York. I have seen firsthand how important accurate, timely test and vaccination data is to how local public health departments coordinate response.

It was infuriating to see the MD DoIT downplay disruptions to COVID related data feeds. We are going into year three of a war that demands accurate, timely data to inform decision making. What the hell have you guys been doing for two weeks?!

The country's public health departments are filled with the true unsung heroes of the pandemic. They're underpaid, exhausted, afraid, and constantly under attack - yet they're our last (and in many ways, only) line of defense.

SO...

To the three people that made it all the way to the end of this post - I ask just one thing:

IF YOU EVER FIND YOURSELF INVOLVED IN A FUCKUP THAT IMPACTS THE DEPARTMENT OF PUBLIC HEALTH:

- RULE 1: Apologize and fix it. Now. With the kindness, urgency, and empathy a mission controller would show a stranded astronaut--Proceed to RULE 6.

- RULE 2: If the problem is not your fault--return to RULE 1.

- RULE 3: If the problem isn't even real--return to RULE 1.

- RULE 4: If they are blaming you for a problem they created on their own--return to RULE 1.

- RULE 5: If the problem is related to Microsoft Access, FoxPro, or any other technology you swore an oath to avoid--return to RULE 1.

- RULE 6: The final rule. Do not downplay the importance of data and tools public health resources rely upon. And NEVER, EVER respond to the problem by boasting about all the great technical achievements made everywhere BUT the underfunded, under-appreciated public health department.

tl;dr: The recommendation is likely driven from you and the provider adding each other to a contacts app LinkedIn has been authorized to source connection data from.

The "People You May Know" feature on LinkedIn is powered by a combination of:

- network analysis (you know A, B, and C. they all know D. you may know D.)

- mining data from your mobile address book (you have A in your contacts, A has you in their contacts, you may know A.)

The recommendation likely occurred as a result of you and the provider adding each other as a contact in a contacts app each of you have authorized LinkedIn to access.

SEEKING FREELANCER | Greater NY Area | Remote | Volunteer Stipend | Covid-19 Vaccine Related

Join a group of MDs, data junkies, and political gurus working on data-driven methods for managing equitable distribution of covid vaccine into some of the most vulnerable communities in the country.

YOU = AN ETL GOD :)

Looking specifically for journeyman-level expertise in building simple yet powerful DQ and ingestion pipelines. Data is a grab bag from sources like cdc, census, state immunization registries, community vulnerability indices, etc...

Approach we have in mind is heavily inspired by this:

https://github.com/datamade/data-making-guidelines/blob/mast...

We are also considering the possibility of making it a bit more easy to manage by using Airflow to keep track of the ongoing DAGs.

AND IF ETL ISN'T YOUR THING...

All of that said, if you're interested in working in data analysis tied to the distribution and management of vaccination opportunities but have different skill sets, I would love to hear from you.

Our work in this area continues to get visibility from leaders in the field and we have several publication-ready findings they could be directly applicable to any future mass vaccination challenges the world faces.

Contact info: https://gist.github.com/thegrif/fd2ac739bf3ca66743d94ba9d049...

SEEKING FREELANCER - Remote

Help our small development team expand our use of Gitlab!

A few things about our work:

* Heavy user of AWS platform services (like RDS, Elasticsearch Service, S3, Cognito, API Gateway, Lambda etc...)

* Backend components are almost exclusively built in Python. Exceptions to this would be cases where we are relying on non-Python based platforms, such as Elasticsearch.

* Frontend components are almost exclusively built as React webapps.

Before shifting work to Gitlab, we experimented with using AWS Codestar (which has fully managed build service, automated continuous delivery and deployments, etc...). It was extremely useful to be able to commit code and have that automatically kickoff a deployment so we could examine the changes from within the context of the application.

For the scope of this project, I would like your help with the following:

- Installation and configuration of Gitlab Enterprise on AWS, Including any integration required to enable automated deployments. This would include configuration of the AWS kubernetes service, etc...

