Category: Editorial

  • Another Reason to Care About Security

    This is likely a short and quiet day for many of you with Thanksgiving in the US tomorrow. Most people have tomorrow off in the US, and those that do business with the US may have a quiet couple of days with little communication from the US. A good time to catch up on things.

    Before you go, I want you to think a bit about security today, and perhaps across the weekend before you come back. Security is important, and many of us that work in the data world know this. We see more and more data breaches occurring every week, with the rate of incidents at this point being a little over 4 per day. These are losses of data from all sizes and kinds of companies from household names to local law firms and retails organizations.

    Most of us work for some company that has data, and we know a portion of this deserves protection to ensure we don’t need to pay for identity insurance or get fined by the government. There’s another reason to care about security: branding. There’s a survey that just came out, which notes that consumers are likely to stop using a brand if there’s a data breach. There’s a report on the survey as well, if you don’t want to give up more data to get the data.

    Consumers note that many would stop working with a brand if there were a data breach, but that might not mean not using that service, just not using their online services. This makes some sense in some industries, but not others. I also know that consumers can be emotional and look to leave a service, like a mobile phone provider, after a breach, to move to a new provider. In many cases, this may create churn as most providers have had some breach, and it’s entirely possible whoever is last is the one losing customers this quarter.

    What I did find interesting is that more consumers are being careful what information they share, preferring to use official portals rather than email, even avoiding clicking on links. To me, this is only a matter of time before customers stop providing most voluntary information, or the start to make up data values. That might be a problem for those of us that look to analyze data for our employers. If quality falls, perhaps we’re less valuable.

    We need to do a better job of securing system, patching them against vulnerabilities, writing better software, and preventing exposure of data. We’ve gotten better in recent years, but we need to do more work, including avoiding keeping extra copies of sensitive data in development and test environments. It requires work to mask or remove this data, but it’s better than the risk of accidental exposure and brand damage.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 4.5MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • The Data Scribe

    There’s an interesting piece in the New Yorker about technology in the medical field from Atul Gawande. It talks about the love hate relationship doctors have with medical systems, and ruminates a bit about whether these new systems are making medicine better or worse. I think Dr. Gawande is a very interesting individual, and whose Checklist Manifesto is a great look at improving processes.

    The article talks about the struggles of doctors with using various systems, but there is one interesting solution that some companies have tried: medical scribes. For these companies, rather than teach a doctor everything and have them do their own work and spend less time with a patient, the meetings are either recorded or witnessed by a scribe. The scribe handles the computer work, writing down observations, notes, orders, etc. The doctor later approves things, but this allows the doctor to focus more on patient care and get less caught up in technology.

    Years ago I worked in a company that had some extensive technology in some areas, but some older senior management. There were still secretaries that literally took dictation, handled schedules, and printed reports for the senior executives, who almost never used their computers. The might pull up some emails, but anything that required more than a few keystrokes was dictated to a secretary who wrote and sent the emails. At the time I thought this was wasteful, after all, couldn’t an executive type a few emails themselves?

    I thought of that experience while reading the other story about doctors. Certainly the executives could type emails, but not as well as others, and was that a good use of their time? Certainly today, with far too much communication being sent, I might argue executives ought to have less access to email, not more. Certainly upper level execs do have assistants, but is it really a good use of time for directors and managers to be dealing with many of our computer applications?

    What about report tools like Power BI and Tableau? Is that a good use of anyone’s time in finding data and assembling it into reports? The analysis is, but tracking down data, formatting it, and more feels like something that is a skill in and of itself.

    Perhaps we need data scribes in more industries. Not a single employee dedicated to one person, but a specialist in the gathering and cleaning of data, preparing it in tools that business people then use to perform their analysis, working for multiple people. Need more data? Ping your data scribe, someone that knows the structure, meaning, and location of data.

    Would you want that job? I know I’ve done this at times for people, finding the data they need and producing a report, often showing them how to do it themselves, but I wonder if that’s a good idea. With data changing, new sources appearing, stronger access controls and more, perhaps this is a role that more companies ought to embrace to ensure that those with experience analyzing data aren’t spending time fiddling with it.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 4.7MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • New Database Options

    I saw recently that Azure SQL Database is getting a few more Database Scoped Options for that platform. These are intended to give more control over the way in which the engine behaves, without requiring each database on a server to function the same way. I expect to get to the on-premises product at some point, where they’ll be even more useful as we often might want different behavior for different contexts on an instance.

    While there are advantages to managing all databases in an instance in the same way, I do think that more and more we consolidate databases at times and it’s better to have additional control when needed at the database level. This week, I wonder if there are things that you wish you would have been able to specify for each individual database.

    What options would you want to see added at the database level? 

    I think that many of the options we’ve been given in current versions, as well as the newer ones appearing in SQL Server 2019 are a good start. I don’t know which instance level settings I might want here, but I certainly would like to see newer capabilities at the database level. It would be nice to see the capabilities for jobs and alerts to be set at the database level. Even if this were a part of the Agent subsystem, having the ability to keep these jobs within a database and have the agent read them would be useful.

    Moving more capabilities to the database level gives us more flexibility in separating the workloads for different applications. With the movement of the platform code, and many customers, to Azure SQL Database where the system requires less dependence on an instance, it makes sense to start including more options at the database level. I would guess that at some point most of the settings that we need for manage a system will be included and set at the database level.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 2.5MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • The Linux CoC

    This is a busy time of year for me, with lots of conferences and other events taking place. It’s busy most years, but this past October was especially busy in my life. I’ve been in New York, London, and Hong Kong during the month, which is quite a spread of time zones. It’s been a mix of work and pleasure, and I agreed to all these trips, so I can’t complain. In any case, it’s both an exciting set of trips and a daunting set, and I don’t know if I’d want to do that again.

    In my travels, I noticed some press about a new Linux Kernel Code of Conduct. This is a change from the original Code of Conflict that Linus Torvalds published. I’m not sure he adhered to his own words from the reports I’ve seen over the years about his comments to developers. In any case, he signed off, though not everyone likes the new code of conduct. I don’t know enough about the issues, but I do realize that not everyone behaves well towards others, especially in this business.

    In any case, I go to lots of conferences. I meet lots of people, and see lots of different situations play out between attendees, organizers, venues, and speakers. For the most part people are fairly well behaved and treat each other respectfully. That’s not always the case, which is why many conferences and organizations have adopted some Code of Conduct that should apply to those that attend events, are members, etc. I do think this is a good idea, as it gives us a common framework where we can evaluate behavior as well as debate future changes.

    Last week PASS has their annual Summit, with their own Anti-Harassment policy. While I haven’t observed any actions that would violate the policy, I have had friends report they have experienced these types of behavior. I’ve had friends ask for an escort over concerns of potential behavior. It’s sad that this happens in the world, but it’s a reality. I’m glad that organizations are trying to move in a direction that protects those that feel harassed or threatened.

    It’s likely that there will be overreactions, reports of misunderstandings, and similar issues. Certainly some people want the freedom to behave as they see fit, where they don’t believe they are doing anything wrong. I understand that, but ultimately I also believe that it would be better to have a few people investigated or thrown out of a conference for no reason than have others suffer because they aren’t believed. I’m here for any of you that are struggling with abuse, and I hope others are as well.

    I hope that we learn to live by the famous quote from Bill and Ted’s Excellent Adventure: be excellent to each other. If some of you can’t do that, then at least learn to live by Wheaton’s Law.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 3.6MB) podcast or subscribe to the feed at iTunes and Libsyn.