Steven Lawrance
Welcome to the web site of Steven Lawrance, master of software engineering (MSE). I enjoy building complete computing solutions at all levels of abstraction to automate business processes at a low cost, in a short time frame, and with high quality. Put my experience, interests, training, and expertise to work for you. Please feel free to contact me today.
Résumé: Portable document format (PDF)
Please feel free to ask me for more information about any project listed on this page.
Software Project Experience
Team software
I materially participated in the team software projects listed below:
| Name | Description | Technologies | SLOC | Year | 
|---|---|---|---|---|
| Salesforce.com | Web-based business software platform and suite of integrated business applications. For Salesforce.com, I wrote a cross site scripting Firefox/Firebug extension to test proper output escaping in the manual and automated tests, improved an internal production testing tool's scheduling of tests by adding prerequisite expressions to increase test parallelization, built a security testing framework for package access controls, enhanced an internal production server testing tool's user interface and configuration system, helped resolve customer cases related to using the application programming interface (API) with TLS and SSL security, and ensured that new releases of the core product did not break older API versions. I also ensured that the software produced by my teams functioned properly through automated and manual testing. | Java, Apache Ant, JUnit, Force.com, Resin, JSP, Servlets | large | 2007-2009 | 
| Reggie/CIS | A 200-user multi-tenant three-tiered HIV/AIDS client database system that was used by all Ryan White Foundation CARE-funded AIDS service organizations in San Francisco in collaboration with the San Francisco Department of Public Health (DPH) AIDS Office and two partners to the San Francisco AIDS Foundation (SFAF), where I worked for about five years. I actively maintained this system with a colleague at the DPH AIDS Office and was principally responsible for maintaining the "CIS" portion of Reggie/CIS, which extended the Reggie platform with extra features that the SFAF and two other organizations used. | Java, VBScript, Swing, T-SQL, MS SQL Server, CVS, JavaScript, C, JNI, CORBA, IIS, COM, Win32 | 162,005 | 2000-2005 | 
| DonorPerfect Online | Donor and fundraising event management system used by the San Francisco AIDS Foundation. I migrated AIDS/LifeCycle data from a Goldmine database to the San Francisco AIDS Foundation's customized DonorPerfect Online system using a test-driven development process for the SQL scripts. I also contributed substantially to the bulk data entry wizard, fixed bugs throughout the system, including security holes, made all pages and JavaScripts operate properly in Mozilla Firefox, and implemented strict URL filtering security using an Apache reverse-proxy and mod_rewrite. | VBScript, T-SQL, MS SQL Server, JavaScript, Apache HTTP Server, IIS, CVS | 97,592 | 2004-2005 | 
| SFAF CRM | Customer relationship management system that was implemented by a colleague at the San Francisco AIDS Foundation that primarily serves the organization's volunteer based programs department, automates expense reports, and runs the California AIDS Hotline. I enhanced the deployment system using CVS in a web-based front-end, helped my colleague fix various bugs, and enhanced its Internet-facing security with an Apache reverse-proxy and mod_rewrite. | VBScript, T-SQL, MS SQL Server, JavaScript, Apache HTTP Server, IIS, CVS | 69,015 | 2001-2005 | 
| Bosch Security Configuration Assistant | An Eclipse-based application that generates three-dimensional security plans for buildings using a rule engine and three-dimensional visualization. In this project, I integrated a Windows-based three-dimensional visualization program into an Eclipse view, kept our RedHat Fedora Core server and software available, secure, usable, and backed up using only one hour per week of my time on average throughout the project, and automated our data collection and reporting processes to minimize project overhead work. This group project involved four other students -- two whom also work at Salesforce.com -- and served as a laboratory for us to directly apply coursework to a software project with a real client throughout our software engineering masters' programs. | Java, Eclipse, UML, Apache Ant, Bugzilla, CruiseControl, MediaWiki, Subversion, SWT, C++, JNI, Win32 | 21,274 | 2005-2006 | 
