Category: Editorial

  • The $50,000 Laptop

    Hopefully you won't lose this amount of data.
    Hopefully you won’t lose this amount of data.

    wrote a long time ago about the value of the data on a laptop being worth more than the hardware. That’s certainly true for me, and I very much worry more about losing the data on my devices than the any of the devices themselves. I use sync services to keep a backup of most things, but I still worry about losing any of my bits.

    There was a large study competed recently, called The Billion Dollar Lost Laptop Program, which examined 329 organizations. The idea was to find out the economic costs of lost laptops related to various public and private entities. The conclusion? The average value of a lost laptop, just one laptop, is $49,000. The conclusions say that least expensive part of losing a laptop of replacing the hardware.

    As we would expect, most losses occurred away from the office, however it’s not known how many of these losses might be targeted thefts. Many of the losses did occur through theft, which is disturbing when most of these disks did not have encryption in place. This was true even when confidential data was contained on the laptop.  It is nice to see that companies that realize they were targets of theft, as opposed to losses, typically do use encryption.

    As the study shows, there are a lot of costs that go into replacing a laptop. Many people don’t think of all of these costs, and even if the costs are double what they should be, these are still substantial costs for companies to absorb. The costs will only go up in the future, especially as more and more people move from desktop workstations to laptops.

    The one positive note? Encrypting the laptop almost cuts the loss in half. A good reason to require encryption on all laptops.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.

  • Hacked

    Getting hacked is never fun, and it can happen in so many ways.
    Getting hacked is never fun, and it can happen in so many ways.

    I’ve been hacked before. My personal web site has been hacked with a variety of injection and XSS attacks over the years. None too serious, and I’ve had backups that allowed me to fix things fairly easily, especially once I had a copy of Data Compare, which saved me a lot of time. At SQLServerCentral, we’ve been hacked as well, though not in a long time. I think we’ve closed most of the security holes, and I haven’t had any issues to deal with in quite some time.

    However as I was reading a note from Richard Douglas about being hacked, it brought back memories of working at JD Edwards. Richard was hacked at work, on his personal system. At JD Edwards, we were required to lock our workstations at all times when we were not physically in front of them. We also had two accounts: a normal user and a domain admin “privileged” user. As you might expect, there were numerous lapses of people walking to the kitchen or bathroom and forgetting to lock their workstations. It was considered fair game to change settings, send email to our group, even place semi-SFW pictures on someone’s desktop. It was quite embarrassing to be caught, and was much more a an effective security reminder than a reprimand from our boss.

    However there is a serious security problem here. Many of us would use our privileged account all too often, since it was a hassle to log out and back in. The “run as” option didn’t work well for some applications, and we were less secure than we probably should have been. If someone walking by, whether an employee, guest, consultant, or someone else noticed SSMS running, how long would it take them to type:

      sp_addlogin 'joeuser', 'joeuser'
      sp_addrole 'joeuser', sysadmin

    I type quickly and that took me less than 30 seconds. I’m sure even a slow typist could get that entered, and erased, inside of a minute. That might result in a serious security breech, if the system to which you were connected contained HIPAA, PCI, or any identity information. Perhaps even worse these days is the chance someone might attach a USB key logger to your keyboard.

    You might be safe in your environment, but you can never be sure. A little care in ensuring you are not unnecessarily exposing security holes, and making sure that outsiders are always escorted can prevent embarrassing incidents from occurring.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.

  • The Year 2013

    My predictions for 2013.
    My predictions for 2013.

    Today is the first day of a new calendar year. I’m hoping most of you have the day off, and I certainly do, but I wanted to ring in the new year with a look forward. What will happen in 2013? I think it’s incredibly hard to predict, but I’ll take a chance and make a few predictions.

    Mobile devices will continue to grow in popularity. No great surprise there for many of you, but I think that we will see more smartphones sold than regular phones in 2013. With a large market of used devices and the constant push of new devices, new form factors and sizes, I truly think that we will be in a very data centric world most for most of the time in 2013. Between tablets and laptops sporting cellular connections and pocket sized smartphones, most of us (including non-technical people) will have some type of data consumption device in our lives.

