Author: way0utwest

  • Another Reason to Care About Security

    This is likely a short and quiet day for many of you with Thanksgiving in the US tomorrow. Most people have tomorrow off in the US, and those that do business with the US may have a quiet couple of days with little communication from the US. A good time to catch up on things.

    Before you go, I want you to think a bit about security today, and perhaps across the weekend before you come back. Security is important, and many of us that work in the data world know this. We see more and more data breaches occurring every week, with the rate of incidents at this point being a little over 4 per day. These are losses of data from all sizes and kinds of companies from household names to local law firms and retails organizations.

    Most of us work for some company that has data, and we know a portion of this deserves protection to ensure we don’t need to pay for identity insurance or get fined by the government. There’s another reason to care about security: branding. There’s a survey that just came out, which notes that consumers are likely to stop using a brand if there’s a data breach. There’s a report on the survey as well, if you don’t want to give up more data to get the data.

    Consumers note that many would stop working with a brand if there were a data breach, but that might not mean not using that service, just not using their online services. This makes some sense in some industries, but not others. I also know that consumers can be emotional and look to leave a service, like a mobile phone provider, after a breach, to move to a new provider. In many cases, this may create churn as most providers have had some breach, and it’s entirely possible whoever is last is the one losing customers this quarter.

    What I did find interesting is that more consumers are being careful what information they share, preferring to use official portals rather than email, even avoiding clicking on links. To me, this is only a matter of time before customers stop providing most voluntary information, or the start to make up data values. That might be a problem for those of us that look to analyze data for our employers. If quality falls, perhaps we’re less valuable.

    We need to do a better job of securing system, patching them against vulnerabilities, writing better software, and preventing exposure of data. We’ve gotten better in recent years, but we need to do more work, including avoiding keeping extra copies of sensitive data in development and test environments. It requires work to mask or remove this data, but it’s better than the risk of accidental exposure and brand damage.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 4.5MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • A Problem with POWER()

    I ran into an interesting problem while working with the POWER() function. I was trying to do some binary conversions and had a statement like this to process powers of 2.

    SELECT POWER(2, n)

    This was designed to take a value and return a power of 2. I then used a different value to determine if this was added to my conversion factor or not. In trying to work with some larger numbers, I ran into this error:

    Msg 232, Level 16, State 3, Line 3
    Arithmetic overflow error for type int, value = 2147483648.000000.

    The error tells me I’ve exceeded the size of an integer. When I looked up the POWER() function, it tells me that it returns a bigint for a bigint input. Since I had ensured my “n” was a bigint, I was confused for a few minutes.

    Then I realized that it’s not the n, but the “2” that’s the problem. By default, this scalar value is an integer. That means I need to ensure that this is a bigint to make this work. I changed to:

    SELECT POWER(CAST(2 AS BIGINT),n)

    And things worked.

    Double check all the data types when you get a conversion error. SQL Server knows what’s wrong, but sometimes you need to dig in to determine where in your code you’ve made the mistake.

  • The Data Scribe

    There’s an interesting piece in the New Yorker about technology in the medical field from Atul Gawande. It talks about the love hate relationship doctors have with medical systems, and ruminates a bit about whether these new systems are making medicine better or worse. I think Dr. Gawande is a very interesting individual, and whose Checklist Manifesto is a great look at improving processes.

    The article talks about the struggles of doctors with using various systems, but there is one interesting solution that some companies have tried: medical scribes. For these companies, rather than teach a doctor everything and have them do their own work and spend less time with a patient, the meetings are either recorded or witnessed by a scribe. The scribe handles the computer work, writing down observations, notes, orders, etc. The doctor later approves things, but this allows the doctor to focus more on patient care and get less caught up in technology.

    Years ago I worked in a company that had some extensive technology in some areas, but some older senior management. There were still secretaries that literally took dictation, handled schedules, and printed reports for the senior executives, who almost never used their computers. The might pull up some emails, but anything that required more than a few keystrokes was dictated to a secretary who wrote and sent the emails. At the time I thought this was wasteful, after all, couldn’t an executive type a few emails themselves?

    I thought of that experience while reading the other story about doctors. Certainly the executives could type emails, but not as well as others, and was that a good use of their time? Certainly today, with far too much communication being sent, I might argue executives ought to have less access to email, not more. Certainly upper level execs do have assistants, but is it really a good use of time for directors and managers to be dealing with many of our computer applications?

    What about report tools like Power BI and Tableau? Is that a good use of anyone’s time in finding data and assembling it into reports? The analysis is, but tracking down data, formatting it, and more feels like something that is a skill in and of itself.

    Perhaps we need data scribes in more industries. Not a single employee dedicated to one person, but a specialist in the gathering and cleaning of data, preparing it in tools that business people then use to perform their analysis, working for multiple people. Need more data? Ping your data scribe, someone that knows the structure, meaning, and location of data.

    Would you want that job? I know I’ve done this at times for people, finding the data they need and producing a report, often showing them how to do it themselves, but I wonder if that’s a good idea. With data changing, new sources appearing, stronger access controls and more, perhaps this is a role that more companies ought to embrace to ensure that those with experience analyzing data aren’t spending time fiddling with it.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 4.7MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • Webinar: What We Learned at the PASS Summit

    Join me tomorrow for a webinar from Redgate Software.You can register for our webinar today at 10am EST here.

    Kendra Little and I join Grant Fritchey, the President of PASS, to discuss some highlights from last week’s PASS Summit.

    Register today and join us tomorrow.