Steven Lawrance

From Moonlight Design
Jump to: navigation, search

Welcome to the web site of Steven Lawrance, master of software engineering (MSE). I enjoy building complete computing solutions at all levels of abstraction to automate business processes at a low cost, in a short time frame, and with high quality. Put my experience, interests, training, and expertise to work for you. Please feel free to contact me today.

Software Built in a Team Software Built by Just Me Employment History Education and Training

Résumé: Portable document format (PDF)

Network: LinkedIn

Please feel free to ask me for more information about any project listed on this page.

Software Project Experience

Team software

I materially participated in the team software projects listed below:

Name Description Technologies SLOC Year Web-based business software platform and suite of integrated business applications. During my time at, I have worked on several teams -- API, Sites,, and Platform Security. Most recently, I led the implementation of custom https domains for Salesforce's site technologies, and this included tangential work, such as the domain management screens that were added in Summer '14. I've been a go-to person for several parts of the platform, and this includes Sites, the database tier of, site publishing, custom https domains, clickjack protection, inbound and outbound https connections, the reverse proxy caching layer for sites, IPv6, and our main production feature testing tool.

At's Dreamforce 2013 conference, I presented a session on the lessons learned while developing a solution to replace an older Microsoft Access solution for the San Francisco AIDS Foundation.

Earlier at, I integrated the low-level parts of Siteforce into the core product; wrote Siteforce's Resin and runtime server configurations; wrote a cross site scripting Firefox/Firebug extension to test proper output escaping in the manual and automated tests; improved an internal production testing tool's scheduling of tests by adding prerequisite expressions to increase test parallelization; and added per-window screenshots to an internal testing tool by extending Selenium with JNI native code.
Java, Apache Ant, Selenium, JUnit,, Jetty, Resin, JSP, Servlets, JNI, Win32, X11 large 2007-current
Reggie/CIS A 200-user multi-tenant three-tiered HIV/AIDS client database system that was used by all Ryan White Foundation CARE-funded AIDS service organizations in San Francisco in collaboration with the San Francisco Department of Public Health (DPH) AIDS Office and two partners to the San Francisco AIDS Foundation (SFAF), where I worked for about five years. I actively maintained this system with a colleague at the DPH AIDS Office and was principally responsible for maintaining the "CIS" portion of Reggie/CIS, which extended the Reggie platform with extra features that the SFAF and two other organizations used. Java, VBScript, Swing, T-SQL, MS SQL Server, CVS, JavaScript, C, JNI, CORBA, IIS, COM, Win32 162,005 2000-2005
DonorPerfect Online Donor and fundraising event management system used by the San Francisco AIDS Foundation. I migrated AIDS/LifeCycle data from a Goldmine database to the San Francisco AIDS Foundation's customized DonorPerfect Online system using a test-driven development process for the SQL scripts. I also contributed substantially to the bulk data entry wizard, fixed bugs throughout the system, including security holes, made all pages and JavaScripts operate properly in Mozilla Firefox, and implemented strict URL filtering security using an Apache reverse-proxy and mod_rewrite. VBScript, T-SQL, MS SQL Server, JavaScript, Apache HTTP Server, IIS, CVS 97,592 2004-2005
SFAF CRM Customer relationship management system that was implemented by a colleague at the San Francisco AIDS Foundation that primarily serves the organization's volunteer based programs department, automates expense reports, and runs the California AIDS Hotline. I enhanced the deployment system using CVS in a web-based front-end, helped my colleague fix various bugs, and enhanced its Internet-facing security with an Apache reverse-proxy and mod_rewrite. VBScript, T-SQL, MS SQL Server, JavaScript, Apache HTTP Server, IIS, CVS 69,015 2001-2005
Bosch Security Configuration Assistant An Eclipse-based application that generates three-dimensional security plans for buildings using a rule engine and three-dimensional visualization. In this project, I integrated a Windows-based three-dimensional visualization program into an Eclipse view, kept our RedHat Fedora Core server and software available, secure, usable, and backed up using only one hour per week of my time on average throughout the project, and automated our data collection and reporting processes to minimize project overhead work. This group project involved four other students -- two whom also work at -- and served as a laboratory for us to directly apply coursework to a software project with a real client throughout our software engineering masters' programs. Java, Eclipse, UML, Apache Ant, Bugzilla, CruiseControl, MediaWiki, Subversion, SWT, C++, JNI, Win32 21,274 2005-2006
Park 'N Park A fault-tolerant, distributed, real-time three-tiered application for tracking parking garage usage. This was an academic project. Java, CORBA, MySQL, CVS 2,027 2006
Teacher's Pet Shares a tab in your Mozilla Firefox browser with one or more remote browsers, which can be useful in virtual classroom environments JavaScript, Java, XUL, XPCOM, Subversion 1,251 2006
Hulk Physically navigates a maze using a customized Parallax Boe-Bot. This project involved both custom hardware and custom software as well as trade-offs between the two when implementing features. Parallax BASIC Stamp, Parallax Boe-Bot, Subversion 784 2006
URL Lock Follow-up project to IE URL Lock that sports a configuration user interface and implements new ideas for visually disabling content on the web JavaScript, XUL, C++, XPCOM, Win32, Subversion 3,868 2006
Ariesbase Intranet system for Ariesnet, Inc. During the Summer of 1999, I helped shape the back-end functionality, such as the security system and global includes, and I also created a high-level specification for an employee rating system for virtual team environments. PHP, MySQL, JavaScript, CVS medium 1999-2000

