Author: way0utwest

  • After X Years

     

    Dave Winer
    Dave Winer has the right views on programming.

    Dave Winer has been programming a long time. He’s not done, not ready to be done, and he has more creative work to be done in his career. After 37 years programming, it’s refreshing to see someone still excited about building software and looking forward to doing it for years to come.

    Dave also sees himself as an a movie director, but one that people don’t believe it. He makes an analogy to other directors, who are older, who have had success and failure, but are still encouraged to make more movies. If we have developers and programmers that have had success and failure, why wouldn’t we encourage them to keep making more software? It’s a great question, and one that I with more people would think about. Managers should consider it, but we should consider it ourselves. Why do we think that older programmers aren’t as valuable as younger ones?

    I like the analogies that Dave makes later in the post. He stops to admire his work, he thinks about it more, and he’s not in a rush anymore. Too often I think younger programmers, and immature managers, want to rush into producing actual work. They want to get code written and something executing on the screen rather than stopping to spend a little time architecting and planning.

    I heard a great quote recently from Abraham Lincoln that I think applies. He said “If I had eight hours to chop down a tree, I’d spend six hours sharpening the ax.” We should stop and consider problems when we encounter them, and think about all the tools and techniques we’ve learned in the past, bringing our experience to bear before embarking on a solution. The wise developers I know tend to do this, knowing they have time to write the code and will make fewer mistakes if they think a little before they start typing.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.

  • We Need to Learn Encryption

    encryption
    We need better encryption and better tools for the future.

    More than learning encryption, we need to demand better encryption tools inside SQL Server. After reading about the issues from the STUXNET worm, it makes me worried that we will see more disruptive attacks, not just from hackers and criminals, but from the virtual vandals and bored teenagers that have more time than morals or sense. The issues from the STUXNET worm spread far beyond any territorial or national issues, and run into all sorts of industrial control systems that may receive more attention from hackers in the future. With some of the brightest hackers in the US and Israeli governments providing a template for compromising those system, I’m sure there will be no shortage of future attacks.

    That doesn’t necessarily mean there are going to be more and more database attacks in the near future, but I’m sure there is research going on into new ways to attack database or applications, either from governments, criminals, or even graduate students. At some point there will be new attacks that come out, and these vulnerabilities may result in zero-day, or even forever-day vulnerabilities.

    We can’t change the way SQL Server, or other vendor technologies, work at a base level, but we can reduce the amount of damage that’s done by not being the easy prey for attackers. In my mind, that means we should be securing our data as best we can, including encrypting communications and limiting access rights, as well as encrypting the actual data we store.

    I’m hoping that Microsoft makes PKI much easier when they release the updated Certificate Services in Windows 2012, and that we also find better private solutions for individuals that allows us to better secure our systems and make it difficult for the casual attacker to compromise our systems. I don’t know if we’ll see viable products and solutions soon, but as we distribute our systems, data, and backups to wider and wider systems, including tablets and mobile devices, we need better security more than ever.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.

  • SQL Saturday #132 Files

    Uploaded here if you need them. These are the PPT deck and the code.

    UnstructuredData.zip

    EncryptionPrimer.zip

  • The Danger of Custom Software

    The Movie Vanishes
    My kids enjoyed this DR tale from Pixar.

    There’s been a great little movie short making the rounds of the Internet from Pixar. It’s called “The Movie Vanishes” and it’s worth a few minutes of your time. Toy Story 2 was almost lost because of a mistake and some bad luck at Pixar.  This was at a time when the company was successful, and certainly should have been able to better prepare for a disaster. If you want a touch more background, there’s a few other notes at Quora.

    A lot of the software that Pixar uses was written in house. That’s a double edged sword because there isn’t anyone that can stand behind the software, other than the people that wrote it. There might not be adequate testing and there are certainly bugs in the software that may lie dormant for years. I have no idea of any of the bugs inside Pixar’s software caused this disaster, and I’m not implying it did.

    The positive side of building your own software is that you know how it works. You have the source code, and if you have a developer that can understand it, you can fix problems, patch issues, and customize it to suit your needs. As long as you have the time and resources to do so.

    I saw someone write recently that building their own monitoring solution for a set of SQL Servers was easy, but that was the smallest part of the job. Maintaining and enhancing it over time were much larger jobs than setting up monitoring. This person said they’d rather buy a package in the future than build their own again.

    If you have a system set up, it probably makes sense to use it, but as you look to develop new software, whether for monitoring servers or handling sales, it might be worth spending a bit of time trying to determine if there is something out there you can buy, which might be well tested, vouched for by other customers, and be easier to integrate than your own system.

    Steve Jones

    SQL Monitor from Red Gate SoftwareIf you don’t have monitoring set up, you should. SQL Monitor from Red Gate software is an easy way to get notified when something in your environment needs to be looked at further.

    If you want to get monitoring setup without minimal effort and immediately, think about downloading a trialof SQL Monitor and testing it with your servers.

    If you’d like to see SQL Monitor working on the live SQLServerCentral database server, go over to monitor.red-gate.com.


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.