
Sign up to save your podcasts
Or

![Code[ish]](https://podcast-api-images.s3.amazonaws.com/corona/show/685572/logo_300x300.png)
Erin Allard is a Platform Support Engineer at Heroku, and she's leading a conversation with Jace Bryan (who works on the Customer Centric Engineering team at Salesforce.org), Eric Routen (a family medicine resident in the New York area), and Bryan Vanderhoof (a manager on Heroku's runtime team). Each of these individuals come from different backgrounds, but they are united together in the larger LGBTQ community. After they came out, they sought ways to support other LGBTQ individuals who were not given the same opportunities as they were. Bryan focuses on helping homeless individuals, many of whom are children kicked out of their homes for being queer; Eric helps LGBTQ youth with job preparedness and substance abuse disorders; Jace shares their story of homelessness to college degree as a means of inspiring others to never give up.
With respect to intersectionality, each of the speakers identifies that they are but a sliver of the communities they represent. It's important for them to acknowledge their own privileges, while at the same team being an ally for voices not at the table. Everyone goes through challenging experiences, but it's important to continue to show empathy towards others who need help too. One way to do that is to continue to volunteer, or at least, reach out to communities, and learn for yourself what problems they have. Uplifting those who don't look like or feel like you is one of the aims of Pride Month.
LinksBen Halpern and Jess Lee are the co-founders of Dev.to, an online community dedicating to helping the developer community communicate. They've been described as a social network for software developers, where anyone from novices to experts can create a blog post to share their ideas. They worked on the site for a long time as a side project, and after they launched, the unexpected and overwhelmingly positive responded they received encouraged them to turn it into their full-time job.
Part of what makes Dev.to so appealing is that it's been designed to be fast. The site is designed to take advantage of caching at POP centers, so that individuals around the world can access the content as quickly as possible. Since the project is also open sourced, they've been able to receive contributions from over 500 individuals, ensuring that no bug goes unseen.
Dev.to also considers community health to not just be essential to the business, but also a value woven into the company and the product. Their focus on education and strong moderation tooling has helped them build trust in their users. Users feel safe when the site actively minimizes aggressive language. The future of Dev.to is shaped by the feedback they receive, but in many instances, they allow the community to thrive without too much administrative interference.
Links from this episodeGreg Nokes is a Master Technical Architect at Salesforce. His focus for this interview is on two members from MX Technologies, a fintech startup that helps financial institutions: Garrett Thornburg, an engineering team lead, and Brett Allred, its CPO. A consequence of COVID has been an increase in unemployment. In response to this, the U.S. Government came out with a paycheck protection program, or PPP, to lend money to small businesses to pay their staff. The program turned out to be incredibly popular, as banks and credit unions were inundated with applications to apply for these PPP funds. Many of these loans were processed by hand, and banks turned to MX Technologies to help process these faster.
The technical challenges were daunting, and due to the urgency of the situation, the team at MX Technologies worked on a solution over three days to try and get an app out there. Choosing Heroku as a basis for the tech stack was not a difficult decision. They were able to code something up using Rails, and an automatically scalable Redis and database system. The only concern was that because they were working with financial data, they needed to ensure that whatever system they used met rigorous security guidelines. Naturally, Heroku did, and it even passed third-party penetration tests, instilling confidence in their use by the government.
The MX team decided to open source their app and the Terraform scripts used to generate it because they want to make sure everyone is able to benefit from this essential program. Through their efforts, they've been able to help distribute $5 billion dollars, helping to save thousands of jobs and businesses.
Links from this episodeOwen Ou is an engineer at Heroku, and he is joined by two employees from AE Studio: Melanie Plaza, the Head of Technology, and Adam Hanna, an engineer. The conversation begins with a discussion of the tools used when developing with the blockchain in mind, including testing environments that mimic production systems like Ethereum. Developers in the blockchain community are constantly trying to lower the barriers to entry, and both Adam and Melanie agree that it's very easy to get started with the available tooling.
