Category: Editorial

  • Confidential VMs

    Ever since we started to offload workloads to hardware that we didn’t physically control, there have been security concerns. I remember when this started with application service providers and web workloads. This has continued to be an issue as more and more types of workloads have moved to cloud vendors and other hosting providers.

    Google is trying to ameliorate some of the concerns by offering customers confidential VMs. These are special types of VMs, using encryption and hardware capabilities to protect the workloads from any unauthorized access. I don’t know to what extent this practically protects a workload compared to a non-confidential VM, as the details are a bit confusing. I’m sure there is some extra protection, but the weak point in most cases here is still likely the humans that use credentials to access the VM. I’d suspect a determined attacker would try to hack the sysadmin and their laptop rather than the VM itself.

    In any case, Google is trying to ensure the added encryption doesn’t cause any workload degradation. Hardware can likely help her, but I’m not sure that you can perform encryption and decryption without using more resources. There might be minimal impact, but there has to be some resource impact. At least compared to a non-confidential VM.

    I’m glad there is research and work still happening to find ways to improve security for systems that we might no longer control. I think that’s increasingly the trend. Whether you go with a cloud vendor like AWS, Azure, GCP, etc., or you look to host with a Rackspace like provider, more and more of our infrastructure is being outsourced, and I don’t know that the trend will reverse itself anytime soon. Even if it does, the more we can provide security hurdles against unauthorized access, the better.

    Steve Jones
    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • Research on the Changing Workplace

    One of the things that I have admired about Microsoft is their desire to invest in research and try to learn more about subjects that relate to their core business. Microsoft Research has a number of fascinating projects underway all the time, and I enjoy browsing the site once in awhile.

    However, they don’t just limit research to this group. They are a data driven culture, and it seems they are constantly using metrics and instrumentation to measure how the entire business works and to glean insights into how they might work better. Recently I saw a report on Microsoft’s new work-from-home workforce, driven by a group that helps companies better work with their own employees.

    Work has changed for many people in the world in 2020, and very dramatically for some. At the same time, many companies have had to drastically alter they continue to do business, recognizing that many technical employees could work from home and be as effective as they are in an office. Microsoft has analyzed their own data, and continue to do so as they seek to understand how the pandemic has changed things for employees. They do find some longer work days, more networking, and more social events.

    Interestingly, meetings are slightly shorter, which is something I’ve noticed as well. It’s almost as if the effort to walk to a conference room means people have invested more in spending an hour there. With remote meetings, I find more people are willing to cut short a meeting and end it early when they can. The downside is that there are more meetings, at least for this group.

    The importance of management is something they noticed, as well as a larger burden on managers that they must deal with as they have more meetings with employees. I’ve actually gone to every other week meetings with my manager for a time, though I’m not sure I like that. I’ll give it another month and then see what I think. I appreciate the extra work for managers, but I also know that managers should be enabling employees, which should be a big part of their job. If that means a bit of hand holding, I think that’s important.

    The two most interesting things in the piece to me were that some of the authors’ clients are planning on a two year work from home, and that work-life boundaries are blurring, especially on weekends. For the latter, I think we sometimes find work to be an anchor, and we may need to spread our 40-ish hours across 7 days to deal with the challenges of family during the week. All the challenges of children, maybe other adults and meetings, etc. can impact when we work. The one thing we certainly need to avoid is having 40-ish hours become 50-ish.

    For the former, if you plan to be at home for two years, why not just make that forever? I’d think the adaptations employees, departments, and workflows make after that amount of time might not be worth undoing.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • A Broken Streak

    SQL Saturday #1 was in Orlando, as the first actual event that has gotten us to nearly 1000 in just over a decade. I didn’t go to the first one, but I did go to SQL Saturday #8 and many more since that time. I’ve been luck to get back to Orlando a few times, and I look forward to more in the future.

    Andy Warren announced that this year’s SQL Saturday in Orlando is cancelled. This breaks the longest streak so far, and I’m sad to see that. I wasn’t likely to go to Orlando this year, though this city is always on my list. I was hoping the event would take place in some form, but I understand the desire to step back and examine how to move forward.

    A virtual SQL Saturday isn’t quite the same for me. I’ve presented at one, and submitted to a couple more to support them, but I don’t love this format, and I think it becomes hard to make it a special event for your city. I know a few more are planned for 2020, and I hope someone runs a SQL Saturday with only local speakers for that area. That might make it feel like a local event.

    Since the pandemic hit, and since SQL Saturday #950 in Victoria, I’m not sure anyone has held a live event. I’m not sure when the next live SQL Saturday will be, but I’m hoping that it happens in 2021 sometime. I don’t think anyone can plan for this year, but I am hopeful we will find a way to get back to some live interaction next year.

    We have until 14 Mar, 2021 to avoid losing a whole year of SQL Saturdays and breaking a streak of having them every year since 2007. I’m confident that if it’s safe, someone will organize and run a SQL Saturday as soon as they can. I’m also sure it will be well attended as I’m guessing many of you are looking forward to a live event as much as I am. I just hope I get the chance to speak, because I will certainly be ready for a live audience.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • The Old Way or the New Way

    Many of us are employed because of our talent and experience. We get things done and our organization values what we do. We got this position because we did something well, as a DBA, developer, manager, or some other role.

    It’s natural that we feel confidence in our abilities and knowledge. However, that shouldn’t prevent us from learning new skills, techniques, and patterns for getting work done. As much as many of us want to feel we regularly learn in technology, I often find that customers, clients, and friend struggle to change their habits.

    Why is this? There is a good post on the topic that looks at why people want to use the old way. It’s from the perspective of the developer that shows something to a client, but I think this applies to many parts of our world. Making change has an effort, and the effort needs to have a high enough return to be worth making a change.

    In terms of development, do we change our efforts when something is slightly better? Perhaps, especially if there security or resource changes could be high for our final deployment. What about if the changes are most nebulous, like slightly less technical debt? Or if there is a chance for more future flexibility in the design? The benefits we get back are sometimes hard to measure.

    The changes also need to be considered for a team. A change for my coding habits might be low with little disruption to my workflow, but the change for a team of 10 is a multiple of the effort. We all have to make a change, and that can disrupt an entire sprint, or a series of sprints if our focus and rework increase as everyone tries to adapt.

    My general rule of thumb is that some change has to be at least 20% better in some way. It has to make a fundamental difference to be worth the effort. This is one reason I never moved from Google to Bing. Bing works fine, but it’s not 20% better. I’m not sure it’s 1% better. It’s different, and that has a high cost to me to change.

    Moving to new ways of working can be good, but the movement needs to be careful and slow, especially in a team environment. However, we also need to learn to move more when there are enough benefits. We sometimes forget that last part.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.