| Park 'N Park | A fault-tolerant, distributed, real-time three-tiered application for tracking parking garage usage. This was an academic project. | Java, CORBA, MySQL, CVS | 2,027 | 2006 | 
| Teacher's Pet | Shares a tab in your Mozilla Firefox browser with one or more remote browsers, which can be useful in virtual classroom environments. | JavaScript, Java, XUL, XPCOM, Subversion | 1,251 | 2006 | 
| Hulk | Physically navigates a maze using a customized Parallax Boe-Bot. This project involved both custom hardware and custom software as well as trade-offs between the two when implementing features. | Parallax BASIC Stamp, Parallax Boe-Bot, Subversion | 784 | 2006 | 
| URL Lock | Follow-up project to IE URL Lock that sports a configuration user interface and implements new ideas for visually disabling content on the web. | JavaScript, XUL, C++, XPCOM, Win32, Subversion | 3,868 | 2006 | 
| Ariesbase | Intranet system for Ariesnet, Inc. During the Summer of 1999, I mostly helped out with the back-end functionality, such as the security system and global includes, and I also created a high-level specification for an employee rating system for virtual team environments. | PHP, MySQL, JavaScript, CVS | medium | 1999-2000 | 
Software that I created
I wrote and maintain the following software:
| Name | Description | Technologies | SLOC | Year | 
|---|---|---|---|---|
| Home Profiler | Synchronizes user profile data between multiple desktop computers, regardless of the operating system. This was used at the San Francisco AIDS Foundation to migrate user profile data from Windows NT to Windows XP while leaving malware and spyware behind | Java, C, JNI, JACOB, COM, Win32, CVS | 5,679 | 2005 | 
| IE URL Lock | A browser helper object (BHO) that prevents users from navigating to web sites in Internet Explorer and Windows Explorer while permitting URLs that match a Perl-compatible regular expression stored in the registry | C++, COM, BHO, Win32, Subversion | 1,105 | 2005-2006 | 
| Backup system | Multi-platform, SSH-secured, Internet-based incremental backup system that I assembled and use to back up all computers that I manage | Unison, Apache HTTP Server, OpenSSH | 2005-2007 | |
| Read-only filesystem | FUSE filesystem view that makes all files unconditionally read-only. I use this in my backup system for the web-based file restore interface | C, FUSE | 241 | 2005-2007 | 
| Serendipity Time Tracking Tool | A two-tier software team time tracking tool used by Team Serendipity while designing and building the Bosch Security Configuration Assistant. It was rapidly developed using Microsoft Access 2003 as the front-end user interface, MySQL 5 as the back-end database, and SSH as the MySQL connection tunnel | VBA, Microsoft Access, MySQL, OpenSSH | small | 2006 | 
| GnuCash to QIF | Converts a GnuCash XML file into a QIF file | Java, Apache Xerces | 2,274 | 2002-2007 | 
| PDF Access Reports | Web-based PDF reports using Microsoft Access, a customized PHP build to run as a COM server, and a custom-built COM object for use by ASP on the reporting server. This was a component of Reggie/CIS's reporting system | PHP, COM, C++, Sockets, VBA, ASP, Microsoft Access | 651 | 2002-2005 | 
| PDFFile and InvokeAsUser | Enables easy portable document format (PDF) file generation on Windows computers when used with AFPL GhostScript and RedMon | C, Win32 | 396 | 2005 | 
| SFAF VPN Client | Connects a Microsoft Windows 2000 or XP computer to the San Francisco AIDS Foundation's virtual private network (VPN) by using the built-in IPsec and PPTP capabilities in Windows. Each client computer is secured with a machine-unique public/private key, and users are authenticated against the NT domain using PPTP over the IPsec connection | C, Win32, Java, Swing, CVS | 2,623 | 2003-2005 | 
| Door Lock | Specification (not an implementation) of a secure residential door real-time, embedded software system that uses electronic locks, secure entry, easy exiting, and alarm state awareness to securely and efficiently manage a door | Parallax Javelin | 0 | 2006 | 
| Swing Inline Spell Checker | Inline spell checker that plugs into Swing's look-and-feel system. This was used in Reggie/CIS as its distributed spell checker with GNU Aspell running on the server | Java, Swing, CORBA, GNU Aspell | 2,859 | 2002-2005 | 