- Guidance on how to best handle projects with heavy AWS dependencies - for example, would deploying a review app standup an entirely separate environment via CloudFormation? Or would we have dev/test/prod AWS assets setup ahead of time that the review apps would depend on (for example, if we were building an app atop the AWS Elasticsearch service).

- Guidance on how we can build application templates that may facilitate the process of beginning work on a new project. For example, CodeStar had several project templates to choose from (https://docs.aws.amazon.com/codestar/latest/userguide/templa...).

- Any other expertise you can provide to help our team move through projects in a more efficient manner (across project management, development, testing, deployment, etc...).

Contact information:

email: tom@thegrif.net telegram: telegram.me/tomgriffin linkedin: linkedin.com/in/tomgriffin

This is a useful post. I'm also currently looking for a computer vision resource to provide expertise in a project centered on visually identifying anomalies in video of industrial machines. In other words, watching a robot and firing an alert when he misbehaves or breaks down :-)

Similar to what I believe your approach is, I'm looking for someone comfortable working in iterations. So much of this type of work is experimentation and trial and error.

If you want to connect, hit me up using:

http://telegram.me/tomgriffin http://linkedin.com/in/tomgriffin http://facebook.com/tomgriffin

Location: Greater New York Area

Remote: Yes

Willing to relocate: Yes

Technologies: Focuses on leveraging emerging technologies and how they can enable new, profound enhancements to user experiences as well as improvements to technical operations. This includes computer vision, machine learning, cloud computing (in terms of operating at a scale that otherwise would have been impossible), location-aware technology, graph databases like neo4j and titan, and large-scale information retrieval.

Résumé/CV: http://www.linkedin.com/in/tomgriffin

Email: tom@thegrif.net

I am looking for opportunities that leverage my passion for building great products and services, value a hands-on approach to design and use of emerging technology, and build upon my success in helping teams embrace and foster innovation and creativity.

I have over fifteen years of hands-on experience in driving design-driven innovation, delivery of large-scale technology initiatives, and identification of new opportunities for growth and sustainable value. I have been regarded as a thought leader in enterprise technology, product innovation, problem solving, and design thinking.

I think search is much harder than browsing. I think what you're seeing on Amazon (and other sites) is that both search and browse is driven off the same set of data. In other words, navigation is created on the fly based on the products within each section. It doesn't matter whether you start by browsing and then search or vice versa - you'll get the same navigational experience.

BestBuy does a bit better job with this - but they too are employing the same strategy - they just don't expose the facets until you're two levels down in the taxonomy. Which makes sense - because usually facets are going to be too much if the user is too high in the taxonomy or brings back too diverse of a results set.

Amazon appliances: http://www.amazon.com/Appliances/b/ref=nav_shopall_ha?ie=UTF...

Bestbuy appliances: http://www.bestbuy.com/site/electronics/home-appliances/abca...

Sears follows the BestBuy approach and alters it slightly by showing iteratively more complex faceting options as you drill down.

Sears is broken down into ~30 departments: http://www.sears.com/en_us/sitemap.html

For each department, they have a nice landing page to facilitate discovery of their most popular sub-departments as well as a page that lists all the sub-departments:

http://www.sears.com/appliances/b-1020003 http://www.sears.com/en_us/sitemap/appliances.html

(as a note, I would wager that sitemap/appliances.html is purely an SEO tactic)

Not integrated with the navigation is also the search results page for the same data that drives all of the navigation throughout the appliances department:

http://www.sears.com/search=?levels=Appliances&catalogId=126...

From http://www.sears.com/appliances/b-1020003:

Drill down into a product category and you get simple facets on the left:

http://www.sears.com/appliances-washers-dryers/b-1320301405?...

For some popular sub-categories they have chosen to do landing pages as well. Like for specialty laundry:

http://www.sears.com/appliances-washers-dryers-specialty-lau...

The same results can be found here (in the search results interface):

http://www.sears.com/search=?levels=Appliances_Specialty%20L...

