Author: way0utwest

  • I have a dream

    It seems fitting with the anniversary of Martin Luther King’s “I have a dream” speech that I would write about discrimination this week in my piece “Stunned”. There’s a long discussion over at SQLServerCentral, and along with a phone call with a friend, I thought a bit about what I wrote.

    I wasn’t present for the quote. I don’t know if there was nuance, or intent to joke, intent to annoy the listener, or something else. The written word doesn’t convey everything, and I decided not to dig deeper, identify the speaker, or take any actions as it’s all hearsay to me.

    However, I do think something along the lines of what you read, was said. I think there are still people that think this way, just as there are people that think various minorities are not competent, trustworthy, or something else.

    I have a dream that we will get beyond this as anything other than a rare occurrence. I don’t believe we will ever eliminate racism, or sexism, or really any type of discrimination. But perhaps we can reduce it to a very, very tiny level, get more people to think about there inherent prejudices and work to overcome them.

    I’m prejudiced in some ways. I recognize that and try to not let it affect my actions. I try to treat people fairly, and professionally. I try to treat them as I’d expect they will treat me. I want to accept them as they are, work with them with their strengths and weaknesses, and try to ensure I make an effort to increase diversity in my life.

    My intent today was to raise awareness. I wanted people to think about the actions, to talk about issues, and recognize that there are still problems in the world, including our tiny SQL Server, data professional world, that we should deal with.

    My hope is that we work to ensure this type of attitude is not tolerated. I hope for a frank discussion at user groups that note discrimination is not a part of the group. I hope that both minority groups (females, races, etc) and event/group leaders make efforts to include more disparate people. I hope more women and others make an effort to join in the community and share their knowledge. I hope more leaders choose to include more diverse speakers. If you have two people that are qualified, make the choice for diversity some of the time, rather than perhaps the more well known or safe choice.

    I hope we grow closer, not further apart, as a community.

  • Stunned

    I’m stunned, and I’m not releasing many details here. Not because I condone this, but because the who did this isn’t nearly as important as the message and the behavior. I didn’t press for more details when I heard about it and I’m not interested in learning specifics.

    A user group leader responded to an inquiry with: “We don’t want female speakers. Our users only want to hear technical content.”

    First, what the <insert your own expression here>? Second, seriously? Third, WTF? I’m actually stunned that in 2013 we have someone that doesn’t believe that female speakers can deliver technical content.

    We will never eradicate prejudice and bigotry from the world. As humans, we all have our own beliefs, likes, dislikes, and our prejudices. We form impressions of people, of groups, even of events, and those impressions influence how we view the world and interact with others. Some of us change our minds over time while some of us cling stubbornly to our stances. There will always be some friction in our dealings with others, depending on how we view the person.

    When I see quotes like this, I know we need groups like the Women in Technology that advocate for more participation and fair treatment of their members. I had someone express concern a few years ago that this type of group might fragment our SQL Server community. What happens if we have Black Men in Technology, or Chinese Women in Technology, or any othe=r subset of our members. I think those groups would be fine, and necessary, whenever we have a group of people that struggle with their place in the the community. Organizations can help their members to improve their own skills are handling situations and improving the way they work within the larger community.

    I firmly believe that we are all better off when we have a diverse community, with all types of people, a variety of thoughts, ideas, opinions, and most importantly, teachers. It takes some effort from all groups to consider and incorporate that diversity into our user groups, conferences, and other events. There are so many talented, technical people around. I’d encourage organizers and attendees to choose and watch a wide variety of speakers. Take a chance on someone that you might not normally consider. You never know when the person you prejudge will surprise you in the end.

    Steve Jones

    Video and Audio versions

    Today’s podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

    Follow Steve Jones on Twitter to find links and database related items and announcements.
    Steve Jones Windows Media Video ( 21.2MB) feed

    MP4 iPod Video ( 23.5MB) feed

    MP3 Audio ( 5.1MB) feed

    Feeds are available at iTunes and Mevio

    To submit an article, rant or editorial,
    log in to the Contribution Center

  • Lost in the Noise

    I’m glad I have well water. Not that it protects me, but it provides some insulation in the event that the local water company’s systems were hacked and unclean water released. That hacking could happen, and the person in this piece speculates it is happening after a water authority honeypot attracted hackers from all over the world. It’s scary to think how the world may change when any individual, as well as any country, could attack our digital systems. It means security is more and more important all the time.

    As I read the article, I looked for a positive in the experiment. Was there something to take away from this research? The thing I thought of was the way in which hacker traffic was drawn to this system. Not that hackers were not also investigating other systems, but if honeypots existed, perhaps in enough places, would the additional targets provide more security?

    That’s an interesting idea. What if you had CRM/Sales/Inventory systems that were available for port scans, and hacks, but didn’t connect to banking systems and had test/dummy data? Would a few of these provide some security by luring hackers into spending their resources on these systems instead of real systems? What if you had 4 or 5 instances of SQL Server, probably Express, responding to port scans and providing a relatively easy target. You could monitor these systems, and perhaps be more prepared for real attacks when they occur.

    I have long felt that we can’t completely eliminate threats and secure our systems from any unauthorized access. What might be worse is that we may not be able to separate real queries from fake ones. What we need is better monitoring and awareness of the traffic to our systems. Perhaps if we had honeypots that we could monitor, we would be able to draw some hacking traffic, identify users that were unauthorized and then use that information to better protect, or audit, our real systems.

    Steve Jones

    Video and Audio versions

    Today’s podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

    Follow Steve Jones on Twitter to find links and database related items and announcements.
    Steve Jones Windows Media Video ( 15.5MB) feed

    MP4 iPod Video ( 18.3MB) feed

    MP3 Audio ( 3.8MB) feed

    Feeds are available at iTunes and Mevio

    To submit an article, rant or editorial,
    log in to the Contribution Center

  • Physical Security

    Think your office is secure? You have guards during the day checking badges, you have key card systems to control and audit access and alarms set at night. You don’t worry if you have various system names or passwords scribbled on scratch paper. After all, who would target your office?

    You never know. With the large number of people working in technology, there are bound to be a few people with less than prefect morals. The turnover of employees in technology can be high, and it might not be as easy to recognize an outsider as you think.  Even in companies that only have 50 or so employees, it’s easy to assume the person you see in the company is new hire, contractor, or other individual that has reason to be there.

    Especially if that person gets into your locked server room because they’ve hacked the alarm or key card system. At the Black Hat conference, hackers demonstrated how they can get past many alarm systems and talked about their methods for cloning RFID cards by walking near someone. The fact that these technologies are available, relatively cheap, and can be implemented by people that have some knowledge of the systems means we have to be more careful than ever about the physical security of our systems.

    Be aware of the authorized users that can physically access systems. Ensure that you don’t have passwords or other critical information easily available, and encrypt your systems. Even if someone breaks into your data center, they won’t want to spend a lot of time there. If someone can easily get information, or copy files, they will. Adding a few security hurdles to bypass might mean the difference between keeping control of your data and losing it.

    Steve Jones

    Video and Audio versions

    Today’s podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

    Follow Steve Jones on Twitter to find links and database related items and announcements.
    Steve Jones Windows Media Video ( 14.4MB) feed

    MP4 iPod Video ( 17.5MB) feed

    MP3 Audio ( 3.5MB) feed

    Feeds are available at iTunes and Mevio

    To submit an article, rant or editorial,
    log in to the Contribution Center