Author: way0utwest

  • Data Breach Danger

    Recently a court in the US ruled that there was no imminent danger from a data breach at a Texas hospital. This is good news and bad news for the world, and I’m a little torn about how I feel. On one hand, it’s good for us as data professionals that we aren’t necessarily going to be liable for the immediate effects from lost data. While the losses aren’t always our fault, we certainly could feel pressure from management if companies faced immediately legal or financial penalties.

    However it’s bad news because I think there’s little else that data breaches do than cause harm to those whose information is lost. It can be incredibly hard to link a specific breach to a specific identity theft incident, and I see this as a way of allowing companies to escape liability for their poor security practices.

    In reality, however, I have no solution to propose. As a data professional, I try to keep data safe, but it’s very, very difficult. One small hole in your technical infrastructure or human employees and you can lose a ton of data very, very quickly. I know it’s not lost, but copied, however you have lost control of it.

    We will face more and more security incidents, and as those tasked with protecting data, I’m not sure what we can do, or should do. However, I do think that organizations can’t take all responsibility, nor can they take no responsibility. The balance of how to deal with losses and issues is certainly something I hope we work out.

    Soon.

    Steve Jones
  • Data Breach Danger

    Recently a court in the US ruled that there was no imminent danger from a data breach at a Texas hospital. This is good news and bad news for the world, and I’m a little torn about how I feel. On one hand, it’s good for us as data professionals that we aren’t necessarily going to be liable for the immediate effects from lost data. While the losses aren’t always our fault, we certainly could feel pressure from management if companies faced immediately legal or financial penalties.

    However it’s bad news because I think there’s little else that data breaches do than cause harm to those whose information is lost. It can be incredibly hard to link a specific breach to a specific identity theft incident, and I see this as a way of allowing companies to escape liability for their poor security practices.

    In reality, however, I have no solution to propose. As a data professional, I try to keep data safe, but it’s very, very difficult. One small hole in your technical infrastructure or human employees and you can lose a ton of data very, very quickly. I know it’s not lost, but copied, however you have lost control of it.

    We will face more and more security incidents, and as those tasked with protecting data, I’m not sure what we can do, or should do. However, I do think that organizations can’t take all responsibility, nor can they take no responsibility. The balance of how to deal with losses and issues is certainly something I hope we work out a a society.

    Soon.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( MB) podcast or subscribe to the feed at iTunes and LibSyn.

  • Learning Continuous Integration for Databases – LA Apr 10

    I’ve been talking about continuous integration for databases for a couple years now as a part of my job. My employer, Red Gate Software, has been building tools to help database developers build better software. We (Red Gate) want to sell software, but we also really want to help people build better software. It’s a big reason why I’m employed there. Red Gate truly wants to make the world a better place while we run a business.

    I’ve gotten lots of interest and questions from my one hour talk and late last year Red Gate decided we needed to do more. We built some all day continuous delivery classes last year and they went over well. Over the winter, Grant, myself, and a few others at Red Gate got together and we’ve been working on adding depth to our instruction and have come up with 3 full days of training to help you build better database software, quicker.

    Continuous Integration in LA

    The middle class we’ve developed is an all day look at how you implement a continuous integration process with a database and application. On April 10, 2015, I’ll be coming to Los Angeles, CA, along with one of our partners, Ike Ellis, to work on a full day of training. It’s a $500 class, but you’ll walk through a couple of different ways to set up a CI process, actually perform the steps yourself, and make changes to the database that get built and tested.

    We think it’s a great way to smooth out your development process and bring more engineering to the way you deploy database updates. Ike is an expert SQL Server consultant and he’ll show you how to create your own CI process. I’ll be in the background to help out, and we think you’ll gain some in depth knowledge that you can use at your job right away.

    If you want to advance your database development, register today and join us in LA on April 10, 2015.

    register

    I’m excited to be a part of these classes, and I hope you are as well.

    We do cover a number of Red Gate tools in the classes, but the procedures and steps are applicable to other methods of accomplishing the same tasks. Even if you choose to use other tools, or write your own, the skills we teach you will be applicable.

    I wouldn’t write my own, however. I’d easily burn the cost of the tools many times over trying to iron out the bugs in my own process.

    The Continuous Delivery Process

    The whole idea of continuous delivery is that you can make changes at anytime. It isn’t sloppy work, untested development, or anything else. This is a way to bring more engineering to software development, and I really believe in it.

    It’s not easy, however, and that’s why we’ve built three days of training. We cover these items in the three days.

    • Day 1 – Version Control for Databases
    • Day 2 – Continuous Integration for Databases
    • Day 3 – Automated Deployment

    We haven’t set these up all in one week, mainly because it’s too much information for you at once. Ideally we want to tour around, running one of these classes each quarter, because it will take you a few months to implement the information and understand it.

    If you get past these courses, we’re also partnering with expert ALM consultancy shops that can help you even more.

    We’ve got a number of all day events coming up for you to consider, so check out our list of training days. We’re adding more all the time, and let us know if you want us to come to your area.

  • The Design Investment

    This editorial was originally published on Sept 29, 2010. It is being re-run as Steve is traveling.

    I ran across a bit of a rant from Don Halloran on the lack of design effort being made in many applications and software. He talks about a lack of consistency in databases, confusing column names and datatypes not used correctly. Don laments that “It seems database design doesn’t get much respect, and I really don’t understand why this is.”

    We all probably have some idea of why systems get built like this: the designer is ignorant, or lazy, or maybe doesn’t pay attention because it’s not part of their job. Any reason could fit, but ultimately it comes down to someone taking on a job without making the investment in their own career.

    If I were putting tile in my own bathroom, I accept a few mistakes, and I might cut some corners. I might be happy to accept a little fumbling around while cutting tile. I would not, however, put up with that if I were paying someone. I would expect a more professional job. If I decided to change careers and lay tile for a living, I’d also expect to make an investment in my own skills to learn how to do a professional job.

    I understand that developers are paid to write code, and that they are more interested in manipulating objects, methods and properties and implementing DR or indexing. If you plan on working with SQL Server, it pays to make the investment in learning how to do it properly. If for not other reason than because you should consider if part of your professional responsibility.

     

    Steve Jones