In the end though, you eventually hit the faceted navigation interface:

http://www.sears.com/appliances-specialty-laundry-centers/b-...

Home Depot has followed the same design approach - showing a level of detail in the facets that tries to match whether the user is in discovery mode or has the intent to purchase something specific.

As you can tell, I have spent way too much time thinking about and building search results pages. Feel free to reach out to me - I'm @thegrif on Twitter or linkedin.com/in/tomgriffin on LinkedIn.

Location: Greater New York Area

Remote: Yes

Willing to relocate: No

Technologies: Graph Databases, Amazon Web Services, Elasticsearch, Google Bigtable/BigQuery, AWS Redshift, AWS DynamoDB, Talend, Tableau, Nutch, AWS Kinesis, Storm, Python, Machine Learning, Predictive Analytics

Résumé/CV: https://dl.dropboxusercontent.com/u/9893126/tomgriffin-resum...

Email: tom@thegrif.net

LinkedIn: http://www.linkedin.com/in/tomgriffin

Background: Most recently held the position of Director of Innovation for IEEE (Institute of Electrical and Electronics Engineers). Ran the company's skunkworks program. Career progression is a blend of business analysis, enterprise architecture, user experience design, and innovation/r&d management. Often cast as a utility player.

Looking For: Full-time and freelance assignments focused on product design, prototype development, UX, and experimentation with emerging tech.

SEEKING WORK (Remote if Outside the Greater New York Area)

Technologies: Graph Databases, Amazon Web Services, ELK, Google Bigtable/BigQuery, AWS Redshift, AWS DynamoDB, Talend, Tableau, Nutch, AWS Kinesis, Storm, Python, Machine Learning, Predictive Analytics

Résumé/CV: https://dl.dropboxusercontent.com/u/9893126/tomgriffin-resum...

Email: tom@thegrif.net

LinkedIn: http://www.linkedin.com/in/tomgriffin

Background: Most recently held the position of Director of Innovation for IEEE (Institute of Electrical and Electronics Engineers). Ran the company's skunkworks program. Career progression is a blend of business analysis, enterprise architecture, user experience design, and innovation/r&d management. Often cast as a utility player.

Looking For: Full-time and freelance assignments focused on product design, prototype development, UX, and experimentation with emerging tech.

I'm the former director of innovation for IEEE. I actually recruited many members of my team from HN. We were developing some great stuff to address many of the comments here. Unfortunately they just didn't have the stomach for it - and hardly none of it hit users (and the stuff that did was so watered down to protect current revenue streams that it's completely different (and in some cases silly).

There were a handful of folks in this thread who said they'd be interested in building some new stuff to solve the era problems in how scientific knowledge is created and shared. If anyone wants to contact me directly, I'd be happy to organize those interested, capture ideas, and see if there's something common we all want to work on. I'm at tom@thegrif.net or www.linkedin.com/in/tomgriffin.

I have a bit of inside knowledge of the subject having worked for UPS and been out during Christmas time delivering packages. Here is what happens:

Drivers get in trouble if they miss a commit time. To avoid getting in trouble, they will scan the package and mark it as delivered - which results in the delivery status being updated. When they make the actual delivery, they will not scan the package (because it's already left the driver's possession according to the earlier scan).

All package tracking is done based on scans/events. Some of those scans are of the actual package (like above), others are based on inheritance (a trailer containing 500 packages leaving San Francisco will show that data replicated down to each of the packages). UPS only publicizes a portion of the tracking data to its customers - there are events captured at a much more granular level of detail that you can usually get out of CSRs if you call and inquire.

:-)

Graph databases shine when the connections between data objects are as important as the objects themselves.

A social network is a classic example. User profiles are the primary objects - but the connections between them - who's friends with who - is just as important to creating the user experience.

Another example is one from academic research: citation graphs. Research papers reference other papers. If one was building an app to mine citation data, a graph database would be ideal.

I built a graph-based recommendation system by defining connections between parent/child/related products. I then was able to traverse the graph, starting at known purchased, and branching outward to find other products/services the customer may be interested in.

