Category: Editorial

  • Encrypt Everything

    Security is a problem with so many of our applications and systems. There are numerous ways that we handle access and protection of data, often with access rights or encryption (or both) being applied to data in order to limit who can access the data. However neither of these systems is perfect for a variety of reasons and no matter how we configure our security, it seems there are always issues.

    Yahoo announced recently that they are trying to improve their security by encrypting all data that moves between their data centers. Other large internet companies do this, though not all. However, this doesn’t necessarily mean that your data is much more secure than it was before. This should make it more difficult to access data while it is transiting networks outside of Yahoo’s control, but there are still potential issues. Just as with TDE, any legitimate user inside a data center that has access to the LAN or systems inside the data center can still potentially read the data.

    I’m not picking on Yahoo here as the same issues might exist with Microsoft, Google, or any service provider that encrypts data between its facilities. This system also suffers from the potential compromise of the keys used to encrypt traffic if any employee were to sell, disclose, or lose a copy of them on laptop.

    However this is a good start, and it does mean that the NSA or any other organization that looks to read data in transit must work harder to access your data if it’s encrypted. I think it’s such a good idea that I think we ought to start encrypting all traffic by default. LAN, WAN, whatever. We’ve had tremendous advances in hardware and I’d argue that most of us have more powerful hardware than we need. If we decided t take the hit to encrypt all traffic now, we’d become used to the overhead and we’d have better security overall.

    I’d love to encrypt all data on disk, but I know people get nervous about losing data. A good start, however, would be to ensure all data in transit is protected.

    Steve Jones

    Video and Audio versions

    Today’s podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

    Follow Steve Jones on Twitter to find links and database related items and announcements.
    Steve Jones Windows Media Video ( 19.2MB) feed

    MP4 iPod Video ( 22.4MB) feed

    MP3 Audio ( 4.6MB) feed

    Feeds are available at iTunes and Mevio

    To submit an article, rant or editorial,
    log in to the Contribution Center

  • The Geek Christmas Poll

    There are just a couple weeks until the Christmas holiday this year, and there are no shortage of new gadgets being released and updated by all sorts of companies. Many of us in technology get intrigued and interested by the new ways in which the various electronics and technologies are implemented and integrated. Whether these items have practical uses or not is often secondary to the joy we get from seeing technology being used in innovative ways.

    With Black Friday and Cyber Monday behind us, I’m wondering this week what things would excite you this year as gifts. There seem to be as many new products, enhanced products, and new ideas that are coming from established vendors as well as independent, crowded funded companies on sites like Kickstarter and Indiegogo. This Friday I’m asking:

    What geek gifts or gadgets would you like this year?

    It’s the season to give and take pleasure in making others smile, but if you were to make a list for Santa, what would be at the top of your list?

    I’ve gotten so many electronics over the years that I don’t really feel a lot of excitement over many of them. I tend to use my cell phone and laptop most of the time, and rarely venture out to other devices. I backed a Kreyos watch project earlier this year and am looking forward to receiving that device in 2014.

    If there were one electronic item that I’m interested in, it’s a FitBit Flex device. As I age, I’m paying more attention to my health and my level of activity, and I’ve seen a few friends learn more about how well they’re taking care of their health using either a Fitbit, Jawbone, or Nike device. I’d like to give one a try and see if it improves my health.

    Let me know this week what interests you. Maybe a Google Glass device? Some tablet? A smart watch? Anything else?

    Steve Jones

    Video and Audio versions

    Today’s podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

    Follow Steve Jones on Twitter to find links and database related items and announcements.
    Steve Jones Windows Media Video ( 19.9MB) feed

    MP4 iPod Video ( 23.2MB) feed

    MP3 Audio ( 4.7MB) feed

    Feeds are available at iTunes and Mevio

    To submit an article, rant or editorial,
    log in to the Contribution Center

  • PVPs

    I had it happen to me. We had an SSL certificate for a website that one of my employers ran. I actually purchased the certificate, and it secured our communications for a couple years until one day it didn’t. The certificate expired and the website stopped accepting connections. If I had noticed, it might not have been a big deal. However when the owner of the company gets a call from one of his large customers, it’s an much bigger issue.

    If you worked at Microsoft last year when their security certificate expired, it was an even bigger deal. It’s not that an affected customer that sends a note; it’s affected, unaffected, and potential customers that hear about the issue from the media. It seems like tracking private virtual properties (PVPs) ought to be easy, but it’s not. As pointed out in this piece, there are a number of issues at an organizational level, and while there are fixes, it takes some effort.

    In many businesses that have periodic activities required for physical assets, there are often people dedicated to tracking, or performing the activity. Mechanics know about maintenance on vehicles, accountants renew leases, workers replace equipment nearing the end of service. Often the time lines and activities involved are understood, and individuals understand their responsibilities.

    This showcases another area in which technology is woefully immature. Need a certificate? It takes a person with specialized knowledge to understand what’s needed, purchase it, and install it. This person either then moves on to a new role without leaving instructions behind, or isn’t well equipped to understand the need to track the expiration and replacement of the technical item. There often isn’t even a system set up to handle replacements of these items, which might be superseded or replaced by some entirely new type of technical wizardry.

    Managing and tracking PVPs is hard, and I suspect, going to get harder. Security requirements increase, technical requirements grow, and specifications change. I’d like to say I’m confident Azure (or AWS or another large service) will never have another outage because of this, but I wouldn’t be surprised if they do.

    Steve Jones

    Video and Audio versions

    Today’s podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

    Follow Steve Jones on Twitter to find links and database related items and announcements.
    Steve Jones Windows Media Video ( 20.5MB) feed

    MP4 iPod Video ( 23.9MB) feed

    MP3 Audio ( 4.9MB) feed

    Feeds are available at iTunes and Mevio

    To submit an article, rant or editorial,
    log in to the Contribution Center

  • 2013 Tribal Awards

    We’re the #sqlfamily on Twitter, and often in person where we often get together for a #sqlrun in the morning and a bit of #sqlkaraoke at night. In some sense, we are a tribe within the larger technology community, focused on our common work with SQL Server. I thought the title for  was fantastic, bringing together new authors to share their knowledge, and raise money for a charity.

    At SQLServerCentral and Simple Talk, with the sponsorship of Red Gate Software, we decided to create some end of year awards in various categories, based on the community, not companies or products. We kick off our nominations today in a number of categories, including Advice that saved my bacon in 2013, Best Speaker, Best Outfit, and more. You can read more about the categories in today’s announcement.

    The idea is that the community can recognize others in the community with a nomination, and some supporting material that encourages others to nominate the same individual, and vote for the winner. The top five with the most nominations will get voted on over the holidays with awards presented in January.

    I hope you have fun with this, and think back to those people and events that stand out in your mind in 2013.  Nominate them, give a few reasons, and celebrate the help that each of us gives each other as a part of the SQL Server tribe.

    PS: we had a great #sqlski last year for SQL Saturday in Albuquerque and we’re doing it again this year. Feel free to join us at Taos on Friday, January 24th, right before SQL Saturday #271 in Albuquerque on Jan 25, 2014.

    Steve Jones

    Video and Audio versions

    Today’s podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

    Follow Steve Jones on Twitter to find links and database related items and announcements.
    Steve Jones Windows Media Video ( 15.2MB) feedMP4 iPod Video ( 18.5MB) feed

    MP3 Audio ( 3.7MB) feed

    Feeds are available at iTunes and Mevio

    To submit an article, rant or editorial,
    log in to the Contribution Center