Tag: software development

  • Secure Coding

    I was looking recently for some sort of guideline that would help me ensure that code was securely written. I stumbled upon the CERT standards, of which there are few, but one that seemed interesting was this one on Oracle and Java. I thought this first standard was a great explanation of good and bad code that you could use for this particular problem.

    I looked for something similar from Microsoft. I found this, which seems more like a random collection of links that don’t teach, or lead, anyone through the ideas of how to write better code.

    In some ways, Microsoft has produced a microcosm of the Internet. A mish mosh of lots of information with no organization applied at all.

  • The Gadget Itch

    Many of the people that work in technology are interested in gadgets and hardware as much as software. Not all of us, but many of us have had side projects where we’ve melded hardware and software together. For those of us that are older, and started working with computers decades ago, that might have been the only way that we could get a computer system to work.

    I’m glad that I still find people interested in hardware. My son recently built his own gaming computer from parts, and I’m hoping to distract him from some games and get him to help me build some robots with a Raspberry Pi computer and BrickPi add-on board. However it’s not just kids as I’ve seen a number of people at Red Gate working with hardware to build a variety of interesting projects.

    This week I’m wondering if any of you are interested in creating your own devices. If you had the chance to build a device or gadget for work, what would it be? A panic button when there’s a problem that you can press and instantly set of Star Trek “red alert” sirens? A status display based on your continuous integration builds? The question this week is:

    What would you build if you had a parts list like this one?

    Whether you’ve started actually assembling things or you’re just dreaming of something, or perhaps even just seen something that’s intrigued you, let us know. I actually think this might be a fun competition of some sort for an event, perhaps a hacking competition across a couple hours at a SQL Saturday or conference.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 1.8MB) podcast or subscribe to the feed at iTunes and LibSyn. feed

    The Voice of the DBA podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

  • Continuous Delivery Visualization

    A good one, one of the better diagrams I’ve seen.

    CD

    From http://markosrendell.wordpress.com/2014/03/03/practical-benefits-of-continuous-delivery/

    Now if we can get tooling and processes to make this work reliably for databases.

  • Good Practices for Software Development

    Would you post your password on a wall in your office? Of course not, because other employees, the cleaning crew, even guests walking around your office would be able to access your system with your account. When I read Brian Kelly’s post on passwords in files, that’s what I thought of. Sticking credentials in a file, where they’re subject to any kind of search, is a bad idea.

    However this happens all the time. Combine this with a few other “common practices” like using sa to connect to a database and building dynamic SQL, and you might as well just set blank passwords and invite someone to have fun with your database. It’s sad that we continue to see these types of software development practices in 2014, and especially poor to see them from companies that sell software.

    There is so much information out there on building software that is of higher quality and is much more secure. However all too often I find developers just aren’t implementing these practices. There are probably a myriad of reasons why, and I wish we had more ways to better train people, disseminate the information, and enforce it’s use.

    Ultimately we can only do what we can. However I’d encourage those of you that see poor practices taking place to have a word with the developer (internally), or send a note to the vendor. If it’s more important to make a few more dollars than implement better practices, I’d encourage you to publicly call some attention to the matter. Maybe a little exposure to the dark side of software development will pressure managers to require more secure work over time.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 2.0MB) podcast or subscribe to the feed at iTunes and LibSyn. feed

    The Voice of the DBA podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.