Author: way0utwest

  • Outsourcing Security

    firewall
    Are security services like this going to be outsourced in the future?

    Security is becoming more of an issue for many companies. Increased regulation, more scrutiny from the media, and customers that are more concerned about their data handling and privacy are forcing companies to spend more resources to ensure better security. However building secure systems takes skill and experience, something many companies lack. Acquiring those skills can be hard, and I think as an industry, we do not disperse information on secure coding well. If we could get developers and administrators to read about security with the same level of interest they show in the iPhone 5 v the Galaxy S3 v the Lumia 920 debate, perhaps things would be different.

    One vendor is betting that companies will look to outsource security needs. Webroot has moved to a hosted service, confident that customers will move to the new service for its ease of implementation and arguably better protection. By controlling the software themselves, and updating it as quickly as possible to meet new threats, Webroot can do a much better job of ensuring security than most companies can by managing the service themselves.

    That’s an interesting idea, and it’s similar to the idea of threat detection that Bruce Schneier wrote about a decade ago. This doesn’t solve application issues, but it can improve security for threats that attack your network. That’s if the vendor actually does their job correctly.

    There are any number of issues with this model, but as more companies get comfortable with the idea of renting services and platforms, moving to the “cloud”, I can see this idea growing. For us in the data world, this means that we have another group to interface with, potentially audit to ensure they are not violating any data protection. As far as your actions if you find issues? That can be complicated, but it certainly will require that your communication skills are strong.


    The Voice of the DBA Podcasts

    We normally publish three versions of the podcast each day for you to enjoy. Today there is no podcast due to Steve being ill. Hope to have the podcasts return tomorrow.

  • Off to the Center of the Universe

    “New York City…center of the universe..” – Rent

    I’m off to New York this morning for the start of the 2012 SQL in the City US Tour. It kicks off tomorrow in New York City.

    As this posts, I’ve just dropped my son off at school early for a Future Business Leaders of America field trip as I head off on a field trip of my own. This is the start of a few busy weeks as I deliver presentations in 5 cities in two weeks.

    I’ve got a group with me as well. A number of talented developers and business people from Red Gate software, along with my co-worker Grant Fritchey (b | t) will be at all the events. We have some special guest speakers at each stop as well from the local areas and I’m hoping we deliver some great talks that you enjoy.

    We had a great time this past July in London and I’m looking forward to these events over the next two weeks.

    I don’t love the travel, and I’m popping in and out of home the next two weeks between some of the stops. However I love my family and my bed, and the chance to get home for a day is worth a little extra travel.

    New York is an amazing city, and I love visiting it. I’m hoping to get into the city and checked in by 4pm at the latest. Then I’ll head over the Central Park for a run. If you want to join me, I’ll be coming up 7th to the park, hopefully by 4:15 at the latest, but watch Twitter.

    Red Gate puts on a great event, and I look forward to seeing some of you in New York, or at any of the other cities on the tour.

    If you wonder where the lyrics at the top come from, watch this:

  • Pair Programming

    pair programming with cat
    I could probably handle some pair programming with this little one.

    I’ve never pair programmed, but I’m not sure I’d like it. As much as I like collaborating, I prefer alone time to work on problems, or think things through and experiment a bit on my own. I prefer brainstorming and discussion sessions to be limited in nature, with the chance to then go work on my own pieces along.

    However pair programming has been touted as a way to improve software quality by many people. It’s not as popular as some other methodologies, but it still exists out there. I ran across a programmer’s reflections on nine months of pair programming that made for a thought provoking read. He looks back at the experience and lists some pros and cons. Better code, more productivity, and lots of knowledge transfer were some of the positives, and would lead many managers to try and push developers into working in pairs.

    However there were downsides. As someone that speaks regularly, I think that the strain on my vocal chords would be hard if I had to speak constantly to someone else. The fact that the environment needs to be consistent for both people would also be a problems as I often find strong opinions from  developers in technology as to how they want an environment configured for their tasks. I know that watching someone else control a browser drives me a little crazy. I think I’d definitely need to have a separate machine for many tasks.

    As with anything, pair programming makes sense at times. I know that I’d like to have senior T-SQL coders work with junior ones when developing complex queries and explaining how and why they solve problems with certain techniques. Doing this in real time might slow down the senior person, but I think the evolution of one’s thoughts as they solve a problem is as important to learn as the inner workings of the actual code.


    The Voice of the DBA Podcasts

    We normally publish three versions of the podcast each day for you to enjoy. Today there is no podcast due to Steve being ill. Hope to have the podcasts return tomorrow.

  • Trade-offs

    scale
    There are always trade-offs when building software.

    I’ve always told my managers that building software is a trade off. We can do things cheaply, or we can do them quickly, but we can rarely do both. We can certainly fail in both ways, and many people do, but I usually see the need to trade time for money, or vice versa, when building software.

    I ran across a piece recently that was similar, though in it Allan Hirt says you can do things right, do them fast, or do them cheap. Allan talks about limited resources in working on projects. At some point time, budget, and staff resources are constrainted and you can’t expect stellar performance on extremely large workloads in a 24x7x365 environment. Something has to give, and one of those resources is going to let you down.

    I had always looked at people as a “money” cost, since they are paid for work, but there is another constraint to people that I hadn’t considered. Each individual in your company isn’t just a resource that’s exchangeable for others. Each individual has knowledge and skills that aren’t easily transferred to, or replaced by, other employees. In addition, each person has time constraints; they will only work so much in a given time period.

    Building powerful, efficient, effective systems, whether in software, infrastructure, or even in culture takes effort, time, and money. However if you do it well, it’s something you’re not only proud of, but something that pays for itself over and over.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.