Software that I created

I wrote and maintain the following software:

Name Description Technologies SLOC Year
Home Profiler Synchronizes user profile data between multiple desktop computers, regardless of the operating system. This was used at the San Francisco AIDS Foundation to migrate user profile data from Windows NT to Windows XP while leaving malware and spyware behind. Java, C, JNI, JACOB, COM, Win32, CVS 5,679 2005
IE URL Lock A browser helper object (BHO) that prevents users from navigating to web sites in Internet Explorer and Windows Explorer while permitting URLs that match a Perl-compatible regular expression stored in the registry C++, COM, BHO, Win32, Subversion 1,607 2005-2012
Backup system Multi-platform, SSH-secured, Internet-based incremental backup system that I assembled and use to back up all computers that I manage Unison, Apache HTTP Server, OpenSSH 2005-2007
Read-only filesystem FUSE filesystem view that makes all files unconditionally read-only. I use this in my backup system for the web-based file restore interface. C, FUSE 241 2005-2007
Serendipity Time Tracking Tool A two-tier software team time tracking tool used by Team Serendipity while designing and building the Bosch Security Configuration Assistant. It was rapidly developed using Microsoft Access 2003 as the front-end user interface, MySQL 5 as the back-end database, and SSH as the MySQL connection tunnel. VBA, Microsoft Access, MySQL, OpenSSH small 2006
GnuCash to QIF Converts a GnuCash XML file into a QIF or an IIF file Java, Apache Xerces 2,274 2002-2007
PDF Access Reports Web-based PDF reports using Microsoft Access, a customized PHP build to run as a COM server, and a custom-built COM object for use by ASP on the reporting server. This was a component of Reggie/CIS's reporting system. PHP, COM, C++, Sockets, VBA, ASP, Microsoft Access 651 2002-2005
PDFFile and InvokeAsUser Enables easy portable document format (PDF) file generation on Windows computers when used with AFPL GhostScript and RedMon C, Win32 396 2005
SFAF VPN Client Connects a Microsoft Windows 2000 or XP computer to the San Francisco AIDS Foundation's virtual private network (VPN) by using the built-in IPsec and PPTP capabilities in Windows. Each client computer is secured with a machine-unique public/private key, and users are authenticated against the NT domain using PPTP over the IPsec connection. C, Win32, Java, Swing, CVS 2,623 2003-2005
Door Lock Specification (not an implementation) of a secure residential door real-time, embedded software system that uses electronic locks, secure entry, easy exiting, and alarm state awareness to securely and efficiently manage a door Parallax Javelin 0 2006
Swing Inline Spell Checker Inline spell checker that plugs into Swing's look-and-feel system. This was used in Reggie/CIS as its distributed spell checker with GNU Aspell running on the server. Java, Swing, CORBA, GNU Aspell 2,859 2002-2005
DirList User directory system that runs as a CGI to serve up user lists, search, and synchronize with the operating system's user database. When used with DirList2ODBC, the ODBC driver that I wrote for DirList2, the entire DirList2 system becomes a structured query language (SQL)-compliant database system within the limits of the DirList2 Server. This project began in January of 1998 and is actively patched for any security issues that arise. Bryant University continues to use this program for their student web site list. C++, C, Sockets, ODBC, Linux, Win32, VBA, Microsoft Access 8,268 1999-2007
