2006/08/10
台灣產的Google人,迷人的公司才能留住一流人才
Google日前公布了二○○六年第二季的財報,營收高達二十四億六千萬美元,較去年同期增長了七七%,而七億二千一百萬美元的稅後淨利(net profit),更較去年同期的三億四千三百萬,增加超過一倍。又一次,Google打破預期,讓它的投資人笑得闔不攏嘴,Google證明了它讓所有公司望其項背的成長動能。
專家們分析,Google的成長來自於新產品與跨國服務的推廣。為了配合持續飆升的成長速度,Google的組織也像吹氣球般持續膨脹。根據Google向美國證管會提交的文件(SEC filings),從二○○一年底至二○○五年底,Google的員工成長了二一八四%,來到了五千六百八十名員工。甚至有人分析,Google每個員工的產值高達一千九百萬美元的天價。
過去幾年,Google持續向業界挖角,包括亞馬遜(Amazon)A9搜尋公司執行長曼博(Udi Manber)、微軟中國區總裁李開復、eBay先進開發技術總監莫尼耶(Louise Monier)等電腦、網路大老紛紛投效Google,但台面上的不過是冰山一角,有更多不願具名的優秀菁英持續向這個人才磁鐵靠攏。
如同《搜尋引擎觀察報》作者蘇利文(Danny Sullivan)所說,Google「用天才吸引天才」(Talent Attracts Talent)的求才策略的確奏效,但衍生的另一個問題就是,Google到底是用何種能力,讓如此多天才與菁英甘願留在Google持續效命?
獨特企業文化是致命魅力
分析家們這個問題的答案或許各有不同。優渥的「員工福利」早隨著Google公司內的照片,流傳各方,但是Google融入自由精神的創新制度卻也絕對會在他們的列表上。
首先,每個人可用二○%的時間,從事自己喜歡的工作。光是這一點,就是讓許多優秀人才難以抗拒的誘因。在專案透明化的Google,所有進行中的專案,都可讓工程師自行挑選。選不到?還可以自行另外開發,做自己喜歡做的事,當然動力十足。
其次,民主開放的風氣深獲員工喜愛。除了用人需要經過「過五關、斬六將」式的密集面試,任何人都無法徇私雇用自己人之外,每年的年度考核與內部晉升也都會交由「同儕考評」(peer review)決定,讓所有人經由同儕的良性競爭,一同成長。
最後,在Google的辦公室裡,沒有絕對的上下關係,不僅員工要對主管負責,主管也有義務對員工負責,這樣的概念表現在每週一次的員工大會上,即使是布林(Sergey Brin)與佩吉(Larry Page),也一樣要接受員工最直接的對話與質詢,至今如此。
這是制度的部分,但還有更多「文化」與「氛圍」因素讓工程師們深深吸引,其中Google環境的「多元」、「社群」與「持續學習」,更是在Google工作的無形資產。
1.好動型工程師——王普澤:永遠都有新鮮的任務,等著你挑戰
隨著Google服務的拓展與飆升成長的搜尋業務,「多元」成為在Google工作的一大特色,對喜歡求新、求變,熱愛挑戰與冒險的人來說,永遠都有新鮮事的Google,是他們實戰夢想的最佳園地。
六十四年次的王普澤,是個思想跳躍、興趣廣泛的工程師,受不了一成不變的生活與工作,「興趣」至上的他,待超過一年的工作屈指可數,一沒了新鮮感就想跳槽的個性,若要讓他緊緊地「黏」在同一個公司或專案,幾乎是不可能的任務。然而,Google卻做到了!
