Category: Blog

  • Untested

    The 2014 Apple keynote was today, with the announcement of the iPhone 6 and iWatch taking center stage. I was excited, with an aging iPhone 4S that needs to be replaced. I tuned in, expecting to watch the announcements while taking care of some busywork on the other monitor.

    At first I saw this screen (though at about 20 minutes beforehand)

    applekeynote2

    About 10 minutes before the event, the countdown switched, and noted that my browser (Firefox) wasn’t supported. I almost switched to Chrome, but then saw the fine print. I wasn’t thinking and didn’t take a picture as I ran to grab my iPad, but Karen Lopez posted an “altered” version of the Apple page.

    applekeynote3

    Fair enough. Apple doesn’t have to broadcast to everyone and I get that they want to let their iPhone/iPad/iTouch/Mac users see it live. The keynote was available about 30 minutes after the end for everyone, so no big deal.

    In fact, in the scheme of my life, not being able to watch live wasn’t a big deal. I can catch the “showmanship” an hour later.

    However I was surprised when my iPad kept showing a test screen from the broadcast truck. When it connected, it was sputtering and halting, even when a speed test showed me getting 20+MBps at the device.

    I did manage to watch a little, with a Chinese translation overlaid on the sound, at a higher volume than the speaker for me. Slightly annoying, but I could deal with it.

    About 15 minutes in, things started crashing, with Safari on my iOS 7 iPad and iPhone crashing. The iPhone would start Safari and connect to the Apple home page and show this:

    Photo Sep 09, 12 49 36 PM

    The iPad connected a few times and showed this:

    Photo Sep 09, 12 49 26 PM

    I gave up, going on with my day, knowing I could watch it later. However that brings up the question.

    Did Apple test in Production?

    By this I mean, did they actually test the broadcast of this event today, with the live event, or did they test things last week on a copy of what this environment would look like? Did they actually run through the same settings for broadcast that they would do today?

    I do suspect they did some testing, and certainly it’s possible that many, many more people than they expected tuned in. They may have been overwhelmed, and that’s understandable. I doubt anyone has any good way to determine what capacity to plan for, other than to just guess. This event might have been larger than the Super Bowl, World Cup, etc.

    Or maybe Apple didn’t want to bother scaling to a capacity beyond some xx% of Apple device owners.

    Any of those is fine with me, and I can understand someone deciding to spend $yyy on this, though I’d argue it was a mistake since this is a great chance for an amazing amount of publicity and hype for their products.

    However there are certainly other problems that I question the level and detail devoted to testing. The overlay of foreign languages means that someone hadn’t configured their audio correctly, and more importantly, no one was monitoring to stop the problems quickly. The problems with the stream meeting devices might have been capacity, but crashing the browser? Either there’s a major QuickTime issue, or the encoding was broken in some way (perhaps again, by capacity).

    This is a shot at Microsoft as well, but I thought Tim Ford’s summary was spot on:

    applekeynote

    We talk about thorough testing on a copy of production. A real, scale, same sized version. Few of us do it, but certainly some do, especially those with big budgets. Apple has big budgets, so I suspect that their testing was cut short, or someone assumed things would work the same way they had in the last keynote, which went off without a hitch for me.

    Complacency, coarse attention to detail, poor quality control and monitoring seemed to be in play today. None of which as a good thing.

    Perhaps Apple was testing in production.

  • T-SQL Tuesday #58–Passwords

    It’s the second Tuesday of the month, time for T-SQL Tuesday again. This time the invitation to participate comes from Sebastian Meine (@sqlity, blog) with the topic of passwords. It’s a great topic, especially as security concerns are growing regularly.

    I would encourage anyone that looks to build their brand, and further their career to write a post for T-SQL Tuesday. It’s easy, just look for the invitation and then publish on the second Tuesday of the month.  Be sure to follow the #tsql2sday tag on Twitter.

    You can even go back and write about previous topics, and share your own thoughts and insight. I keep a list of previous topics here: T-SQL Tuesday Topics.

    SysAdmin Passwords

    I’ve tried to maintain strong passwords for years. I used to have a formula, similar to Bruce Schneier, where I’d use a sentence to build a password. However a few years back I went to Password Safe, and have been using that on Windows, OSX, iOS, and Android, with Dropbox keeping my password safes in sync. I let Pasword Safe generate my passwords, 12 characters), with random digits and I use this to stick passwords into systems.