SEEKING WORK (Remote, Greater New York Area)

Technologies: Graph Databases, Amazon Web Services, Elasticsearch, Google Bigtable/BigQuery, AWS Redshift, AWS DynamoDB, Talend, Tableau, Nutch, AWS Kinesis, Storm, Python, Machine Learning, Predictive Analytics

Résumé/CV: https://dl.dropboxusercontent.com/u/9893126/tomgriffin-resum...

Email: tom@thegrif.net

LinkedIn: http://www.linkedin.com/in/tomgriffin

Background: Most recently held the position of Director of Innovation for IEEE (Institute of Electrical and Electronics Engineers). Ran the company's skunkworks program. Career progression is a blend of business analysis, enterprise architecture, user experience design, and innovation/r&d management. Often cast as a utility player.

Looking For: Full-time and freelance assignments focused on product design, prototype development, UX, and experimentation with emerging tech.

Location: Greater New York Area

Remote: Yes

Willing to relocate: No

Technologies: Graph Databases, Amazon Web Services, Elasticsearch, Google Bigtable/BigQuery, AWS Redshift, AWS DynamoDB, Talend, Tableau, Nutch, AWS Kinesis, Storm, Python, Machine Learning, Predictive Analytics

Résumé/CV: https://dl.dropboxusercontent.com/u/9893126/tomgriffin-resum...

Email: tom@thegrif.net

LinkedIn: http://www.linkedin.com/in/tomgriffin

Background: Most recently held the position of Director of Innovation for IEEE (Institute of Electrical and Electronics Engineers). Ran the company's skunkworks program. Career progression is a blend of business analysis, enterprise architecture, user experience design, and innovation/r&d management. Often cast as a utility player.

Looking For: Full-time and freelance assignments focused on product design, prototype development, UX, and experimentation with emerging tech.

SEEKING WORK - Remote or Onsite in New Jersey or NYC - Product Design and Emerging Tech

Since October 2012 I have been running a startup incubator and innovation lab within IEEE. In its first two years the program has delivered patent pending intellectual property, a pair of breakthrough product platforms, and countless incremental enhancements throughout the IEEE user experience and business architecture.

How can I help you? -Product design and development -Expertise in emerging tech (machine learning, computer vision, cloud computing) -Experience in early-stage ventures and financing -Bullpen of awesome, highly specialized business and technical consultants

Check me out at http://www.linkedin.com/in/tomgriffin

You may also email me at tom+hn@thegrif.net.

:) :)

SEEKING WORK - Greater New York Area - REMOTE (unless in area)

Focuses on leveraging emerging technologies and how they can enable new, profound enhancements to user experiences as well as improvements to technical operations. This includes computer vision, machine learning, cloud computing (in terms of operating at a scale that otherwise would have been impossible), location-aware technology, graph databases like neo4j and titan, and large-scale information retrieval.

Résumé/CV: http://www.linkedin.com/in/tomgriffin

Email: tom@thegrif.net

My passion is in building great products that people love.

I am constantly questioning the world around me, asking why things are the way they are, and seeking new ways of delivering great user experiences and sustained business growth.

Most of my work focuses on new, bold, breakthrough innovations that could fundamentally transform the path of a product or even an entire company. Other times I am immersed in quiet, simple ideas - ones that are so small they may have otherwise been missed had it not been for insight and curiosity.

I have over fifteen years of hands-on experience in driving design-driven innovation, delivery of large-scale technology initiatives, and identification of new opportunities for growth and sustainable value. I have been regarded as a thought leader in enterprise technology, product innovation, problem solving, and design thinking.

My key strengths include:

♦ identifying transformation opportunities in business architecture and technical capability

♦ developing and leveraging emerging technologies

♦ evangelizing enterprise-wide change

♦ creating corporate innovation processes and incubation programs

♦ aligning technology teams, business capabilities, and solution development

♦ innovative resourcing/staffing strategies

I am looking for opportunities that leverage my passion for building great products and services, value a hands-on approach to design and use of emerging technology, and build upon my success in helping teams embrace and foster innovation and creativity.

