Category: Editorial

  • Pride and Security

    Do you love your job? I do.

    The weakest link in most security schemes is the human. We know that there are regular breaches of trust by employees, mistakes made (fat fingers, misconfigurations and more), and supposed favors done by someone with trusted access that send data to criminals. Social engineering, in a variety of forms, preys on the trusting nature of most people to gain unauthorized access, and unfortunately, it often works.

    Part of social engineering is the inherent trust for others that most of us have. Part of it is the desire that most people have to help others. However I think a part of it is also the attitude that many workers have when they aren’t treated well. When employees don’t feel they are a part of the company family and just work for a paycheck, they are less vigilant or caring about safeguarding the digital assets, and sometimes physical assets, of the company.

    If you had more pride in your employer, wouldn’t you be a little more careful in caring for the company and its assets? I think most people would. I don’t have any data on this, but I bet that the companies where people take pride in their work are more secure. Employees probably know more about each other, and problem recognize a larger percentage of the company. Workers will be a little more observant and protective if they feel that the company is “theirs.”

    One of the best things management can do to raise the level of security at the company, and build a better organization, is to ensure they are creating an environment that people enjoy and take pride in. That comes from showing respect, consideration, and fair treatment of all employees. It’s not even that hard to do, just be a decent human that does what’s best for everyone in the company, not just for the CEO.

    Steve Jones


    The Voice of the DBA Podcasts

  • The Connections Launch Event

    The SQLServerCentral track at SQL Server Connections

    The Spring SQL Server Connections conference will be one of the launch events for SQL Server 2012, the next version of the platform that we write about every day. This spring SQLServerCentral is sponsoring a track again, with Brad McGehee, Grant Fritchey, and myself speaking in one room. We’re all focusing on SQL Server 2012, trying to get ready to upgrade and use the new features.

    However we’re only a small part of the SQL Server track. SQLskills.com headlines the track, as they have for many years, with Kimberly L. Tripp, Paul Randal, and Jonathan Kehayias presenting some amazing information based on their years of experience (go to one of the SQLskills.com classes if you can). Paul and Kimberly have also invited a number of other great speakers, including Aaron Bertrand, Allen White, Brent Ozar, Glenn Berry, Mike Walsh, and more. These are the people that write many of books, blogs, and articles that you read to learn more about the SQL Server platform.

    The DevConnections conferences are a great place to not only learn about SQL Server, but also learn about all parts of the Microsoft technology stack. There are nine conferences in all taking place at the same time, covering Windows, Visual Studio, Sharepoint, Exchange, and more. There’s even a Cloud Connections, dealing with those issues that you’ll find when working with the Microsoft Azure products.

    It’s still winter in many parts of the US, so schedule your own “spring break” from work and come to Las Vegas this spring. The weather will be great, and you’ll have the chance to learn about all different type of Microsoft technologies and platforms in a fun environment. You can even take in an amazing show one of your nights in town and let your brain relax from all the tech talk during the day.

    Steve Jones


    The Voice of the DBA Podcasts

  • Be careful with your smartphone

    I love my iOS device and find it very handy.

    More and more tech professionals I know are carrying smartphones. There seems to be a split among technical people between iOS, Android, or WP7 platforms, but it seems that all the mobile OSes are extremely handy for system administrators. I know that I appreciate the ability to connect to email and other people when I’m away from my desk. If I were a production DBA, the ability to potentially fix something remotely, without the need to go to the office or back home, would be extremely valuable.

    However, carrying around a smartphone isn’t without a risk. The features and capabilities of the various mobile operating systems are a double edged sword. The power of the smartphone can easily be used for attacks against your network. This piece talks about hackers targeting the mobile platforms as another attack vector. That’s scary, especially as most of these mobile OSes were not designed to be secure.

    One of the very attractive parts of the Android platform is it’s openness. Anyone can build an app and sell it in the Android Marketplace. However that openness also means that the marketplace is a target for malware. While you might not like the Apple review process, it does offer some security. I’m not sure how the Windows Phone 7 platform is affected, but I would hope there is some security review. I also hope third party stores, like the Amazon Android store, will do some kind of security review to prevent malware.

    Ultimately if you are a privileged user on a corporate network, and you connect from your smartphone, you need to be extra careful. Set a password on your phone, don’t save passwords to trusted systems in your mobile browser, and be especially careful about scanning your system regularly.

    Steve Jones


    The Voice of the DBA Podcasts

  • Propose this to your boss

    If Nordstrom's can have an innovation lab, can't you?

    I’ve written a few times about the ways in which you could find interesting projects at work and potentially learn a few new skills while improving the ways your company uses technology. More and more companies are willing to allow side projects like the Google 20% time or the Atlassian FedEx days. My own company, Red Gate Software, implements this a few times a year as “Down Tools Week.”

    Many of you have replied that your companies are resistant to this, or your boss doesn’t think it’s a good idea. I have certainly had a few managers that felt that way, but I’ve also had success over time in changing their minds a bit. I’ve been able to get them to give me the chance to pilot ideas in a small way. Sometimes it’s taken years, but I’ve learned to play “long ball” and think about succeeding over time, not getting my way this week.

    One of the ways you can convince someone to give you a chance is to continue to show other examples of success from other companies. Nordstrom’s, not necessarily the place you’d expect to see IT innovation, has a video of how their lab enables them to build better applications. It might be worth saving this link, and even sending it to your boss with a proposal.

    If your boss is supportive, ask for a week to work on a project with another person or two and spec something out in your proposal. If your boss is skeptical, ask for a few half days across a month to work on something and build some basic prototype project. Even if it’s mocked up on paper, you can show the value of how an idea might work. If you get some support from your end users and customers, you might find yourself with a fun project to work on in 2012.

    Steve Jones


    The Voice of the DBA Podcasts