    I use a different password for every system, which has been fine for me. It’s slightly annoying to unlock the safes on a mobile device, but I like the idea that a compromised password on one system doesn’t affect any others.

    Years ago, I worked as a DBA and we managed a large number of systems. One of our mandates was that administrative passwords would be changed every 30 days. That was fine for the people running the systems, but changing the administrator password for hundreds of Windows hosts was an issue. We grouped servers (IIS servers, Exchange servers, etc), to make it easier for each administrator to manage the systems, but it was still a challenge to create passwords for each group every 30 days.

    I introduced Password Safe, and simplified things. We let the application generate passwords for each group, stored them in the safe, and used a script that took the group and password as parameters to change all the systems passwords. This was still time consuming, but it provided for a limited window to crack a password, allowed us to use longer passwords, and we could also retrieve them when we needed to administer a particular system.

    Note that this was just for administrator passwords. We had a separate scheme for service accounts, which was to randomly create a long, 15+ character, password that was used to start the service, but was never stored. Similar to many applications, we couldn’t recover the service account passwords. If we needed one, we changed it, and sent a note to the security group whose event log scanners would note the change.

    I know that strong passwords don’t necessarily solve our security issues with hackers and social engineering, but I do think this is the lowest bar you can tolerate. If “sa” and blank, or “sa” and “password”, or “system” and “manager” (for the Oracle folks) work on your database, you deserve to be fired. There’s no excuse for not picking a strong password for privileged accounts.

  • The BBQ Crawl at SQL Saturday #300

    This weekend is SQL Saturday #300 in Kansas City. I’ll be traveling Friday for the event, hoping to arrive in time to go on the pre-event barbeque crawl that the organizers set up every year. It’s hard to believe it’s been 4 years since I was last in KC. I still have, and often wear the shirt I got from SQL Saturday #53 when I travel and was surprised to note recently that it’s a 4 year old shirt. How time flies.

    Kansas City is a neat city, and the event is a lot of fun in a very unique setting. An old river casino, converted to a training center. I still remember driving up and being unsure if it was the right place, and then enjoying the view inside.

    This week I’ll be talking about Continuous Integration for Databases, so if you’re in the area and have time Saturday, then register and come by,

  • Better Presentations–Fonts

    This is part of a series of tips for speakers to make your presentations better.

    Please, please, please, learn how to set up your machine to look good on screen.

    I saw Brent Ozar write a few notes on how to make your presentations better recently. This was primarily for the people presenting at the PASS Summit, with a few specifics to that event. Buck Woody also had a mini rant about sizing the fonts on your laptop.

    Both are worth reading. The visual display of your work can overcome some poor speaking habits. Likewise, great speaking performances overcome some poor visual displays. Having both fail means your presentation may fail.

    Note by failure, I mean that the attendees don’t like the talk and lose out on information because they’re bothered by the way your session appears. This could be at a conference, a SQL Saturday, or a lunch and learn at work.

    Increase Fonts

    To move on from Buck’s post, change the defaults in SSMS. Paul Randal has a nice post on configuring SSMS. Read it and try it.

    I go for 14 point fonts, but note that you need to set Text and Grid results separately and restart SSMS. Do this before you walk in front of people.

    It’s easy to do in SSMS. Click the Tools and then Options menu items. You’ll get a dialog like this, and on the left, under Environment, there’s a Fonts and Colors selection. Click it.

    badpresent4

    The top drop down on the right controls the section of SSMS. Query Windows are the Text Editor items. Below this, I have a font (Consolas) and a size (14). Below that on the left I have the various items in the Text Editor I can change fonts for. There are so many settings that this could be a weeklong project.

    I usually just change the “Plain Text” to 14. I don’t’ worry about the others, but if you use other items in your presentation (like line numbers), change them.

    If you select the top drop down, you’ll see this

    badpresent5

    These are the other places you can change fonts. The two I want to point out (I use them) are the Grid Results about 2/3 of the way down and Text Results a few below that. Change both of these font sizes, though you’ll have to restart SSMS.

    If you make these changes, your attendees might not thank you, but they’ll be less likely to complain. Even in the largest rooms, 14 points seems to reach to the back of the room. And if it doesn’t, learn to zoom.