| DirList | User directory system that runs as a CGI to serve up user lists, search, and synchronize with the operating system's user database. When used with DirList2ODBC, the ODBC driver that I wrote for DirList2, the entire DirList2 system becomes a structured query language (SQL)-compliant database system within the limits of the DirList2 Server. This project began in January of 1998 and is actively patched for any security issues that arise. Bryant University continues to use this program for their student web site list | C++, C, Sockets, ODBC, Linux, Win32, VBA, Microsoft Access | 8,268 | 1999-2007 | 
| DirList2ODBC | ODBC 2.0 compliant driver written for the DirList server. This driver is primarily used with Microsoft Access, but can also be used from other ODBC client applications, such as SPSS | C++, Win32, Sockets, ODBC | 12,671 | 1999-2000 | 
| PAM CueCat Module | Turns the CueCat barcode scanner into a pluggable authentication module (PAM) library, permitting logins with bar code scans | C, PAM, Linux, CueCat | 285 | 2000 | 
| Home Control | The project that marked my first significant work towards complete home and office automation systems | C, Win32, Serial, CP290 | 2,270 | 1996,1998 | 
| ResNet Online | I rewrote the old site for ease of use with more capabilities. Automatic port registration and heavy database integration saved the ResNet program a substantial amount of time while greatly improving customer/student satisfaction | PHP, SNMP, MySQL, PHPLib | 4,572 | 1999-2001 | 
| FAT Recover | Manual FAT filesystem recovery tool that I made to help with manual floppy disk recoveries and to salvage my dad's laptop when Windows totally crashed | C, Linux | 246 | 2000 | 
| Bryant PRIDE web site | In the Fall of 1997, when I was a freshman at Bryant University, I greatly enhanced Bryant PRIDE's site with several pages and JavaScripts. This also included a JavaScript-driven background MIDI music jukebox in a pop-under, which was unique for a web site at that time. While I was the web site's maintainer, it moved from static HTML to ASP and then to PHP | JavaScript, PHP, VBScript, ASP | 3,681 | 1997-2000 | 
| ActiveMail | Provides SMTP email sending, POP3 email downloading, and FTP authentication services to ASP, Visual Basic, and other COM-consuming programs | C++, COM, Win32, Visual Basic | 4,691 | 1998-2000 | 
| CPU ID | A very simple program that displays information about the CPU that it happens to execute on | C, x86 Assembler, Win32 | 111 | 1999 | 
| Disk Imager | Reads, writes, verifies, and erases entire disks into/from raw image files. This is similar in principle to rawrite.exe, but Disk Imager implements a graphical user interface | C, Win32 | 520 | 1998 | 
| EzMIDI32 | A 32-bit version of the ScreenWindow+EasyMIDI libraries that I wrote for Grapevine High School | C++, Win32 | 854 | 1998 | 
| LPD | Written for the Grapevine-Colleyville Independent School District (GCISD) to allow employees to send AS/400 printouts to their local Windows printers. I wrote the piece that translates HP DeskJet 500 compatible instructions into a Windows GDI context | C, Win32 | 1,850 | 1996-1998 | 
| PortProxy | TCP connection forwarding service that I wrote in college so that I could run servers from behind a firewall. When I put Linux onto resnet.bryant.edu, I no longer needed this program, but it's still cool if you are running Windows. I also wrote a version that runs as a system tray application in Windows 95 | C, Win32, Sockets | 1,461 | 1999 | 
| ScreenWindowX | An ActiveX version of ScreenWindow that I created during the ActiveX hype. This gives Internet Explorer pages, COM clients, and .NET applications an easy-to-use text console user interface control | C++, COM, Win32, ActiveX | 1,614 | 1998 | 
| KJMouse | Busy cursor for Java that is similar to the launch feedback in KDE 2.2 | Java, JNI, Win32, X11, Cocoa | 736 | 2001-2004 | 
| CatSetup | Scriptable install and uninstall utility for 16-bit Windows that I wrote in the mid-1990s to ease the distribution of my software. Most of my software from 1994 to 2000 used CatSetup. I eventually switched to using NSIS and, later, MAKEMSI | C, Win16 | 3,676 | 1994-1998 | 
| Trig Grapher | Plots trigonometric functions in a window. This was my first multi-threaded Win32 program, which I wrote in high school for fun. I later back-ported it to Win16 | C, Win32, Win16 | 1,441 | 1995-1996 | 