DirList2ODBC ODBC 2.0 compliant driver written for the DirList server. This driver is primarily used with Microsoft Access, but can also be used from other ODBC client applications, such as SPSS. C++, Win32, Sockets, ODBC 12,671 1999-2000
PAM CueCat Module Turns the CueCat barcode scanner into a pluggable authentication module (PAM) library, permitting logins with bar code scans C, PAM, Linux, CueCat 285 2000
Home Control The project that marked my first significant work towards complete home and office automation systems C, Win32, Serial, CP290 2,270 1996,1998
ResNet Online I rewrote the old site for ease of use with more capabilities. Automatic port registration and heavy database integration saved the ResNet program a substantial amount of time while greatly improving customer/student satisfaction. PHP, SNMP, MySQL, PHPLib 4,572 1999-2001
FAT Recover Manual FAT filesystem recovery tool that I made to help with manual floppy disk recoveries and to salvage my dad's laptop when Windows totally crashed C, Linux 246 2000
Bryant PRIDE web site Web site for the Bryant PRIDE LGBT group. In the Fall of 1997, when I was a freshman at Bryant University, I greatly enhanced the web site with several pages and JavaScripts. This also included a JavaScript-driven background MIDI music jukebox in a pop-under, which was unique for a web site at that time. While I was the web site's maintainer, it moved from static HTML to ASP and then to PHP. JavaScript, PHP, VBScript, ASP 3,681 1997-2000
ActiveMail Provides SMTP email sending, POP3 email downloading, and FTP authentication services to ASP, Visual Basic, and other COM-consuming programs C++, COM, Win32, Visual Basic 4,691 1998-2000
CPU ID A very simple program that displays information about the CPU that it happens to execute on C, x86 Assembler, Win32 111 1999
Disk Imager Reads, writes, verifies, and erases entire disks into/from raw image files. This is similar in principle to rawrite.exe, but Disk Imager implements a graphical user interface. C, Win32 520 1998
EzMIDI32 A 32-bit version of the ScreenWindow+EasyMIDI libraries that I wrote for Grapevine High School C++, Win32 854 1998
LPD Written for the Grapevine-Colleyville Independent School District (GCISD) to allow employees to send AS/400 printouts to their local Windows printers. I wrote the piece that translates HP DeskJet 500 compatible instructions into a Windows GDI context. C, Win32 1,850 1996-1998
PortProxy TCP connection forwarding service that I wrote in college so that I could run servers from behind a firewall. When I put Linux onto, I no longer needed this program, but it's still cool if you are running Windows. I also wrote a version that runs as a system tray application in Windows 95. C, Win32, Sockets 1,461 1999
ScreenWindowX An ActiveX version of ScreenWindow that I created during the ActiveX hype. This gives Internet Explorer pages, COM clients, and .NET applications an easy-to-use text console user interface control. C++, COM, Win32, ActiveX 1,614 1998
KJMouse Busy cursor for Java that is similar to the launch feedback in KDE 2.2 Java, JNI, Win32, X11, Cocoa 736 2001-2004
CatSetup Scriptable install and uninstall utility for 16-bit Windows that I wrote in the mid-1990s to ease the distribution of my software. Most of my software from 1994 to 2000 used CatSetup. I eventually switched to using NSIS and, later, MAKEMSI. C, Win16 3,676 1994-1998
