Category: Editorial

  • The Challenge of Audio Data

    I’ve worked remote from my co-workers for nearly 20 years. In that time, I’ve spent a lot of time on the phone, as well as in audio and video calls. Quality has often been an issue, both with seeing others and hearing them. Add in accents, speech patterns, and equipment quality, and I’ve often found myself frustrated and upset with calls. Over the years things have improved, and I have to say that the modern Zoom/Teams/Slack style of everyone working separately and being in their own environment has made it easier to communicate.

    However, it’s still not great. I was on a call a few hours before I wrote this, where someone was talking on a laptop microphone, and as they moved their head, the audio quality changed dramatically. They also raised and lowered their voice, depending on their interest in that part of the update, which had me constantly raising and lowering the volume on my side.

    There was an article recently that noted employees can struggle with bad audio as they try to work remotely with others. Stress, frustration, embarrassment, and more can affect employees. For a once a week hour-long meeting, this might not be an issue. For daily stand-ups or multiple meetings a day, this is likely going to be a long term problem.

    When I’m on a call, I don’t know how I sound, unless someone tells me that there is an issue. I sometimes use a headset and mic, but I also take meetings with my PC speakers and external mic. To b fair, I haven’t often reviewed my audio sounds on a recording, but I know that there are times I get annoyed by heavy breathing by others, typing on keyboards, or even echos from someone else’s laptop speaker.

    It’s not often, but it does happen regularly. I haven’t even mentioned the issues at the beginning of calls of getting people connected to audio on calls, which are frustrating and often waste five or more minutes at the start of the meeting. We’ve tolerated and dealt with a lot of issues across the last few months of this pandemic, and I’m glad that most organizations, in most situations, have done so.

    That doesn’t mean that continued issues will be as easy to handle over the long term. We will see stress and struggles go up if we can’t ensure that audio data has a high quality, as we expect from email, chat, and other written data. I’m going to try and ensure that I listen to some recordings of myself in meetings, and ensure my audio setup is good, not just for me, but for everyone. I hope others do the same.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • Desktop or Laptop for Remote Work

    When I started working in a corporation, I was assigned a desktop. No choice of hardware and upgrades were extremely rare and limited. This was in the early 90s, and laptops were rare, and they were coveted by those that received them. I was lucky to get to use one when on call, to allow me to remotely dial in when we had issues. Yes, I dialed in after being paged.

    Over time, laptops became more common, and as I began traveling for work, I had one full time. The last few years, I’ve depended on laptops while working for Redgate. I even ask for advice periodically when I look for a new one. Today I have two active laptops that I carry when (and if) I travel.

    However, I also have a desktop. In fact, I’ve maintained a desktop all throughout my time at Redgate and use that for most of my daily work. I like the multiple screens, and I can’t beat the multi-TBs of storage, lots of cores, tons of RAM, and more. I like my desktop, and I prefer using it.

    This week I saw an article on the reasons why a desktop PC makes more sense than a laptop. With the move to more virtual, and solo work, does a laptop make sense? Certainly there is a tradeoff. Being able to move to a different room in your house if others are using the same space is helpful. Having kids pick up your laptop and leave it elsewhere is less helpful.

    These days, I wonder how many of you feel? Some of you have dedicated office space, some do not. Some like the more powerful desktops, some prefer to flexibility of laptops. Some want to control their hardware, some want to just have a pre-assembled package.

    This week, how do you feel? Do you like desktops or laptops more? Have you changed your mind through this pandemic? What about the future, will you change for your next machine?

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • Attacks on Unsecured Databases

    Imagine that you’re a researcher doing some data analysis for your company. You run some queries or load some data and then go home. The next day, you come in and find that all of our data has been deleted. Perhaps you’re the victim of a Meow attack, where people look for unsecured databases and wipe them out. If you read the comments, many of them indicate this may be considered a public service.

    I think I agree with that, and here’s why. If you put up data about me in a system and don’t secure it. I’m not sure you should be trusted with the data. The article notes that UFO VPN was a victim. They got caught not only with an unsecured database, but one that had data that wasn’t supposed to be logged, including passwords. They moved their data to a new database, also unsecured, and a meow attack wiped it out.

    While I understand this might cause a company to fail and affect employees who hadn’t made the decision to store this data and ignore security, I’m don’t think that the world overall is worse off because their data is gone. I’m also not sure that the employees are worse off as I’d suspect fines or other legal action might have wiped the company out anyway.

    I know some university groups may lose data that is difficult or impossible to recover. I know some companies might be irreparably harmed. However, I also know that it’s 2020 and there is no reason to have an unsecured set of data available to the public. Whether a database, a file-share service, or anything else. Security needs to be provided for data.

    Like many of you, I do use some services in the cloud to share files. I also find it maddening that most public access has been revoked and I need to specifically invite people, set passwords, and more to easily share things. However, that’s what we need to do in an interconnected world where we have personally identifiable and sensitive data. We need to secure it.

    I’m glad SQL Server doesn’t allow blank passwords for sa, and I hope that no one allows simple, easy passwords on their systems. It is convenient, but the price your organization might pay for this convenience could put them out of business. It’s also a large price to ask someone whose data you have to pay if it impacts their life.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • A Data Attack

    I got a new mobile phone and was going through the setup. On top of numerous Android updates, I had to reset a number of applications back up. While it’s a pain, I also appreciate from a security standpoint that moving access to my data and sites to a new device could be an issue. One of the applications I was trying to set up was Garmin Connect, as I track my exercise, heart rate, and more on my watch. When I first tried this, I got a 404 in the app, which was strange.

    Apparently Garmin was having issues. They had a large outage. The next day I saw that article, and while I could get to the main Garmin site and log in, I couldn’t get a new install of the app to connect on my phone, and I couldn’t get access to any of my workout data. Even old data, apparently isn’t on my phone, as I thought. It’s being read from the cloud. That’s disconcerting, though I record my data separately at MapMyRun, so I’m not overly worried. I even found a procedure and tested it for saving my data locally.

    Over the weekend after this happened, I didn’t do much, but as of the Monday after the attack, the Verge reported that some data was visible and sync was working. Not for me, but for someone. That’s good, and Garmin has a touch of information about the outage, saying they expect devices to begin syncing at some point. Mine didn’t that day, but did a day or two later.

    This is interesting as an attack because it’s not just the company’s own internal data, but also their customers’ data. I don’t know if that was the intention, but what better way to put pressure on a company that take away their customers’ data. I don’t know that this would make them respond differently than losing their internal data, but it  likely would be more public. It also might put more pressure on them to pay some ransom.

    Ultimately, this is an area that I think the GDPR started to help, but allowing customers to access copies of their data, as well as have rights over how it is used. I think having the right to not only get a copy of my data, but a regular backup is something I think should be required of organizations that collect information about me. Likely there might need to be a charge, but perhaps some regulation about what is reasonable and how this data should be available is a something else that might need some regulatory boundaries.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.