    What does this mean for data professionals? I don’t think it matters which platform sells the most phones because all of them will be looking for more data-drive applications. Whether these are apps, HTML5 websites, or something new, all of us that manage data will have to deal with more and more mobile delivery of information in 2013. That means security, especially XSS and injection attacks, will be more of a concern. Good backups, warm copies of data in the event of vandalism, and comprehensive auditing will be something we need to focus on implementing.

    I think we’ll continue to see more and more BYOD at work, though with the nature of security being what it is and constant data loss, there will be a push to work through more virtual interfaces like RDP. It won’t succeed and we’ll have more data breeches in 2013, including some big ones as Verizon as predicted. Encryption will become a bigger battle in 2013, with more companies asking for personal devices to implement encryption. I’m not hopeful that this will become the norm

    Lastly, I’ll predict that we see a change for SQL Server. I think that some of our instances will move away from SAN storage pools and move to dedicated SANs or perhaps back to local storage. We will get more SSD storage implemented in new system, perhaps the standard becoming 2-4 SSDs for new hardware. I think flash is here to stay, at least until high speed optical storage becomes economical.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.

  • 2012 in Review

    It was an interesting year, though not quite this interesting.
    It was an interesting year, though not quite this interesting.

    It’s the end of 2012, but not the end of the world. As I look back at this past year, I think it’s been a great year for SQL Server and data professionals. The big news of the year was the release SQL Server 2012. This is a great step forward for the platform with a number of enhancements that both make our jobs easier, as well as challenge our skills. The addition of AlwaysOn provides a number of great new ways to scale out SQL Server as well as ensure high availability. Power View, columnstore indexes, and the BI Semantic Model allow for better BI applications, and who could applaud the undo/redo features in Integration Services. There are lots of great things in this new release for the technical staff, though the licensing changes might cause some companies to reconsider or delay their upgrade plans.

    We had more opportunities to use SQL Server in new ways, many of them with the expansion of cloud services. Amazon added SQL Server to its RDS platform, allowing quick and easy deployment of SQL Server in the AWS cloud. SQL Azure lost its name, as it was folded into Windows Azure, but it was enhanced throughout the year with a number of releases.

    SQL Server is still one of the most secure database platforms available, though it did require patching for a critical flaw in an ActiveX control. There have been fewer advisories and issues with SQL Server 2008 and later than any of the other RDBMS platforms. That’s good news as security continues to be an ongoing challenge for many organizations. However the security of the platform doesn’t mean that DBAs can relax. There has been no shortage of data loss in 2012, mainly though laptop loss or insider actions. Everyone should continue to be vigilant about security, auditing, and especially SQL Injection.

    The positive side of 2012 were lots of events for SQL Server professionals. There were 79 SQL Saturday events in 2012. That’s amazing to me and it’s something Andy Warren and I never would have imagined when SQL Saturday #1 took place in Orlando in 2007. A lot of the success is due to Karla Landrum’s work in helping organize the events. Many thanks and congrats to Karla for an amazing job.

    I only attended 4 of these because I participated in the SQL in the City tour that Red Gate Software put on. We held 8 fantastic events in the US and UK this past year, and we will put on a few events next year as well. Grant Fritchey and I will also be visiting some SQL Saturdays in 2013, and I hope to see some of you there. Along with Connections, SQL Server Live, the PASS Summit, and a number of other free events, there’s a lot of great training and knowledge being shared in the SQL Server community. If you’ve got pictures or blogs of your time at an event, please share them in the discussion.

    Here at SQLServerCentral I had a few milestones as well. Our Stairway Series took off and we published over 120 articles on various topics. We crossed over 1.5 million registrations, and receive over a million unique visitors every month, which are fantastic milestones for us. ASKSSC continues to grow as well for those people that prefer a Q&A format rather than a discussion. Based on comments and emails, the site continues to help educate and inform many data professionals on a daily basis. I hope that you have found us to be a valuable resource in your job and I hope we can continue to do so in 2013. If you have suggestions, comments, or critiques, please feel free to share them with us.

    Happy New Year and my best wishes to each of you.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.