<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>Don Kiely's Technical Blatherings</title><link>http://sqljunkies.com/WebLog/donkiely/default.aspx</link><description>All Things Technical in .NET, SQL Server, and Security</description><dc:language>en-US</dc:language><generator>CommunityServer 1.0 (Build: 1.0.1.50214)</generator><item><title>Sun Acquires MySQL</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2008/01/16/103070.aspx</link><pubDate>Thu, 17 Jan 2008 02:01:17 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:103070</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/103070.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=103070</wfw:commentRss><description>&lt;p&gt;Wow. I didn&amp;rsquo;t see this coming, but &lt;a href="http://blogs.mysql.com/kaj/2008/01/16/sun-acquires-mysql/"&gt;Sun Microsystems has acquired MySQL&lt;/a&gt;. That blog post pretty much says it, about trying to figure out what this means. &lt;/p&gt;
&lt;p&gt;I think overall it is a good thing, particularly since the open source version of MySQL is more likely to flourish under Sun than other potential buyers, notably Microsoft. But I wonder what it means for enterprise users? &lt;/p&gt;
&lt;p&gt;Gut reaction: seems like a good fit. Best of luck to both companies, their employees, and users!&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Kudos to Patricia Baer for tipping me off before I heard about it from the regular sources!&lt;/em&gt;&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=103070" width="1" height="1"&gt;</description></item><item><title>Second Chance League Charity eBay Auction</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2008/01/08/102560.aspx</link><pubDate>Tue, 08 Jan 2008 18:43:35 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:102560</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/102560.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=102560</wfw:commentRss><description>&lt;p&gt;Please pardon this slightly commercial message, but the auction is a benefit for the &lt;a href="http://www.secondchanceleague.org/"&gt;Second Chance League&lt;/a&gt;, a sleddog rescue organization here in Fairbanks, Alaska. (I&amp;rsquo;m currently president of SCL, but we have a lot of very talented and enthusiastic volunteers who work with dogs.)&lt;/p&gt;
&lt;p&gt;&lt;a class="style1" href="http://www.midnightmushingalaska.com/"&gt;Midnight Mushing&lt;/a&gt; has donated 2 beautiful anoraks to SCL for a fundraiser. The first one is &lt;a class="style1" href="http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&amp;amp;item=160197041286&amp;amp;ssPageName=ADME:B:EF:US:1123"&gt;now on eBay&lt;/a&gt; to be auctioned off.&lt;/p&gt;
&lt;p&gt;This anorak is a "2nd" but only because it has a very slight stain (that we could barely make out!!) on the back. Becky of Midnight Mushing apparel is a perfectionist and her clothing is beyond wonderful. This anorak is not only functional but super nice looking. The workmanship is beautiful and these anoraks will last a lifetime of outdoor Alaska--or any cold climate--use!&lt;/p&gt;
&lt;p&gt;All of the proceeds go to the Second Chance League in Fairbanks, Alaska, to support its mission of rescuing sleddogs and finding them good, forever homes.&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=102560" width="1" height="1"&gt;</description></item><item><title>SQL Server 2005 September BOL Refresh Available</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/12/10/99551.aspx</link><pubDate>Tue, 11 Dec 2007 01:17:02 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:99551</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/99551.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=99551</wfw:commentRss><description>&lt;p&gt;The September 2007 update for SQL Server 2005&amp;rsquo;s Books Online (BOL) is &lt;em&gt;finally&lt;/em&gt; available for download. The update has been available online since, well, September but this time it took the UE group forever to make the download available. Because of &amp;ldquo;technical issues,&amp;rdquo; whatever they might be.&lt;/p&gt;
&lt;p&gt;Anyway, &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=be6a2c5d-00df-4220-b133-29c1e0b6585f&amp;amp;DisplayLang=en"&gt;go grab it&lt;/a&gt;*. An updated BOL is one of your more valuable SQL Server resources.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;* No guarantees the link will work forever, or even for very long. But Google always knows.&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;