| 256-Color SDK | Library that I wrote a to easily manage 256-color bitmaps on 256-color displays | C, Win16 | 704 | 1994 | 
| AudioCD Pictures | Displays predefined pictures as a playing CD reaches predefined moments | C, Win16 | 550 | 1994 | 
| BBS Ads | Simply a program that can advertise bulletin board systems, when they used to be popular | C, Win16 | 258 | 1993-1994 | 
| Bids-to-ASP | Converts American Airlines bidsheet files into Procomm Plus for DOS ASPect scripts | C, Win16 | 562 | 1994 | 
| Horses | A fun horse racing strategy game for Windows | C, Win16 | 3,348 | 1995,1997 | 
| KittyCat! Comm | Bulletin board system (BBS) communications program with a dynamic data exchange (DDE) based application programming interface (API) and support for ANSI text and RIPscrip graphics. This was never finished due to the Internet and the World Wide Web making it obsolete | C, Win16 | 8,166 | 1994-1995 | 
| MCI SendString | Allows users to work with the Microsoft Windows media control interface (MCI) with text rather than through pointing and clicking | C, Win16 | 212 | 1994 | 
| MeowyMIDI | A 1.0 sound font with cat meows and purrs for Sound Blaster AWE32 and AWE64 audio cards | SoundFont, MIDI | 0 | 1994-1995 | 
| PCL Page | Manipulate PCL-compliant printers with this utility that works in both Win16 and DOS | C, Win16, DOS | 196 | 1995 | 
| ScreenWindow | Text console and MIDI library for Win16 that I wrote so that students at Grapevine High School in first-year computer science class could use MIDI in their music projects using Borland's Turbo Pascal. When they switched to teaching C++, I made a 32-bit version of the library that used Win32's native console rather than my own | C++, C, Pascal, Win16, Win32, MIDI | 2,953 | 1996-1997 | 
| AriesType | A touch typing education program that I made while I was a freshman in high school. It tied into the local Novell NetWare network to be a multi-user application with different capabilities given to students, teachers, and system operators. AriesType also included basic local email and paging capabilities | QBASIC, DOS | 4,364 | 1993-1994 | 
| IntMap | A small image library that I wrote for a Pascal project in high school to provide image drawing, movement, and rotation operations in DOS | Pascal, DOS, C | 1,797 | 1995,1998 | 
| Jingle Bells | A first-year computer science course project to visually and audibly play a traditional December holiday song, which I later ported to Windows using ScreenWindow | Pascal, DOS, C, Win16, Win32, MIDI | 611 | 1994,1996 | 
| SLOS-DOS | A small interpreted toy operating environment written in BASIC for DOS. Programs are written in a trivial and limited scripting language | QBASIC, DOS | 1,277 | 1993 | 
| SLOS-Win | Windows version of SLOS, a small interpreted toy operating environment written in BASIC for DOS. Programs are written in a trivial and limited scripting language | C++, Win16 | 1,679 | 1993 | 
| TSNHead | Kept track of how much time my brothers and I spent on The Sierra Network (TSN) | QBASIC, DOS | 291 | 1992 | 
| TrackTrek | A track meet program that "keeps track" of events and allows others to view scores in realtime. This was my first Java program. This was more of a self-driven academic exercise as the project was never finished | Java, AWT | 3,690 | 1996-1998 | 
| Thunderforce | An open-source Mozilla Thunderbird extension for Salesforce.com. This project is now abandoned due to other priorities and interests. | JavaScript, XPCOM, C++, XUL, Subversion, MediaWiki | 5,411 | 2007-2009 | 
Software and project contributions
I contributed to the following projects:
| Name | Description | Technologies | SLOC | Year | 
|---|---|---|---|---|
| Mozilla | Workaround code for a shutdown bug in Firefox (bug 239223) and helped others find the cause of a NTLM authentication crash in a pre-Firefox build | 156 | 2005 | |
| Samba | Patch to allow the use of 32-bit user and group IDs in smbmnt | 11 | 2004 | |
| Pan | Contributed a small multi-threaded bugfix to a function that was crashing on several important dialog boxes in version 0.6.3 | small | 1999 | |
| PHP | Contributed the snmpset() function to PHP 3.0.12 and PHP4 Beta2 so that ResNet Online could turn on the ResHall ports when students registered their computers | C, Net-SNMP, CVS | 172 | 1999 | 
| Spruce | Contributed several small usability patches and a fix for a thread-based crash that brought down Spruce while checking messages in previous versions | C, GLib threads, GTK+ | 200 | 2000 | 
