Tag: software development

  • A Secure Application Model

    I like the AppStore, but would like to be able to choose from other stores besides Apple's.

    Amazon introduced a Cloud Reader for the Kindle, and the Financial Times pulled their iPhone app out of Apple’s store and introduced an HTML5 web application. All of these moves point to the fact that companies are finding Apple’s 30% fees for revenue to be a bit onerous and want to find a way to reduce their costs. That makes sense, and my suspicion is that Apple will ease their terms at some point as companies move to their own web model of building and deploying applications instead of building native iOS apps.

    I don’t think the AppStore model is dying, however. One of the things that I have noticed in the apps between the iPhone and the Android devices at the ranch is that the quality of the iOS apps is higher. It’s rare that I have crashes, there is more consistency between the various interfaces, things work as you expect, and they run well. It’s not that Android apps are horrible, but outside of the large company apps, the quality of any particular app is likely to be lower. That’s expected because there is no gate that prevents someone from building a poor quality app and deploying it in the Android marketplace.

    However there’s another thing I take from this. The most important part of the app is the data or the content. Companies are arguing over who gets how much of the profits from various content delivery methods. Some companies think 30% is too much, some don’t. However, it doesn’t change things for the consumer since many of us will pay the same price, though I suspect we might pay more in an open market. If they could, companies might give away apps for free, but then charge a small amount for the information, which will add up over time to be more than the cost of an app right now.

    One of the things I like about the AppStore is that quality control check. While anyone can submit an app, Apple has been slow, and sometimes inconsistent in how the approve or reject the items. That’s good for quality, bad if you want an app that doesn’t meet Apple’s vague standards. I’d like a more open market, but I also want some quality standards. Windows has been open in that we’ve been able to download applications that anyone has written and install them. Windows has also suffered from the proliferation of malware as well as the poor quality of so many pieces of software that are available for download.

    In my ideal world, we’d have some secure application models, essentially app stores that were run by different companies. Amazon has an Android store, but I wish they had an iOS one as well (and WP7). Microsoft could run a store, but so could any other enterprises that had the resources to vet the software, manage a marketplace, and gain the trust of consumers. I could even see eBay getting into the game, allowing developers to auction off their software after it had received some stamp of approval from the company.

    That’s the direction I hope we are moving in, but I’m not sure if we’ll get there.

    Steve Jones


    The Voice of the DBA Podcasts

  • A Walkabout

    A great read. My wife and I considered this at one point.

    At one point when I was in college, I spent a few weeks touring around Europe. I had a bicycle with me, a backpack with a couple changes of clothes, and wandered throughout parts of France, Spain, and Italy, staying in hostels and living a carefree life. However my few weeks were nothing compared to what many students in Australia often do. I met a few dozen students at different times from down under that were on a walkabout from school, traveling around the world for a year, experiencing life on their own terms, far away from home.

    I was somewhat jealous, and I even considered joining them for an extended vacation of my own. I never did, but I’ve always wondered if I should have. My wife and I read One Year Off about seven or eight years ago and debated taking a walkabout the world with our kids, but decided against it. As I’ve gotten older, I’m not sure it’s the way I would want to live my life, but I admire those that can live like that. Personally, I’m not evens sure what I would do on a sabbatical, something that my company, Red Gate Software, has provided to a few of my co-workers.

    James Moore of Red Gate, is combining the idea of a sabbatical away from work with a walkabout in another country. As James looks forward to the future of software tools, he’s decided that reading feature/bug requests and doing customer surveys isn’t enough. James is actually touring the US, meeting with customers, watching their developers in action and trying to learn how database development is evolving in a rapidly changing modern world with cloud services, new version of SQL Server and ever increasingly complex applications.

    I don’t know how this walkabout will turn out, but I think it’s great that my company is actively trying to make sure that they solve the right problems, in the right way, for their customers. I think Red Gate has done a great job in building simple, intuitive, but incredibly useful tools over the last decade and I’m looking forward to seeing what James comes up with after this trip.

    Steve Jones


    The Voice of the DBA Podcasts

  • The Window Is Shrinking

    Security is important, but perhaps doubly so in the cloud.

    There have been a number of issues with Dropbox and their encryption process for files stored on their systems. This highlights some of the issues with cloud services, as I’ve talked about as well. I use Dropbox, but for any files that have identity information, I encrypt them locally and only store the encrypted versions.

    There have been quite a few issues with cloud-type services related to security, and at this point, I think it’s good. The press about the Sony hacks, the RSA issues, and others should be scaring consumers and management in companies into demanding better security from vendors. Without a strong emphasis on security from clients, cloud vendors have no reason to spend more effort on security than they do now. I am actually hoping that insurance doesn’t cover the Sony issues, which will help force companies to consider purchasing insurance specifically for security issues. That will force insurance companies to demand better security as well.

    That means the window for throwing together a service without a well thought out security plan is shrinking, and that’s good. We should have security on the mind as we write code. Building that habit takes training, but it also takes practice and requires management to buy into the need to spend some time implementing security throughout our code, and testing for potential issues.

    I look forward to the time when strong security exists in all applications, not bolted on as an afterthought, but designed in from the very beginning.

    Steve Jones


    The Voice of the DBA Podcasts

  • The Impact of Outages

    This is not what any of your clients want to see. So prepare for issues

    Are you going to start seeing more pressure for outages in applications? I suspect many outages are caused more by application issues than database ones, but those two are becoming very tightly linked as we look to more rapidly deploy features and enhancements in our applications, which often include database changes

    This outage from United shows that there can be a huge impact, not only financially, but also an inconvenience to clients and potential lost future business. A company might struggle to with future business after a large outage, especially when there are so many other choices easily available to consumers across the Internet.

    That brings to mind a very interesting problem as companies grow and look to build scalable systems. Large groups of servers require some level of standardization, mostly for the ease of management by IT workers as well as the ability to train future workers to understand the systems. However that standardization becomes a point of failure when there is a problem during an upgrade, or even a hack from some type of malware.

    I saw an interesting piece on how Netflix has tried to expect, and handle failures in the cloud, and a comment from Jeff Atwood that you ought have your own chaos monkey to regularly test your systems. Interesting advice, and in many cases, it’s probably good advice to ensure that both your systems and your people know how to deal with outages.

    You probably cannot eliminate outages, as Netflix and many other companies have learned. However you can work to ensure your people and systems know how to respond. I also wonder if having (at least) two versions of your systems out there at all times that work in a similar way might be a way to provide some tolerance against a single point of failure. I don’t know how you might implement this, but it might provide some protection against a failure in a completely homogeneous environment.

    Steve Jones


    The Voice of the DBA Podcasts