&lt;p&gt;&lt;em&gt;Update: BOL is now part of Microsof Update! How long has that been? Forever, and&amp;nbsp;I just noticed it? Either way, cool!&lt;/em&gt;&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=99551" width="1" height="1"&gt;</description></item><item><title>PDC Returns to L.A., October 2008</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/12/09/99095.aspx</link><pubDate>Sun, 09 Dec 2007 13:11:10 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:99095</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/99095.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=99095</wfw:commentRss><description>&lt;p&gt;Microsoft has just announced that &lt;a href="http://msdn.microsoft.com/pdc2008"&gt;PDC&lt;/a&gt; (Professional Developers Conference) will be back 27&amp;ndash;30 October 2008 in Los Angeles. That&amp;rsquo;s good.&lt;/p&gt;
&lt;p&gt;But it will be interesting to see how they uniquely position PDC versus &lt;a href="http://www.microsoft.com/events/teched2007/default.mspx"&gt;TechEd&lt;/a&gt;*, now that TechEd has been separated into separate developer and IT weeks in Orlando.&lt;/p&gt;
&lt;p&gt;* Interesting link for TechEd: &lt;a href="http://www.microsoft.com/events/teched2007/default.mspx"&gt;http://www.microsoft.com/events/teched2007/default.mspx&lt;/a&gt;. The link says 2007, but at the moment it it is about TechEd 2008.&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=99095" width="1" height="1"&gt;</description></item><item><title>Is Vista Not Ready for Laptops?</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/12/05/97691.aspx</link><pubDate>Wed, 05 Dec 2007 13:33:47 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:97691</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/97691.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=97691</wfw:commentRss><description>&lt;p&gt;I attended a lot of sessions at &lt;a href="http://www.devteach.com/"&gt;DevTeach&lt;/a&gt; in Vancouver last week. It&amp;rsquo;s one of my favorite conferences because it is relatively small and therefore intimate, yet it attracts some amazing speakers, including some fine speakers from Microsoft.&lt;/p&gt;
&lt;p&gt;Unlike some conferences, all speakers deliver their sessions from their own laptops instead of from a desktop machine provided by the conference. Not surprisingly, most speakers are running Vista since it is Microsoft&amp;rsquo;s latest and greatest client OS.&lt;/p&gt;
&lt;p&gt;But it struck me at how many problems speakers were having with Vista. I&amp;rsquo;m not sure I attended a single session where some problem didn&amp;rsquo;t arise (but maybe I&amp;rsquo;ve blanked the good experiences out of my memory). One speaker couldn&amp;rsquo;t get the projector to work with Vista without technical help from the A/V support staff, then the magnifier was so small as to be worthless, making it hard to see important stuff. Many machines were slowed to a crawl, presumably from the combined performance-sucking power from PowerPoint and Vista&amp;rsquo;s Aero interface, not to mention Visual Studio or SQL Server Management Studio.&lt;/p&gt;
&lt;p&gt;The carnage was impressive. It seems that Vista pushes the limits of laptop technology. Apparently the OS demands not only a new laptop but a top of the line version of the laptop with all the processor and memory you can throw at it.&lt;/p&gt;
&lt;p&gt;And me? No problems at all. I had one issue with Diskkeeper kicking in during a session but I shut that off and problem was over. PowerPoint, Visual Studio, and whatever else I had to run, no problem.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m running Windows XP. I think I&amp;rsquo;ll stick with it for a while longer, maybe even after I replace my three-year-old laptop. Sorry, Microsoft!&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=97691" width="1" height="1"&gt;</description></item><item><title>Another Reason to Attend DevTeach</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/11/28/95112.aspx</link><pubDate>Wed, 28 Nov 2007 20:06:38 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:95112</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/95112.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=95112</wfw:commentRss><description>&lt;p&gt;&lt;a href="http://www.devteach.com/"&gt;DevTeach&lt;/a&gt; is one of the very fun conferences I speak at regularly, based in Canada. It is small, intimate, attracks some great speakers, and has support from Microsoft. There has long been plenty of good reasons to attend, as indicated by its motto, training you just can&amp;rsquo;t get any other way.&lt;/p&gt;
&lt;p&gt;But now there is another reason: Beer! I&amp;rsquo;m blown away, but during the afternoon break they set out beer. And none of the 3% stuff either, this is 5%.&lt;/p&gt;
&lt;p&gt;So it should be an interesting afternoon of sessions. Thank heavens I did my only session today right after lunch and before the alcohol flowed! Beer and SQL Server encryption just don&amp;rsquo;t mix.&lt;/p&gt;