算算王普澤進入Google的時間,時光飛逝已經超過兩年,但王普澤還是覺得這份工作很新鮮。從小就是台灣、美國兩頭跑的他,養成了對變動環境的狂熱,或許這種性格的他,不適合生存在組織嚴密、層層關卡的大企業中,但卻恰恰好能夠融入Google。
在Google這個以倍數成長的公司裡,工程師一方面得處理多元、多變的各式專案,另一方面還得追趕日新月異的網路大環境及日益複雜的使用者搜尋習慣,這一切都是「變、變、變」,別人眼中的大難題,對王普澤來說,可是如魚得水的絕佳工作。「這裡的方向很多,事情永遠做不完,我還沒想要換工作,」一臉的滿意與愉悅。
然而,最讓王普澤津津樂道的,就是Google處理緊急問題的「War Room」(戰爭室),這是一個機動性的緊急單位,只有在遇上了迫切的問題,才會召集相關人員進入War Room即時應變,但置身其中的精神與時間壓力,也不言可喻。
對於這種團體戰鬥式的緊急狀況,一般人總是避之唯恐不及,但王普澤卻甘之如飴。他認為從War Room也可看到Google對於工程師的無限支援:「我很佩服他們願意把很多重要的人放在一起、解決問題,而且公司也願意提供資源,幫助大家解決問題,這是其他公司所不能做到的。」
2.天才型工程師——翟本喬:在這裡每個天才都會和夥伴互動
翟本喬小學二年級跳念四年級,成為台灣首開紀錄的跳級生,高中畢業直接保送台大數學系,大學時就設計出讓老外都佩服的交通控制機制。充滿好奇心、又酷愛知識的翟本喬,與一般人對Google的印象十分吻合——十足的天才。
談到在Google工作的魅力,十個中有八個Google人直覺的回答都是「人」。各路英雄好漢集結而成的Google工作團隊,每個人都蘊藏了各種令人驚喜的可能性,激盪出來的不僅是一個個令人驚嘆的創意,更是社群凝結的最佳原點。
自認只是鬼點子多、充滿好奇心、又酷愛知識的翟本喬,與一般人對Google的印象十分吻合——十足的天才。
大學時代的翟本喬就已經參與核三廠人員輻射管理系統與台南市交通號誌管理系統,當時他用陽春的Z80電腦,完成國外動輒花費數千萬元的城市交通儀控機制,連國外團隊也來台觀摩。即使是今天,翟本喬在交通號誌上的貢獻仍在,台灣大街小巷的S型測速儀,就是出自翟本喬之手,而且別忘了,那時他還只是個大學生!
一路上學、經歷顯赫的翟本喬,研究所畢業後進入了美國貝爾研究室,但最後他也輾轉進入
Google,為什麼?
實驗室裡的電腦宗師派克(Rod Pike)離職了,前往一個搜尋功能做得不錯的公司——Google,面對工作上接踵而來的不快,翟本喬向前輩打聽起近況,「這裡很好玩,不過離職時我跟公司有協議,不能挖角,你想過來,就自己申請吧,」翟本喬愈聽愈對這個公司心動,經過八人大軍的面談,翟本喬進入Google。
說起Google工作最有趣的部分,翟本喬首推這裡的「人」:大師、頑童、各領域頂尖專家,翟本喬在充滿「菁英」、「天才」的團隊裡如沐春風。
其實令翟本喬感到興奮的,不是天才間的菁英式對話,而是令人驚喜萬分的無限互動可能:「原來那個東西是你發明的!」、「原來你有飛機駕照?」、「原來你之前是空軍情報官?」這類對話常常出現在人與人的談話之中。
在Google的社群裡,永遠都有可能被其他人的靈光一閃,激發出更多的創新概念。在這裡,翟本喬不再是唯一的特例,反而更悠遊於一群老頑童之間的遊戲兼工作,與漫無邊際馳騁想像。
2006/06/28
台北好吃炭烤店 - 一心堂
第一次去時沒啥概念,那時還是烤肉吃到飽,跟老友兩隻大肚吃了最少十幾盤牛五花,從此也愛上了燒烤店。
約200度的炭火熱烤不到一分鐘,翻個面涮一下火,六分熟的牛五花就可以享用啦。看看那均勻的油花,不用說就知道入口時的那種幸福的甜味啦。
全台比來比去,還是這條巷子的最好吃,尤其推薦一心堂這家比較沒名氣的小店。服務好、東西讚,依照我自己的實際經驗,對面那家人人皆知、更有名的店真的是遜掉囉。
每次去一心堂大惦燒烤後,沒啥好說,就是一個爽字可以形容。吃的還是台灣好...
