Author: way0utwest

  • Don’t Use MD5

    “The hashing alone being MD5 tells me that they really don’t care about their passwords too much, so it’s probably some pre-generated site.”

    That was from this article on an Anatomy of a Hack. It’s an interesting quote, and it shows a few things.

    First, we have a history issue with our frameworks and the lack of updates as we learn more about a technology, or circumstances change. This could be that frameworks are not being updated. It could be that developers are not updating their frameworks. It could be that they are downloading the wrong versions.

    The bottom line is that older technologies, those that have vulnerabilities, are still being used. If you use encryption for passwords, don’t use MD5, and I’d say that SHA1 is a bad idea. If you are on a version of SQL Server prior to 2012, SHA2 is not available, but with the SQL CLR and SHA2 in .NET, you can write your own.

  • A Release from Data

    Morihei-UeshibaThis editorial was originally published on Aug 14, 2008. It is being republished as Steve is at SQL in the City 2013 – London today.

    Have you ever had that frustrating day where you can’t get your queries to work, or can’t find a problem and spend all day working on an issue you can’t solve? Have you had customers or clients that make unreasonable demands, and you want to just punch the wall? Any co-workers that upset you with requests or complaints that make you walk away before engaging in some other career-ending action?

    Someone actually suggested to me that this might make a good topic as they noticed quite a few people that were interested in databases were also interested in martial arts. At first glance it might seem strange, after all, the traditional geek is more of a passive individual, someone that spends their spare time in virtual worlds they visit on the computer, on a TV screen, or in their minds while reading a book.

    I studied martial arts as a teenager for about 6 or 7 years, trying different styles and teachers as I moved around early in my career. It was a great exercise and a nice release after working hard during the day. However I got married, had kids, and my career took off, and I turned to running, swimming, and other activities I could do during lunch, freeing up evenings for my family.

    Over the last year, my middle son become interested in karate, and it got me back into a dojo after 15 years. We go together 3-4 times a week and even have one class together where parents and kids and study together. I’m even planning on going to the PASS Summit early and taking him to an aikido demonstration the weekend before ( Puget Sound Aikikai).

    Martial arts are not for everyone, but I will say that being able to focus on hitting a pad, and actually hitting it, is a great stress reliever for me. If you’ve never tried it, I’d recommend taking a class or two from a school that doesn’t engage in a lot of contact between people to get a feel for the sport. You might really enjoy it.

    If it’s not for you, I do think it’s important for everyone to take care of their body a bit, especially by putting it under some physical stress. Walking, running, basketball, even chopping wood with Grant, anything that gets you moving will only help the rest of your life. I’d encourage everyone to find some release for those days that you just need to unload some stress after work.

    Steve Jones


    The Voice of the DBA Podcasts

    Everyday Jones

    The podcast feeds are now available at sqlservercentral.mevio.com to get better bandwidth and maybe a little more exposure :). Comments are definitely appreciated and wanted, and you can get feeds from there.

    Overall RSS Feed: or now on iTunes!

  • Lost in Space

    hammacher-lost-in-space-b9-robotToday’s editorial was originally published on Sept 2, 2008. It is being re-run as Steve is traveling today and out of the office.

    Well perhaps not lost in space, but according to this article, a number of US airports report over 600,000 laptops lost a year. Over 10,000 are lost each week at the 36 largest airports. That’s a lot of bits floating out there in the world. There’s some dispute as to these numbers in another article, so it’s hard to know who’s correct. I tend to think these numbers might be high.

    In any case, what might be even more amazing is that 65% of these laptops are not reclaimed. What’s scary is that 53% of people surveyed said confidential company information was on their laptop and 65% said no effort was taken to secure their data. I found this on Bruce Schneier’s blog, and he sees it as a huge dollar loss for the country if the numbers are correct.

    My wife travels quite a bit, 30-40,000 miles a year, and she’s not surprised by these numbers. She guesses that the main problem is that there is no good way to match a lost laptop with a traveler. Unless you lose it at your home airport, with a lack of staff and the time it might take for something to get your lost and found, it’s likely you would never be able to search for it.

    And how long would you search? After how many days would you just move on and file a claim and replace the laptop? I tend to carry my important data on a USB key (and likely will upload to some service for future travel), so I’d probably spend whatever time I had in the airport, or maybe a day here in Denver, but after that I’d be ordering a replacement and moving on.

    Information has a tremendous amount of value, but to many of us, the information also has a shelf life. We might move on quickly and just accept the losses as part of doing business. I understand that and agree with it for the most part.

    However I think we should all have some sort of encryption and protection for our data. You never know when you might have some letter to a bank you drafted with your account information, or something else. For most thieves, I’d guess that an encrypted laptop isn’t worth dealing with. They’d wipe it and move on.

    Steve Jones from SQLServerCentral.com

    » Join the debate, and respond to today’s editorial on the forums


    The Voice of the DBA Podcasts

    The podcast feeds are now available at sqlservercentral.mevio.com to get better bandwidth and maybe a little more exposure :). Comments are definitely appreciated and wanted, and you can get feeds from there.

    Overall RSS Feed: or now on iTunes!

  • SQL Server Should Work for Us

    failI ran across a post the other day from someone that was trying to find out why their maintenance plan failed. This person had received a failure notice from SQL Agent, which is good. We should all be aware of failed jobs from some sort of monitoring system. Like any good DBA, this person checked the job history, saw an error, couldn’t figure it out and posted a question at SQLServerCentral, looking for help. That’s a good plan for most anyone 😉

    Experienced DBAs know that to debug this issue, you need to look at the maintenance plan log, which has more details. The job history contains a minimal amount of information and usually doesn’t help. If you examine the maintenance plan log, it’s usually easy to determine which part of the plan failed since the plans are fairly simple constructs. The really exceptional DBAs don’t use maintenance plans and instead would rely on some sort of tool or well known script instead to handle their maintenance.

    However why do we need to go to the maintenance plan’s log? SQL Server includes the job history. It includes maintenance plans. Why doesn’t the job understand there is a maintenance plan, read it’s log, and return the information? Or give us a button on the job history that loads up the maintenance plan log? That’s a simple thing to do, and isn’t the job of software to make tasks easier?

    This is one of those places where SQL Server feels a bit immature and unrefined. I understand the complexity of the entire product and the limited resources that are devoted to enhancing and growing the product. However, where are the resources that make SQL Server easier for the average and accidental DBAs to use? Those are the majority of the people using the platform.

    SQL Server led the industry in producing tools that made it easy to manage and use. Other platforms are quickly catching up, however, and if SQL Server can’t continue to improve its toolset, in addition to its features, people will consider other platforms. The cost of SQL Server has risen, but so has the revenue. Do us, and yourself, a favor, Microsoft. Put a team of 50 people to work on usability and improving the tooling. It will be a great investment for the future.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.