| Novell openSUSE | Fixed bugs related to LVM on a USB boot drive and J-Pilot thinking that the username is always wrong on 64-bit platforms, and added a workaround for Bluetooth DUND issues. Full bug list | C | small | 2007-2008 | 
| Bryant University | During the Spring of 1998, I enhanced Bryant's main page with rollovers and images. Other miscellaneous pages were also updated, and the DirList project was started originally as a web directory for Bryant | JavaScript, HTML | small | 1998-1999 | 
Lines of code were computed using SLOCCount and, for extensions not supported by SLOCCount, find . -iname \*\\.js -print0 -or -iname \*\\.bs2 -print0 -or -iname \*\\.idl -print0 -or -iname \*\\.asp -print0 -or -iname \*\\.clp -print0 -or -iname \*\\.xul -print0 -or -iname \*\\.bas -print0 -or -iname \*\\.exc -print0| xargs -0 -Ixxx cat xxx| grep "[a-zA-Z0-9]"|wc -l. SLOC counts that relate to San Francisco AIDS Foundation software that has not been made open-source were computed during my final months of employment; Carnegie Mellon University asked for those numbers as part of the admission process. Generated code is excluded from the SLOC counts. With generated code, such as the Reggie/CIS code generated from idlj, the SLOC counts balloon substantially.
Employment History
Salesforce.com
- Senior Member of the Technical Staff: Core Infrastructure, Security, and API Teams
- January 2007 to present
- Accomplishments
- Brought attention to specific cross-site scripting (XSS) vulnerabilities by writing a Firefox Firebug extension that looked for improper string escaping in a test org that had been specially populated with attack strings by another tool and having quality engineers from every functional team test the system with the Firebug extension running. This led to the identification and resolution of a large number of vulnerabilities, thus making Salesforce.com even more secure
- Improved an internal production testing tool's scheduling of tests by adding prerequisite expressions to ultimately increase test parallelization
- Built the initial security testing framework for package access controls
- Tracked down and, in some cases, fixed difficult threading and cache related bugs
- Championed an improvement to an anti-phishing feature's design successfully, and that improvement is patent-pending
- Designed and began to implement a Thunderbird add-on for Salesforce.com: Thunderforce
- Enhanced the user interface and added Apache Ant build files to an internal production testing tool
- Created and automated anti-phishing and security test scenarios
- Resolved customer cases related to the application programming interface (API) and secure sockets layer (SSL), quickly becoming the go-to person for HTTPS and SSL
- Automated HTTPS troubleshooting with an internal utility for support representatives that substantially reduced the number of escalated HTTPS cases
- Ensured that new releases of the core product did not break older API versions through gold files and automated testing
- Established a methodology for determining equivalence partition coverage in the test cases for the Salesforce.com object query language (SOQL)
- Assisted developers and quality engineers with installing and maintaining Novell openSUSE Linux on their primary desktops
 
San Francisco AIDS Foundation
- Database Administrator and Software Engineer
- September 2000 to July 2005
- Accomplishments
- Maintained a large 200-user multi-tenant three-tiered system used by all Ryan White CARE-funded AIDS service organizations in San Francisco in collaboration with the Department of Public Health AIDS Office of San Francisco and two direct partners. That involved all aspects of the software development lifecycle as well as server and client deployments, network maintenance, and top-tier user support
- Gathered requirements for new features collaboratively with stakeholders, designed those features, coded them, tested them, and deployed them
- Assisted the other database administrator with the foundation's customized customer relationship management (CRM) and donor relationship management systems
- Implemented large parts of the data conversion and customization of the Foundation's purchased donor relationship management system
- Secured the Internet-facing presence of the donor relationship management system using a locked-down Apache configuration and strict URL regular expressions