Location: Greater New York Area

Remote: Yes

Willing to relocate: Yes

Technologies: Focuses on leveraging emerging technologies and how they can enable new, profound enhancements to user experiences as well as improvements to technical operations. This includes computer vision, machine learning, cloud computing (in terms of operating at a scale that otherwise would have been impossible), location-aware technology, graph databases like neo4j and titan, and large-scale information retrieval.

Résumé/CV: http://www.linkedin.com/in/tomgriffin

Email: tom@thegrif.net

My passion is in building great products that people love.

I am constantly questioning the world around me, asking why things are the way they are, and seeking new ways of delivering great user experiences and sustained business growth.

Most of my work focuses on new, bold, breakthrough innovations that could fundamentally transform the path of a product or even an entire company. Other times I am immersed in quiet, simple ideas - ones that are so small they may have otherwise been missed had it not been for insight and curiosity.

I have over fifteen years of hands-on experience in driving design-driven innovation, delivery of large-scale technology initiatives, and identification of new opportunities for growth and sustainable value. I have been regarded as a thought leader in enterprise technology, product innovation, problem solving, and design thinking.

My key strengths include:

♦ identifying transformation opportunities in business architecture and technical capability

♦ developing and leveraging emerging technologies

♦ evangelizing enterprise-wide change

♦ creating corporate innovation processes and incubation programs

♦ aligning technology teams, business capabilities, and solution development

♦ innovative resourcing/staffing strategies

I am looking for opportunities that leverage my passion for building great products and services, value a hands-on approach to design and use of emerging technology, and build upon my success in helping teams embrace and foster innovation and creativity.

For the enterprise IT market, build a tighter experience for sites like Gartner, Forrester, and other research providers. IT execs shell out a lot of money for subscriptions to these services - and they will realize a greater return from their investment if they can easily disseminate information to other stakeholders.

:-)

I've had a few prospective search use cases and have used both the percolator out of elastic search and the service out of Google cloud platform. I would find committers that worked on the percolator future and see if your work could possibly be baked into the core elastic search platform. that would solve a lot of people's problems. :-)

and don't forget that solr remains a major player in terms of open source faceted search. and they have no prospective search feature. i would think they would have done it already though - there must be something architecturally that's preventing them from delivering the high-performance solution you built.

Believe it or not there are companies out there looking for people exactly like you: individuals that can come in, question the status quo, and push things forward. Many big organizations are realizing that in order to compete they actually have to operate like much more nimble enterprises. You'd be the only one who knows how to do that :-)

I draw a lot of parallels between this and the movie Moneyball. You will have lots of fun with your work - because you bring entrepreneurial passion, creativity, and grit. But there will be many that don't like you coming in, asking obvious questions, and then delivering better stuff. Find someone in executive management that has your back politically and you'll be fine. :-)

Shoot me a note at @thegrif if you want to talk more. Depending on where you are in the world I might be able to facilitate some introductions.

I highly doubt he had eyes on you :-)

The fact that he goes out of his way to talk about a very special iPad leads me down the path that maybe he's signed in to your iCloud account? If so, he's watching iMessages and any activity to contacts/calendars/reminders/etc...

A few clarifications that might better help us:

1. Is there some sort of bet or challenge?

2. Were you intentionally hiding?

3. Has your friend had recent physical access to any of your devices?

Boy have I hit rock bottom responding to this...fucking insomnia :(

It will be impossible to deliver a worthwhile UX if the details of the product are obfuscated from the design team. Find a reputable product design professional willing to execute an NDA.

Figure out a compensation scheme that makes the both of you comfortable - but make sure his skin is in the game and he's not just burning hours. It doesn't have to be equity - maybe a big payout once you hit a certain critical mass of users.

I'd be glad to put you in contact with some folks that may be interested. I'm at tom [a] thegrif [dot] net. Good luck :-)