The three take a step back from this and start talking about the origins of the blockchain and Bitcoin in particular, how it came about from a need for a decentralized system of privacy. The ultimate goal of the blockchain is to provide a repeatable and verifiable chain of anonymized information that cannot be tampered with. Each block in the blockchain is a cryptographic hash of all the data that came before it. Adam talks about how "mining" works--the incentives for people to provide computational resources to help verify the blockchain. Since all of this information is decentralized, no one can control or manipulate the history of the hashes.
While cryptocurrencies have been used for nefarious activities in the past, Melanie is optimistic for its current and potential uses. Filecoin, for example, is a distributed file storage network on the blockchain. Residents of countries with draconian censorship laws rely on Ethereum to communicate safely with each other. Adam believes that a potential "second Internet" could arise for social conversations that's separate from the transactional, ad-driven one we currently use.
Links from this episodeCharlie Gleason, a designer and developer at Heroku, is joined by Lynn Fisher, a designer, CSS developer, and a software and design consultancy at &yet. Lynn went to school for Fine Arts, majoring in inter-media art. She found her unique perspective on art and design gave her a leg up in working with HTML and CSS projects in the mid-2000s, and from there, moved into working in frontend development.
Her personal work has explored the creative possibilities of web design. A Single Div shows the incredible possibilities when drawing with a single div and CSS. The Food Place (from The Good Place), Top Chef Stats, and Dress David Rose (from Schitt's Creek) explore pop cultures through through minimal illustrations, and emphasize the flexibility of pure web development. US Flags [dot] Design is an exhaustive design guide to the flags of the United States, while Airport Codes demystifies the IATA three-letter airport code. Their discussion probes these projects, and how Lynn balances her work responsibilities with her creative (and time-consuming) artwork.
Links from this episodeBrian Chan and Vikram Sreedhar are Asian Americans and Anna Chan is British born Chinese and they are all working in various roles across Salesforce. Each of them grew up in different parts of the world and with varying interest in a career in tech. They discuss their journeys into a STEM career and ultimately how they ended up at Salesforce.
One of the consequences of the COVID-19 situation has been an increase in the amount of racism aimed at members of various Asian communities. Because of these, each of the speakers has felt an increased responsibility in helping members of their community and others around them. This takes the form of donation, volunteering, or even just educating people on why their behavior could be interpreted as being hostile. What drives them in this work is the goal of raising awareness for these problems and helping improve the diversity for future generations entering tech.
They conclude with some words of encouragement for people who want to start helping people in their community, whether they come from an Asian background or not. They also provide advice for those coming into tech on how to prepare themselves for success.
Links from this episodeBecky Jaimes is a product manager at Salesforce interviewing Dejim Juang, Master Principal Solutions Engineer at Mulesoft. Recently, Dejim wrote an article describing how to connect Mulesoft with Heroku Postgres as a new data source. The main function of Mulesoft is to integrate with various SOA, SaaS, and APIs, and provide developers with a single integration point. Rather than writing entirely new data ingestion software from scratch, Mulesoft does the heavy lifting of connecting to data sources and responding back with the requested information.
MuleSoft can be used to build integrations between Salesforce and applications outside of that ecosystem through a drag and drop interface. Some use cases where Mulesoft might not be appropriate include building a BPM tool or managing file transfers. Although Mulesoft certainly has these capabilities, they are too fragile and inefficient to be relied upon heavily. In terms of database connections, you can make RESTful API calls to Mulesoft and have it access information across all of your systems. This is especially useful if your customer data is located in one place and your software data is located somewhere else.
Developers can also write their own code to manipulate the data from disparate sources. They can choose to share their project on the Anypoint Exchange, or continue to use it locally. Although Java is the primary language of choice, there are also scripting choices for JavaScript, Python, .Net, and Ruby. Mulesoft also comes with protections against reporting changes from underlying database migrations, as well as issues with connectivity.