btw, 走回林森公園地下停車場,新生北路上那家新開的黑糖冰店也超讚喔 - 解油剛剛好。
2006/05/26
台中香蕉新樂園
台中香蕉新樂園這家茶館和餐廳 (http://www.vernaldew.com.tw/) 是台中市近來很少見最特別的店家之一,這整棟大型的建築物裡面包含了將60年至80年前的街道重新造景在裡面,有清朝及日據時代的店面,還有其中一位股東收集的數百件古董,包括了老舊的信箱、路牌、海報、四十年的計程車、腳踏車、相片以及設備齊全的寫真館、牙醫診所、甘仔店、理髮店、及電影院。
大約有250個座位可提供顧客沿著這條街道或店面內享用多樣的台式套餐像是牛肉飯、東坡肉飯等,約180元,還有其他的點心及餐點。也提供一般的冰熱各式茶、咖啡、飲料,另外還有四至十人座的包廂。台灣香蕉新樂園人文生活館離孔廟很近,就在對面。
2006/05/04
情感的設計
這幾年來,設計變成了一門顯學。不論是哪個產業,都開始強調設計的重要性。
看看這期IDEO公司的這篇文章,你會發現,設計絕對不像我們刻板印象中所想的一樣,只是視覺或美感的層次而已。
對全球設計界首屈一指的企業IDEO來說,設計是在為使用者解決背後隱藏的問題。這家公司創立十五年來,美國商業週刊的年度產品設計獎首獎,年年都由它包辦。
它把設計的重點從創造產品,擴大到創造經驗上。例如,美國一家醫院希望藉由它的協助,找出節省成本、吸引病患的方法。原來以為可能會需要改建新大樓、配備新科技設備,沒有想到,IDEO帶領醫院工作人員深入觀察病患看病流程後發現,只重新設計病人掛號流程,更新候診室,就能收到很大的成效。
因為要把設計從創造產品擴大到創造經驗,因此IDEO刻意聘用背景多元的員工,設計團隊包含設計師、工程師、心理學家、人類學家等。
在設計的過程中,IDEO所依靠的絕對不只是創意和靈感,還包含更多科學的流程和紀律。例如,它有嚴密的五個步驟,第一個步驟就是好好觀察顧客使用產品的經驗,甚至自己變成顧客。第二個步驟是腦力激盪:它嚴格要求參加的人不能說,「這點子不錯,『但是』……」;而要說「這點子不錯,『還有』……」。
某個程度來說,IDEO已經不是一家設計公司,而是一家管理顧問公司,它所做的很多事情,都是在幫助企業改變思維模式(EMBA雜誌第237期第六八頁)。
關於改變,是另外一門很大的學問。
在公司裡,不論是導入一個資訊系統,或推出一個人力資源方案,往往都會遭遇很大的抗拒。有經驗的經理人都知道,不順利是常態,能夠順利推動,才是奇怪的事情。在變革行動的中期,阻力往往也特別大,也就是當開場的鑼鼓喧天熱度降低,員工開始精神不濟、注意力渙散的時候。
要怎樣才能讓「改變」不偏離軌道,變革之火不熄滅呢?管理顧問Eric Beaudan提醒我們,這個時候,要重新思考變革的目標和期望,並且改變速度。
例如,也許你的變革速度太慢,讓人不耐,或者恰恰相反,你速度太快,讓人員跟不上。此外,也許你必須設法添加刺激,或者創造危機,讓人們重新把注意力投注在這個變革行動上(EMBA雜誌第237期第三六頁)。
畢竟,就像IDEO創辦人凱利所說:「設計代表的是產品的情感層次。」變革處理的,又何嘗不是人的感情層次?
2006/04/11
What Is A Permission, by Keith Brown
Throughout my discussions of access control and ACLs in this book, I will often talk about permissions as numbers. For example, I might talk about 0x1FF as being a set of permissions, or granting "permission 1 and 2" to someone. What I'm doing is being very generic and using literal access masks or numbered permissions. I'm not specifying just what types of objects I'm talking about; I'm just talking about how access control works for all different types of objects.
So let's make this concrete and look at some examples of permissions for some specific types of objects in Windows. Let's start with, oh, a registry key. Peeking at a Win32 header file called winnt.h shows us the following1:
// excerpt from winnt.h
#define KEY_QUERY_VALUE (0x00000001)
#define KEY_SET_VALUE (0x00000002)
#define KEY_CREATE_SUB_KEY (0x00000004)
#define KEY_ENUMERATE_SUB_KEYS (0x00000008)
#define KEY_NOTIFY (0x00000010)
#define KEY_CREATE_LINK (0x00000020)
Let's also look at the permission definitions for a thread:
// excerpt from winnt.h
#define THREAD_TERMINATE (0x00000001)
#define THREAD_SUSPEND_RESUME (0x00000002)
#define THREAD_GET_CONTEXT (0x00000008)
#define THREAD_SET_CONTEXT (0x00000010)
#define THREAD_SET_INFORMATION (0x00000020)
#define THREAD_QUERY_INFORMATION (0x00000040)
#define THREAD_SET_THREAD_TOKEN (0x00000080)
#define THREAD_IMPERSONATE (0x00000100)
#define THREAD_DIRECT_IMPERSONATION (0x00000200)
If you wanted to grant Alice permission to create a new registry key under some existing key, you'd edit the existing key's DACL and add an ACE ( What Is An Access Control List ) that grants Alice the KEY_CREATE_SUB_KEY permission. Pretty simple. But look at those permissions again and tell me how you'd grant Alice the permission to delete the key she just created!
