Author: way0utwest

  • Encryption Works

    If you have better encryption than this, it will work.

    I don’t know that the government hires the best people or they have the best tools to work with, but they have some expertise. There’s a short note from Bruce Schneier that full disk encryption (FDE) does appear to by preventing unauthorized access to computer systems by police in many cases.

    If you read the comments, there are all sorts of flaws and potential holes with encryption, which are valid arguments. However that doesn’t mean that you shouldn’t implement any encryption on your removable or portable drives, especially those in laptops. Those devices are like the locks on your home or car. They can be defeated by determined professionals, but all too often the casual criminal doesn’t bother if they are in place.

    Keep in mind many laptops are lost, stolen, or sold without wiping the drives. Most people that received the drive wouldn’t bother to try and decrypt it unless they were sure it had something valuable on the drive. Since it’s no guarantee that a laptop grabbed at Starbucks or from a car has valuable data, most likely the target is the hardware, not the disk contents.

    I think disk encryption is a good layer of defense in your security strategy and worth implementing. My laptops are encrypted, mostly because it’s an easy security mechanism, and I’m not always sure if something I have on there is sensitive enough to worry about. My recommendation is that you implement FDE if you can.

    You should also make sure you are backing up your data. Losing the laptop might not result in the release of sensitive data, but losing the data itself could be a major problem.

    Steve Jones


    The Voice of the DBA Podcasts

  • PASS Speaking Results

    I got the PASS speaking results today on the new speaker portal. They posted the top sessions as well, overall and in each track. I did two sessions, and here are my summarized results:

    Branding Yourself for a Dream Job

    67 attendees, 39 surveys.

    Overall, I was mid 4’s (4.59, 4.72, 4.74, 4.56, 4.56) for the various questions. Anything over a 4 means that I was doing a good job overall. I got some great comments, many of them in caps. I hope that means people were excited, but in any case, here are a few:

  • IT IS TIME TO VAN SP_UPDATERESUME
  • GREAT, GREAT PROFESSIONAL DEVELOPMENT TIPS! ESPECIALLY LIKED THE PART ABOUT BLOGGING. WELL DONE!
  • IDEAS FOR FINDING EMPLOYEES AND OWN CAREER
  • THE IMPORTANCE OF MANAGING MY IMAGE
  • STEVE OPENED MY EYES TO THINGS I ALREADY KNEW BUT WASN’T REALLY AWARE OF.
  • LEARNED SOME GREAT TIPS FOR IMPROVING "BRAND" TO HELP IN KEEPING/FINDING JOBS
  • GLAD I CAME. VERY ENJOYABLE AND INFORMATIVE.
  • SUPERB PRESENTATION!
  • I GOT SOME GREAT TIPS TO IMPROVE MY ONLINE PRESENCE.
  • DESIRE TO PROMOTE ONLINE PRESENCE
  • I ALREADY STARTED TO UPDATE MY ONLINE PRESENCE AND I’LL BE UPDATING MY RESUME WHEN I GET HOME.
  • GREAT STUFF! MORE GOOD INFO THAN EXPECTED!
  • Nice comments, and I enjoyed the session. Got some great questions during this presentation.

    In the PD track, I was third, and I regret not going to see Plamen’s talk on great presentations. The slides look good.

    The Top Ten SQL Server Skills You Need

    188 attendees, 80 surveys.

    I was worried about this session a bit because it was near the end of Friday, the last day, and it’s a basic 100 level session. Also, I was in a huge room, the one that Adam Machanic filled up with 500+ people that morning.

    However I was pleasantly surprised to see similar scores here in the mid 4s (4.43, 4.66, 4.6, 4.45, 4.34). I guess that means I do a decent job presenting, even when I’m not at my best. One comment caught my eye:

    • Voice was more monotone than yesterday. Sounded tired.

    Very, very true. I was wiped out, and after this session I left immediately for the airport for a flight. I dislike speaking late in the day, and after being in Seattle for a week, I was definitely tired.

    This is a tough session since it’s basic, and I suspect some people come to see me, expecting something more. I was actually surprised this session was picked by the program committee, though clearly wanted. I was more surprised it was scheduled so late in the week. I had some nice feedback:

    • several of the tips were useful and possibly the links to more information is most helpful
    • go home and use what I learned
    • finally someone at this conference who teaches people new to sql server the basics and not something over my head Thanks Steve!
    • how to train my entry level dba’s

    Glad I met the need. Some not to great feedback, though I’m not sure how I can fix some of these. It’s listed as a 100 level session.

    • Could have said for beginners. This was a very low level presentation of many basics that most dbas do every day.
    • I expected sql server dba function more advanced than types of joins and how to create basic indexes
    • Could use a little more just like most sessions

    I’m not sure what “more” I could do, especially with 10 things. I suppose I could cut it down, but my aim was to point people in a direction, not teach them deep skills.

    I think I’ll retire this one, unless I get a call for it. I don’t love it, and with a mixed skill level audience, I always find people complaining that it’s too basic.

  • The Employment Contract

    I ran across this piece on how we should pay people from Business Week. It’s a look at the issues of specifying the exact work that someone will do once you hire them. I suspect this is a problem in many industries, but it can be especially tricky in technology, where the job requirements can change as the technology rapidly changes.

    Most of the time I’ve taken a job in the US, it’s been an “at will” employment, with a verbal contract between me and the hiring manager or HR representative. Nothing was signed, and I essentially did whatever my manager wanted, regardless of my job title. That was fine with me. Currently I have a written contract, but the requirements for my position are a little vague and my duties aren’t explicitly spelled out.

    However I wonder how most of you feel. Does it make sense to more explicitly list the requirements for your job? As a DBA, developer or other professional, would you want any limits on what you were required to do?  This Friday, answer this poll question:

    Would you like to have your duties spelled out explicitly in a contract?

    I know we don’t typically sign contracts, but would you like that? What if the duties were modified every quarter, with an agreement by both you and the management of the company? What if you could just list the things you were not required to do?

    Let me know this week what you think.

    Steve Jones


    The Voice of the DBA Podcasts

  • Not So Unbreakable

    Nothing is unbreakable

    There’s a report on Dark Reading that says some researchers think Oracle is not working on security as hard as they should. The proportion of security fixes has diminished, which some people think implies that they are not taking security as seriously as they should. The window of time between the disclosure and the patch has grown wider, which is troubling, especially when newer software displays vulnerabilities.

    I’ve been proud to work on SQL Server over the last 6 years from a security perspective as there have been very few security patches issued, and correspondingly, few vulnerabilities disclosed. It’s possible Microsoft has muzzled some researchers, but I doubt it. I would guess that if any serious security issues existed in SLQ Server 2005, 2008, or R2, we’d have heard about them. I think the security engineering process that is used for SQL Server has truly resulted in more secure software.

    It’s possible that Oracle faces a resource issue with all their acquisitions, but for a billion dollar company that employs over 100,000 people, they shouldn’t be having resource issues with their development process. It’s a question of accepting greater development costs in order to ensure their software is secure.

    This is one area where we ought to have independent security researchers that can discuss, debate, and disclose vulnerabilities, after a limited amount of time. That would help us at least understand the security risks we face, and perhaps pressure companies to build better software.

    Steve Jones


    The Voice of the DBA Podcasts