Trig Grapher Plots trigonometric functions in a window. This was my first multi-threaded Win32 program, which I wrote in high school for fun. I later back-ported it to Win16. C, Win32, Win16 1,441 1995-1996
256-Color SDK Library that I wrote a to easily manage 256-color bitmaps on 256-color displays C, Win16 704 1994
AudioCD Pictures Displays predefined pictures as a playing CD reaches predefined moments C, Win16 550 1994
BBS Ads Simply a program that can advertise bulletin board systems, when they used to be popular C, Win16 258 1993-1994
Bids-to-ASP Converts American Airlines bidsheet files into Procomm Plus for DOS ASPect scripts C, Win16 562 1994
Horses A fun horse racing strategy game for Windows C, Win16 3,348 1995,1997
KittyCat! Comm Bulletin board system (BBS) communications program with a dynamic data exchange (DDE) based application programming interface (API) and support for ANSI text and RIPscrip graphics. This was never finished due to the Internet and the World Wide Web making it obsolete. C, Win16 8,166 1994-1995
MCI SendString Allows users to work with the Microsoft Windows media control interface (MCI) with text rather than through pointing and clicking C, Win16 212 1994
MeowyMIDI A 1.0 sound font with cat meows and purrs for Sound Blaster AWE32 and AWE64 audio cards SoundFont, MIDI 0 1994-1995
PCL Page Manipulate PCL-compliant printers with this utility that works in both Win16 and DOS C, Win16, DOS 196 1995
ScreenWindow Text console and MIDI library for Win16 that I wrote so that students at Grapevine High School in first-year computer science class could use MIDI in their music projects using Borland's Turbo Pascal. When they switched to teaching C++, I made a 32-bit version of the library that used Win32's native console rather than my own. C++, C, Pascal, Win16, Win32, MIDI 2,953 1996-1997
AriesType A touch typing education program that I made while I was a freshman in high school. It tied into the local Novell NetWare network to be a multi-user application with different capabilities given to students, teachers, and system operators. AriesType also included basic local email and paging capabilities. QBASIC, DOS 4,364 1993-1994
IntMap A small image library that I wrote for a Pascal project in high school to provide image drawing, movement, and rotation operations in DOS Pascal, DOS, C 1,797 1995,1998
Jingle Bells A first-year computer science course project to visually and audibly play a traditional December holiday song, which I later ported to Windows using ScreenWindow Pascal, DOS, C, Win16, Win32, MIDI 611 1994,1996
SLOS-DOS A small interpreted toy operating environment written in BASIC for DOS. Programs are written in a trivial and limited scripting language. QBASIC, DOS 1,277 1993
SLOS-Win Windows version of SLOS, a small interpreted toy operating environment written in BASIC for DOS. Programs are written in a trivial and limited scripting language. C++, Win16 1,679 1993
TSNHead Kept track of how much time my brothers and I spent on The Sierra Network (TSN) QBASIC, DOS 291 1992
TrackTrek A track meet program that "keeps track" of events and allows others to view scores in realtime. This was my first Java program. This was more of a self-driven academic exercise as the project was never finished. Java, AWT 3,690 1996-1998
Thunderforce An open-source Mozilla Thunderbird extension for This project is now abandoned due to other priorities and interests. JavaScript, XPCOM, C++, XUL, Subversion, MediaWiki 5,411 2007-2009