That's right, the registry subsystem doesn't bother defining a permission for deleting a key. That's because it's such a common permission (most secure objects can be deleted) that it's included as part of a standard set of permissions that are common across all types of objects. Here are the standard permissions that are allowed to be put in an ACL:
// excerpt from winnt.h
#define DELETE (0x00010000L)
#define READ_CONTROL (0x00020000L)
#define WRITE_DAC (0x00040000L)
#define WRITE_OWNER (0x00080000L)
#define SYNCHRONIZE (0x00100000L)
Compare the numerical layout of the standard permissions to the specific permissions defined for registry keys. Note how the standard permissions all fall in the upper word of the 32 bit mask, while the specific permissions are defined in the lower word. Notice the same technique is used for the thread permissions. You see, each class of object is allowed to define up to 16 specific permissions, and they must all be in that lower word, so they don't conflict with permissions Microsoft has already defined for all objects, such as the standard permissions shown above.
The standard permissions are really quite straightforward. Let me briefly explain what they mean. READ_CONTROL ("Read Permissions") controls whether you can read the owner and DACL in the object's security descriptor. If you don't have this permission, you're not even allowed to see what permissions you do have! WRITE_DAC ("Write Permissions") and WRITE_OWNER ("Take Ownership") say whether you're allowed to change the object's DACL or take ownership of the object by changing the owner SID to be your own SID (for more detail, see What Is Ownership ). SYNCHRONIZE says whether you can wait on an object (this is most often used with synchronization objects such as a mutex or semaphore). By limiting SYNCHRONIZE access, you can prevent an untrusted user from grabbing a mutex that your program depends on and deadlocking you. And DELETE is pretty obvious.
Let's say you want to grant Alice permission to read a registry key. It'd make sense to grant her a combination of the following:
- KEY_QUERY_VALUE
- KEY_ENUMERATE_SUB_KEYS
- KEY_NOTIFY
- READ_CONTROL
If you binary OR these values together, you'll end up with 0x00020019. This would be the access mask you'd put into the ACE ( What Is An Access Control List ) to grant Alice read access to the key. For an example of code that modifies an ACL programmatically, check out How To Program ACLs .
Look at the following access mask and try to figure out what it means: 0x00130000. The answer is in the following footnote2. Now try to decode this one: 0x00000001. Surely this one is easier! Oh wait, I didn't tell you what type of object we're talking about. I mean, if it were a registry key, this would be KEY_QUERY_VALUE -a fairly benign permission to grant, at least compared to THREAD_TERMINATE! You see, given a random permission mask, you really can't tell what it means unless you know the type of object to which it applies, unless it simply consists of standard permissions, which are defined centrally for all objects.
With this in mind, think about a permission mask that would be generic enough to grant read permission to any type of object in the system, including registry keys and threads. For a registry key, we'd want 0x00020019, as we calculated earlier for Alice. But for a thread, it'd be 0x00020048. That's a very different mask. As you can see, because no two types of objects can be expected to have the same sorts of permissions, at first glance it'd be impossible to treat objects polymorphically with respect to permissions. But if you look a bit further into winnt.h, you'll find the following rather interesting definitions:
// excerpt from winnt.h
#define GENERIC_READ (0x80000000L)
#define GENERIC_WRITE (0x40000000L)
#define GENERIC_EXECUTE (0x20000000L)
#define GENERIC_ALL (0x10000000L)
What do you think would happen if you added an ACE to a registry key's DACL that granted Alice GENERIC_READ? Think about it for a moment. If you guessed that the system would convert the access mask from 0x80000000 to 0x00020019 before storing the new DACL in the metadata for the registry key, then you'd be correct. You see, each class of object in Windows defines a mapping from these four generic permissions onto standard and specific permissions. This allows us to make statements like, "By default, I'd like to grant full control to SYSTEM and myself for any object I create. Oh and I'd also like Alice to have read access as well." Here's a text representation of just such a DACL:
grant SYSTEM 0x10000000
grant Keith 0x10000000
grant Alice 0x80000000
It turns out that Windows makes a statement like this for every process! You see, inside the token ( What Is A Token ) is a default owner and DACL that are used whenever you create new objects3. For example, if you were to create a thread, how would the system know what the DACL for that thread should look like? Well, it looks at this default DACL that's tucked away inside your token.
Here's what a default DACL would look like for me on my laptop4:
grant SYSTEM 0x10000000
grant Keith 0x10000000
So by default, any new threads that I create, or semaphores, shared memory sections and so on, start life with DACLs that specifically grant my account and SYSTEM full control. Nobody else will be able to touch the objects I create, barring specially privileged users such as administrators ( What Is A Privilege ). Note that hierarchical systems like the file system and registry instead use ACL inheritance to come up with a default DACL; this ensures that permissions remain consistent through the branches of the hierarchy. See What Is ACL Inheritance for the details.
