Author: way0utwest

  • The Public Perception of Security Issues

    It’s my fault.

    That’s what I think if there is a security incident with my employer that involves the database. It’s almost my first thought when I hear about issues at other organizations, thinking a technical person is at fault. Since I’ve been a developer and administrator, and I know how complex systems are, I usually stop myself and try to learn more before I assign blame.

    The public and your customers also think that it’s just your fault. At least, that’s what I see and hear from friends. Non-technical people are very quick to assign blame and get upset. They can’t understand why some companies get breached and others don’t.  To them, it’s because the staff or management are lazy and haven’t done a good job keeping their systems secure.

    However, even my technical friends get upset. I’ve had more than a few of them chastise an organization for getting breached when they themselves haven’t always kept up to date on patches. I mean, how many of you are sure every SQL Server you have is at the latest CU level? How quickly do you patch? Are you sure your firewall people haven’t accidentally misconfigured a rule for port 1433?

    Anyone can get breached, as noted in this article. However, a good response can set you apart, and I wish that more management and technical people would be prepared now for a data loss incident, a ransomware attack, or really any security issue that might occur in the future.

    It’s easy to panic and make rash decisions. The best time to draft your response is now, when you have a clear head and no pressure. Have a few people start to game out how to react, what words and message to send, and who will take responsibility for communicating with customers. It’s worth a little exercise to discuss some possible responses to events and at least have the outline of a plan.

    And no matter what, be sure you have a copy of the plan air-gapped from your network. On a few flash drives, saved to a separate OneDrive/Google Drive/Dropbox account, or even printed out. The last think you need is for all of your work to be inaccessible because of something like ransomware encryption.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher, Spotify, or iTunes.

  • Design Lessons for Software

    I play guitar as a hobby. Not great, but I enjoy it and find it relaxing. It’s a good break from my day periodically, killing a few minutes before a meeting. It’s also a nice way to unwind at night. I find it better than playing games or my phone or streaming more Netflix shows. I enjoy those as well, but there is something different about music.

    I tend to use acoustic guitars, meaning no electronics. However, I have had electric guitars in the past, and have even used pedals to alter sounds. When I saw this article about design lessons from guitar pedals, I was intrigued. It has 5 lessons from these devices, which are for other digital gear. However, I think they could apply to software as well.

    The first one is that these pedals are rugged. While I’m not stomping on pedals with my feed, I do think that we could ensure software is more robust and not susceptible to small mistakes by users, especially in the order of their touches/clicks that might cause problems.

    The second is about using more than our hands, which I hope doesn’t apply. You can add voice or gestures but don’t require those. I HATE those features. The fourth is about physical UIs, including physical buttons, which I think is important for cars, but not necessarily for all software. However, if you can give someone a button or knob instead of a touch, it can be helpful.

    The third is to have bold, visual cues. I had a designer once say we ought to build more Fisher-Price software, meaning something obvious and usable by a child. I know some of our processes are complex, but we ought to work to keep things as simple as we can. For databases, I think clear, consistent names help here, especially for indexes, FKs, and triggers.

    The last one is to make things beautiful. I have to admit I didn’t think about this much before coming to work for Redgate Software. Across the last 15 years, I’ve learned to appreciate the value of design, UX, and the people that make things look good. I can’t do that; I have no skill in this area, but I know that having someone come behind me to do this is worth the effort.

    Of course, on top of all this, your software has to work and perform well. If the software doesn’t work correctly or is very slow, none of your clients are happy. Learn to write better code, improve your skills, and listen carefully to those asking for features. If you do that, these design lessons will make sure all your efforts shine through.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher, Spotify, or iTunes.

  • Sharing the Code

    I don’t know how many of you use the ScriptDOM. I haven’t really used it, but was very impressed with Mala Mahadevan’s Stairway Series on the topic. I have recommended this to a few customers that were looking for some complex code analysis features, which go beyond what SQL Prompt or SQL Fluff do.

    I noticed this week that ScriptDom has been open sourced by Microsoft. The code is available on GitHub, which means you can fork it and change it. Or submit PRs. No idea if Microsoft will take them, but if you write solid, useful code, they might.

    I like that more and more Microsoft is open-sourcing and sharing code that they write. Usually, their repos aren’t for software they sell, but maybe they will change that at some point.

    There are over 5000 repos in their account right now, including one for VSCode, which I use almost every day. While I don’t plan on contributing or even bug-fixing, I bet some of you might. I might contribute to the docs, which I do regularly for the SQL Server docs. There are a lot of changes here, but there are a few marked way0utwest.