Software and project contributions

I contributed to the following projects:

Name Description Technologies SLOC Year
Mozilla Workaround code for a shutdown bug in Firefox (bug 239223) and helped others find the cause of a NTLM authentication crash in a pre-Firefox build 156 2005
Samba Patch to allow the use of 32-bit user and group IDs in smbmnt 11 2004
Pan Contributed a small multi-threaded bugfix to a function that was crashing on several important dialog boxes in version 0.6.3 small 1999
PHP Contributed the snmpset() function to PHP 3.0.12 and PHP4 Beta2 so that ResNet Online could turn on the ResHall ports when students registered their computers C, Net-SNMP, CVS 172 1999
Spruce Contributed several small usability patches and a fix for a thread-based crash that brought down Spruce while checking messages in previous versions C, GLib threads, GTK+ 200 2000
Novell openSUSE Fixed bugs related to LVM on a USB boot drive and J-Pilot thinking that the username is always wrong on 64-bit platforms, and added a workaround for Bluetooth DUND issues. Full bug list. C small 2007-2008
Bryant University During the Spring of 1998, I enhanced Bryant's main page with rollovers and images. Other miscellaneous pages were also updated, and the DirList project was started originally as a web directory for Bryant. JavaScript, HTML small 1998-1999

Lines of code were computed using SLOCCount and, for extensions not supported by SLOCCount, find . -iname \*\\.js -print0 -or -iname \*\\.bs2 -print0 -or -iname \*\\.idl -print0 -or -iname \*\\.asp -print0 -or -iname \*\\.clp -print0 -or -iname \*\\.xul -print0 -or -iname \*\\.bas -print0 -or -iname \*\\.exc -print0| xargs -0 -Ixxx cat xxx| grep "[a-zA-Z0-9]"|wc -l. SLOC counts that relate to San Francisco AIDS Foundation software that has not been made open-source were computed during my final months of employment; Carnegie Mellon University asked for those numbers as part of the admission process. Generated code is excluded from the SLOC counts. With generated code, such as the Reggie/CIS code generated from idlj, the SLOC counts balloon significantly.

Employment History

  • Senior Member of the Technical Staff: Sites, Core Infrastructure, Security, and API Teams
  • January 2007 to present
  • Accomplishments
    • Brought attention to specific cross-site scripting (XSS) vulnerabilities by writing a Firefox Firebug extension that looked for improper string escaping in a test org that had been specially populated with attack strings by another tool and having quality engineers from every functional team test the system with the Firebug extension running. This led to the identification and resolution of a large number of vulnerabilities, thus making even more secure. A security research firm later commended's security, saying that they couldn't find any XSS or cross site request forgery (CSRF) vulnerabilities, despite looking for them over the course of several days.
    • Championed an improvement to an anti-phishing feature's design successfully, and that improvement is patent-pending
    • Resolved customer cases related to the application programming interface (API) and secure sockets layer (SSL), quickly becoming a go-to person for HTTPS and SSL
    • Improved an internal production testing tool's scheduling of tests by adding prerequisite expressions to increase test parallelization
    • Built the initial security testing framework for package access controls, which helped quickly bring that feature to market with confidence in its quality and security
    • Designed and began to implement a Thunderbird add-on for Thunderforce
    • Enhanced the user interface of, added Apache Ant build files to, significantly improved the configuration system of, and added multiple-window browser screenshots to an internal production testing tool that is used by multiple teams
    • Created and automated anti-phishing and security test scenarios
    • Automated HTTPS troubleshooting with an internal utility for support representatives that substantially reduced the number of escalated HTTPS cases
    • Ensured that new releases of the core product did not break older API versions through gold files and automated testing
    • Established a methodology for determining equivalence partition coverage in the test cases for the object query language (SOQL)
    • Assisted developers and quality engineers with installing and maintaining Novell openSUSE Linux on their primary desktops