Links from this episodeCharlie Gleason, a designer and developer at Heroku and Salesforce is in conversation with two members of the non-profit Active for Good: Troy Hickerson, its co-founder, and Luke Mysse, its managing director and brand strategist. Some years ago, Troy and Luke learned about Ready-to-Use Therapeutic Food, which is a powdered milk formula designed to provide vitamins and nutrients to malnourished children. Since such a simple product had the potential to help so many lives, they were inspired to find a way to increase its production and distribution. This led to them starting Active for Good. They knew that people weren't likely to make behavior changes unless there was a motivation. They decided that in order to help people get more fit, the distinguishing feature of their activity-tracking app would be to convert every minute of exercise into points, and those points into RUTF packets.
Active for Good has two types of challenges: an open public challenge, where you and your friends can try to meet a goal over the course of 30 days; and company challenges, where a company can invest in their people to encourage more movement. The aim of the app is to minimize screen time, get active, and help real people in the process. Activities aren't limited to strenuous exercise, either; housework, meditation, and other positive physical movements are also considered. Everyone from individuals to high schools to corporations have found the project useful.
Both Troy and Luke understand that changing your habits can be difficult. But they also know that it's just important to pick an activity and try it. Whether that's slowly gaining miles on a bike ride, or deciding which philanthropic project to get involved in, the most important thing is to just start doing it.
Links from this episode:Robert Blumen is a DevOps engineer at Salesforce, and he's interviewing Sean Porter, the CTO of Sensu, a cloud monitoring platform. Monitoring your infrastructure often looks like keeping track of the four golden signals: latency, throughput, error rate, and saturation. To that, Sean advocates identifying data specific catered to security and privacy. For example, with regards to intrusion detection, a company could track the rate at which unauthorized attempts are being made, and where they're coming from. This could signal potential weak spots in the system or software which malicious actors are probing. Armed with this data and analysis, one could reinforce their security.
More broadly, intrusion detection is really about monitoring changes to your system's state. You could take a snapshot of your entire file systems, from permissions of folders to the individual bytes of each binary; by recording the information of a known "good" state, you can track any changes that are occurring. You would be able to identify the rate at which your servers are undergoing configuration drift, or be notified if key system software, such as ssh or ps, have been tampered with. Monitoring your security is about taking a proactive approach to observing any state change on a machine, not necessarily whether unauthorized ports are being sniffed.
With regards to privacy, you could build some auditing functionality to ensure that you're not exposing any user information you shouldn't be. One approach might be to monitor whether numbers that look like a credit card are being accidentally showing up in your logs. It's also important to be mindful of compliance with regulations like GDPR. GDPR stipulates that users must give explicit permission for the ways in which you store and make use of their information. Sean points out that there are tracing systems which can track a user's movement from their browser navigation through each microservice they transparently access. Your monitoring system would want to keep an eye on these flows and ensure that every system is behaving appropriately.
Links from this episodeChris Castle, a developer advocate at Salesforce, is joined by Evan Grim, a software architect at Salesforce responsible for the Salesforce Authenticator mobile app. Salesforce Authenticator is a component of a two-factor authentication flow. After a user signs in to their Salesforce organization, the mobile app will generate a secure code which is used to provide additional verification. This guarantees that even if a user's password is compromised, a hacker won't be able to login unless they have access to your phone, too.
Experiencing a flow like this has become commonplace, with banks and other websites taking a security-first approach to their user experience. What's starting to change is the way these 2FA apps work. For example, Evan has built a flow where the Salesforce Authenticator uses geolocation to identify where you are. If you log in to a website from the same location enough times to establish a pattern, the app can send the security code automatically, without you needing to type anything in. Evan is very interested in exploring further trends where safety is not compromised for the sake of usability.
For the remainder of the episode, Chris and Evan discuss the fundamentals of the technologies and systems used to build the app. Evan believes that keeping things simple is paramount to any software project. For many years, the Salesforce Authenticator backend was situated in one region, and it served them well. Now that the app has become more popular, they are considering the complexities of multi-region support, including sharding their Postgres database. Their trade-off for focusing on adoption over sophistication has paid off, as it often does. Now that their idea has been validated, they can plan to rearchitect their app to support increased volume from a growing security-conscious user base.
Links from this episodeFrom the publisher's feed