    BTW, if you don’t want to do your own PRs, send me a note. I’m happy to edit the docs and submit changes.

    I am a fan of open-source projects, because I do think collaboration is useful in many situations. While I don’t expect many people to actually make changes to software, some will. Some, like me, will correct docs, and others will find issues in the code and report them. All of those efforts help us improve software, and I am all for higher quality software.

    Now if we could get Microsoft to open-source SSMS, maybe a few of you would find ways to improve that application.

    Steve Jones

  • Learning and Building Skills

    This is completely off topic and feel free to stop reading if you don’t care about how to tap a bolt, but it was something that I had to a) learn, b) spend time practicing, and c) get done to save money.

    tl;dr it’s not hard, but it was interesting.

    Bear with me as I’ll explain the situation, what happened, and what/how I learned.

    We have this building on the ranch.

    IMG_2882

    That’s not a great show, but it is cool at night. Here’s a better shot.

    20210315_161916

    This is a fabric building, made of a steel frame that’s anchored to the ground and fabric pulled around it. The fabric is actually secured by weaving straps through the frame. Here’s a good shot of how this works, albeit with a broken strap. We actually had to climb up here and tie a new strap to the existing one to secure things. Another skill, but a simple one. Mostly climbing and tying strings.

    messages_0 (1)

    At the bottom of the the fabric, there is a pocket. It’s actually a loop that runs horizontally along the material. Similar to how a hoodie has a pocket around the hood in which a string is threaded. In this case, there’s a steel pole in there. You can see this below, as the white material at the bottom is doubled over and a different color. There is a small pocket cut out towards the middle left where you can see the steel pole.

    20230225_161501

    This steel pole is secured to the bottom frame with a threaded rod. You can see a couple of these in the image, with a washer and nut on it. These go through the pole and screw into the frame that’s on the ground. The nut is tightened and holds the walls down in the wind. There is some space in some places where the wind and go in and out, which allows pressure to equalize inside and outside the building, and also helps the frame resist strong winds by having it flow through.

    I didn’t think much of this when the building was built, but at some point my wife told me a rod had broken and the building was flapping. In this case, part of the wall was moving, which wears the fabric down and can tear it.

    Not an easy thing to fix and potentially something that will cost a lot.

    Repairs

    When I examined the rod, I saw it had broken off in the base frame. I don’t have a great picture, but this is roughly what I saw, albeit in a round steel frame. This picture shows a bolt head broken, but for me, it was a longer rod.

    2023-04-26 13_45_07-bolt broken off in hole - Google Search

    I did what I often do. I triaged the scope and scale of this problem. I saw articles like this one from Bob Vila. That didn’t look took hard, so I decided to see if I could remove the old bolt with a left handed bit and easily fix things.

    I bought a left handed bit and tried and failed. The old bolt is exposed to dirt and the weather and I think it slightly rusted in the nut, or perhaps it was too clogged from dirt, but I couldn’t get it out.

    My thought was to call a service person, but I also know this is a small job. Likely someone can do this in minutes, which means it’s not much $$ and hard to get someone to come.

    A little more research led me to videos like this one, which shows how to make a mark and drill out the screw. In checking with the costs of the tools, I found some that weren’t expensive, and certainly less costly than getting a handyman out.

    So I tried this. I took the broken rod to the store, found it was 1/2”, bought a slightly smaller drill bit (29/64) and a tap/die set.

    I got a hammer and a metal drill bit and drilled down into the hole. I used a little gear oil to keep things cool and worked my way down.

    2023-04-26 13_53_10-Photo - Google Photos

    Once I had a hole, I read instructions, watched a video, and then tapped new threads into the space. This is really keeping this tool aligned and screwing it down into the hole. It’s hard, and definitely tiring on the hands.

    82580967_10220563234979744_3451612706077933568_n

    Once I have this through the metal, I usually can easily go up and down a bit, threading it into and out of the hole. This is really only about 1/2-3/4” of metal as the horizontal tube below is hollow.

    The last part is threading in a new rod and tightening down the not on the bolt to hold the base.

    Reusing New Skills

    Once I did one, I felt confident in doing others. In fact, the first time my wife pointed out the problem, there were 2 to fix. Since then, I find that I need to fix 2-3 every year, in different places. Some from weather, some perhaps from horses or people kicking the base.

    I found that after the second time, I didn’t even need to go look up the process, as I internalized what needed to be done.

    There are quite a few skills like this I’ve learned in my lifetime, and plenty here at the ranch, that save money, and more importantly, time. They also give me a sense of satisfaction.

    On the list this year is to teach my daughter this skill as she’s hoping to come work on the ranch after college and this is something she can do.