San Francisco AIDS Foundation

  • Database Administrator and Software Engineer
  • September 2000 to July 2005
  • Accomplishments
    • Maintained a large 200-user multi-tenant three-tiered system used by all Ryan White CARE-funded AIDS service organizations in San Francisco in collaboration with the Department of Public Health AIDS Office of San Francisco and two direct partners. That involved all aspects of the software development lifecycle as well as server and client deployments, network maintenance, and top-tier user support.
    • Gathered requirements for new features collaboratively with stakeholders, designed those features, coded them, tested them, and deployed them
    • Assisted the other database administrator with the foundation's customized customer relationship management (CRM) and donor relationship management systems
    • Implemented large parts of the data conversion and customization of the Foundation's purchased donor relationship management system
    • Secured the Internet-facing presence of the donor relationship management system using a locked-down Apache configuration and strict URL regular expressions
    • Obviated a need for Crystal Reports by implementing web-based PDF reports using Microsoft Access, a customized PHP build to run as a COM server, and a custom-built COM object for use by ASP on the reporting server, saving a significant amount of money
    • Migrated client operating system data during the Windows XP transition using a multi-platform profile migration tool that I wrote
    • Planned, deployed, and provided training for Mozilla Firefox as the default web browser to all foundation users and created IE URL Lock for business-related sites that only worked in Internet Explorer
    • Evaluated, purchased, and managed the licenses of software related to Reggie/CIS
    • Maintained the Cisco network equipment, including the PIX firewall's access control lists (ACLs) and routers' virtual local area network (VLAN) ACLs
    • Cut unsolicited commercial email (UCE or SPAM) drastically and added virtual private networking (VPN) using Astaro Secure Linux (ASL) in the demilitarized zone (DMZ) behing the Cisco PIX firewall
    • Administered databases, servers, and the organization's backup system


  • Intranet Developer
  • May 1999 to August 1999 and May 2000 to July 2000
  • Accomplishments
    • Developed specifications for a statistical employee rating system to help Ariesnet move towards building teams of virtual at−home employees
    • Helped Ariesnet build their secure intranet system using PHP and MySQL
    • Administered the intranet system's Linux server as well as the development test server using the CVS versioning software

Bryant University

  • ResNet Consultant
    • January 1999 to May 2000
    • Accomplishments
      • Shortened residence hall computer registration port activation turnaround times from two weeks to one second with a custom-written Linux-based PHP web site
      • Provided in-person network and computer support to students living in the university's residence halls
  • Internet Developer
    • January 1998 to May 1998 and September 1998 to May 1999
    • Accomplishments
      • Implemented the university’s first web-based faculty and student directory using the common gateway interface (CGI)
      • Wrote an ODBC driver and Microsoft Access database for its administration. This lives on as the DirList2 open-source project

Grapevine-Colleyville Independent School District

  • Student Intern
  • January 1996 to August 1997
  • Accomplishments
    • Provided hardware and software support, winning an employee award for exceptional service
    • Worked with wide-area network configurations
    • Wrote a networked printer driver to save thousands of dollars in licenses by allowing printing from their AS/400s to local printers

Education and Training

Carnegie Mellon University

  • Master of Software Engineering, Institute of Software Research
  • Pittsburgh, Pennsylvania
  • Graduation: December 2006
  • Masters group project: Bosch Security Configuration Assistant, which is an Eclipse-based application that generates three-dimensional security plans for buildings using the Jess rule engine and three-dimensional visualization
  • Project roles: Technology support manager and, via rotation, planning manager, software process manager, project risk manager, and quality manager
  • Focus areas studied: Fault tolerant, distributed, real-time systems; software project management; formal models and analysis of software systems; software architecture; and software requirements elicitation methods
  • Accomplishments
    • As a team, we met and exceeded our client's original picture of success by the end of the project's one-year time frame.
    • I reduced the status meeting data collection time to less than 30 minutes through automation and used historical data to reduce our estimation error.
    • As the support manager, I kept our RedHat Fedora Core server and software available, secure, usable, and backed up using only one hour per week of my time on average throughout the project.
  • Quality point average: Graduated with 4.03 out of 4.00, which is a weighted grade point average (GPA), due to earning several A+ grades

Bryant University