- Obviated a need for Crystal Reports by implementing web-based PDF reports using Microsoft Access, a customized PHP build to run as a COM server, and a custom-built COM object for use by ASP on the reporting server, saving a significant amount of money
- Migrated client operating system data during the Windows XP transition using a multi-platform profile migration tool that I wrote
- Planned, deployed, and provided training for Mozilla Firefox as the default web browser to all foundation users and created IE URL Lock for business-related sites that only worked in Internet Explorer
- Evaluated, purchased, and managed the licenses of software related to Reggie/CIS
- Maintained the Cisco network equipment, including the PIX firewall's access control lists (ACLs) and routers' virtual local area network (VLAN) ACLs
- Cut unsolicited commercial email (UCE or SPAM) drastically and added virtual private networking (VPN) using Astaro Secure Linux (ASL) in the demilitarized zone (DMZ) behing the Cisco PIX firewall
- Administered databases, servers, and the organization's backup system
 
Ariesnet
- Intranet Developer
- May 1999 to August 1999 and May 2000 to July 2000
- Accomplishments
- Developed specifications for a statistical employee rating system to help Ariesnet move towards building teams of virtual at−home employees
- Helped Ariesnet build their secure intranet system using PHP and MySQL
- Administered the intranet system's Linux server as well as the development test server using the CVS versioning software
 
Bryant University
- ResNet Consultant
- January 1999 to May 2000
- Accomplishments
- Shortened residence hall computer registration port activation turnaround times from two weeks to one second with a custom-written Linux-based PHP web site
- Provided in-person network and computer support to students living in the university's residence halls
 
 
- Internet Developer
- January 1998 to May 1998 and September 1998 to May 1999
- Accomplishments
- Implemented the university’s first web-based faculty and student directory using the common gateway interface (CGI)
- Wrote an ODBC driver and Microsoft Access database for its administration. This lives on as the DirList2 open-source project
 
 
Grapevine-Colleyville Independent School District
- Student Intern
- January 1996 to August 1997
- Accomplishments
- Provided hardware and software support, winning an employee award for exceptional service
- Worked with wide-area network configurations
- Wrote a networked printer driver to save thousands of dollars in licenses by allowing printing from their AS/400s to local printers
 
Education and Training
Carnegie Mellon University
- Master of Software Engineering, Institute of Software Research
- Pittsburgh, Pennsylvania
- Graduation: December 2006
- Masters group project: Bosch Security Configuration Assistant, which is an Eclipse-based application that generates three-dimensional security plans for buildings using the Jess rule engine and three-dimensional visualization
- Project roles: Technology support manager, planning manager, software process manager, project risk manager, and quality manager
- Focus areas studied: Fault tolerant, distributed, real-time systems; software project management; formal models and analysis of software systems; software architecture; and software requirements elicitation methods
- Accomplishments
- As a team, we met and exceeded our client's original picture of success by the end of the project's one-year time frame
- I reduced the status meeting data collection time to less than 30 minutes through automation and used historical data to reduce our estimation error
- As the support manager, I kept our RedHat Fedora Core server and software available, secure, usable, and backed up using only one hour per week of my time on average throughout the project
 
- Quality point average: Graduated with 4.03 out of 4.00, which is a weighted grade point average (GPA), due to earning several A+ grades
Bryant University
- Bachelor of Science in Business Administration
- Smithfield, Rhode Island
- Graduation: May 2000
- AACSB Accredited
- Focus areas studied: Computer information systems with a minor in applied business statistics
- Grade point average: Graduated summa cum laude with a GPA of 3.96 out of 4.00
- Leadership: Served as president of Bryant PRIDE for more than a year and conducted a Linux installation event
Certification
- RedHat Certified Engineer (RHCE for 6.2): 806200565301847