The default DACL is one of the few mutable bits of data in a token. In most cases you shouldn't ever need to change this DACL, as it's already about as tightly secured as it can be. If you ever find the need to adjust it, you'll want to look at the Win32 function SetTokenInformation.
- I've omitted three permissions that are specific to 64-bit Windows for brevity.
DELETE,READ_CONTROL, andSYNCHRONIZE.- By "objects" I mean any object that has a security descriptor ( What Is A Security Descriptor ), such as a process, thread, mutex, etc.
- If you want to do this experiment, you should download the Token Dump component from my website. I don't know of any built-in tool that shows this information.
2006/04/06
美國富豪唐納川普一手策劃熱門的真人實境秀 - Apprentice (誰是接班人)
比賽的方式十分簡單,十六位參賽者分成兩組,每星期要想辦法解決川普所出的難題,輸的一方要淘汰一名組員。最後勝利者,可以獲得任職於川普旗下公司的機會,而且年薪高達六位數美金。
繼第一季創造了"You're fired."的名言之後,川普在第二季請出財富雜誌前五百大企業,給予參賽者比第一季更嚴酷、更高難度的行銷挑戰,包括為年營業額上千億的電子公司上電視現場推銷產品、幫知名牙膏大廠在一周內開發出新口味、建立行銷通路等,更多想像不到的商場致勝秘訣從第二季一一登場。這次總計十八人參賽,有長春藤名校的高材生,也有連高中都沒畢業的小老闆。他們每星期想辦法解決川普所出的難題,輸的一方要淘汰一名組員。最後勝利者,同樣可以獲得負責川普旗下公司的機會,年薪高達六位數美金。這些參賽者再度引爆精采的職場爭鬥戰!
Apprentice Theme: "for the love of money"-The O'Jays
The Apprentice Rules: http://www.theapprenticerules.com/
The Apprentice Blog: http://www.theapprenticeblog.com/
Official site for season 2: http://www.nbc.com/nbc/The_Apprentice_2
Official site for season 3: http://www.nbc.com/nbc/The_Apprentice_3
Official site for season 4: http://www.nbc.com/The_Apprentice_4
2006/03/13
Problem:: VS2005 - The current identity does not have write access to temporary file...
I finally powered up again with my newly purchased dual-core laptop, which also enables me to refresh software installations that I've been wanting to do for a long time. As I'm putting things back together, I kept running into this error with my projects:
The current identity (xxx\ASPNET) does not have write access to 'C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files'.
Description: An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.
Here's a quick fix to the problem (do this only to your dev box):
1. From the framework directory (Usually c:\windows\microsoft.net\framework\v2.0.50727\Config), modify machine.config:
<processModel userName="SYSTEM" password="autoGenerated"/>
2. Execute this command:
> aspnet_regiis -ga "ASPNET"
By applying MS's Web updates (often times including security patches), or putting you box into domain (which I am), the security constriant of your windows install drive got stricted. If you read the prompt from aspnet_regiis carefully, switch -ga is granting the daemon user access to the IIS metabsae and other directories used by ASP.NET, which is exactly what I'm looking to do..
Further Reading:
Microsoft's KB: http://support.microsoft.com/kb/315158/
Mercury簡易改裝
有同好有一樣的困擾 - 如何使用自己的data logging軟體,因此寫了這篇來分享我的簡易改裝。 Background 雲豆子 MERCURY roaster 烘豆機的設計是使用自行開發的軟體,來:1. 操控風門/火力; 2. data logging/自動烘焙。 ...
-
有同好有一樣的困擾 - 如何使用自己的data logging軟體,因此寫了這篇來分享我的簡易改裝。 Background 雲豆子 MERCURY roaster 烘豆機的設計是使用自行開發的軟體,來:1. 操控風門/火力; 2. data logging/自動烘焙。 ...
-
最近這一整個月都在玩大風大火的烘焙。一些心得記錄一下: 2017-09-22 烘豆機: 雲豆子 MERCURY roaster 第1鍋 果丁丁 1 (生豆量:200g,熟豆:171.8g,失重:14.1%) 原本計畫:入豆溫:170 風門一路不變 (MERCURY...
-
等了非常久的 Mercury 烘豆機 終於到貨了。找了水電來接220V就迫不及待開烘了。 Overall 這是一台CP值非常高的機器,可以說是目前(2017年5月)最接近貴森森營業機種的縮小版。 一應鉅全:有下豆槽,小型化的的風門,銀皮收集桶,跟風管。 ...