&lt;p&gt;Now, if I only liked beer&amp;hellip;. Oh well.&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=95112" width="1" height="1"&gt;</description></item><item><title>Is SQL Server 2005's Surface Area Configuration Tool Cluster Aware?</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/11/12/92286.aspx</link><pubDate>Mon, 12 Nov 2007 22:22:52 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:92286</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/92286.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=92286</wfw:commentRss><description>&lt;p&gt;At &lt;a href="http://www.devconnections.com/shows/FALL2007SQL/default.asp?s=114"&gt;SQL Server Magazine Connections&lt;/a&gt; at &lt;a href="http://www.devconnections.com/"&gt;DevConnections&lt;/a&gt; in Las Vegas last week, I had the opportunity to geek out on SQL Server security for a full day at the end of the conference. Attendance was great and I hope that everyone left with a solid foundation of understanding of SQL Server security.&lt;/p&gt;
&lt;p&gt;One question that came up was about the Surface Area Configuration utility that ships with SQL Server 2005. The question was whether SAC is cluster-aware. At the time I was showing the command-line version of the tool, but it really applies to both that and the GUI tool. Showing my developer bias, I didn&amp;rsquo;t know the answer but promised that I&amp;rsquo;d find out.&lt;/p&gt;
&lt;p&gt;The answer is that yes, it is cluster aware, at least to the extent that you can configure remote computers with it. In the GUI version of the tool, use the Change Computer link on the opening page:&lt;/p&gt;
&lt;p align="center"&gt;&lt;img alt="" src="http://www.sqljunkies.com/WebLog/photos/donkiely/images/92283/416x375.aspx" border="0" /&gt;&lt;/p&gt;
&lt;p&gt;In the command line version of the tool, use the -S switch to specify the name of the remote computer. If you leave off this switch, SAC connects to the local computer.&lt;/p&gt;
&lt;p&gt;If anyone has specific experiences using SAC in a cluster environment, I&amp;rsquo;d love to hear about them!&lt;/p&gt;
&lt;p&gt;By the way, if you&amp;rsquo;re not familiar with the command line version, it is a handy way to export and import settings, making it relatively painless to configure multiple SQL Server instances the same way. See the &lt;a href="ms-help://MS.SQLCC.v9/MS.SQLSVR.v9.en/sqlcmpt9/html/f33be2c5-a8b0-4feb-bc66-926aebea0e2b.htm"&gt;sac Utility&lt;/a&gt; entry in BOL for more information.&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=92286" width="1" height="1"&gt;</description></item><item><title>DebuggerTypeProxy Proxy Class is Compiled into Release Build</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/11/16/92280.aspx</link><pubDate>Fri, 16 Nov 2007 21:50:21 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:92280</guid><dc:creator>donkiely</dc:creator><slash:comments>1</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/92280.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=92280</wfw:commentRss><description>&lt;p&gt;I recently did a session about debugging ASP.NET applications at the &lt;a href="http://vicdotnet.org/Default.aspx"&gt;Victoria .NET Developers Association&lt;/a&gt; in Victorial, B.C. It was a fun meeting, and as an Alaskan from Fairbanks I always feel a special bond with my Canadian peers down south!&lt;/p&gt;
&lt;p&gt;I also had the opportunity to meet &lt;a href="http://www.kencox.ca/"&gt;Ken Cox&lt;/a&gt;, who I&amp;rsquo;ve long known through &lt;a href="http://visualstudiomagazine.com/"&gt;Visual Studio Magazine&lt;/a&gt; but had never met. He and I have written&amp;nbsp;the majority&amp;nbsp;of the First Looks reviews in the magazine for years. I&amp;rsquo;ve always thought that he got the coolest products to review, and now I know that he has thought the same thing about me!&lt;/p&gt;
&lt;p&gt;Ken asked an interesting question during the session, one that I had never explored. I was showing the DebuggerTypeProxyAttribute attribute, which lets you substitute an entirely different class for display in Visual Studio 2005&amp;rsquo;s Locals window (as well as other debugging windows where object variables are displayed). It&amp;rsquo;s a cool way to simplify the display of complex objects for debugging, although it can easily be abused to make debugging &lt;em&gt;harder&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;He asked whether the proxy class&amp;mdash;used as the substitute display object&amp;mdash;is compiled into&amp;nbsp;the release build of the assembly. I didn&amp;rsquo;t know, but promised to find out. &lt;/p&gt;
&lt;p&gt;Turns out that the proxy class is indeed included in the release build. Which, now that I know the answer, makes sense. There really isn&amp;rsquo;t anything special about the proxy class, and it is conceivable that it could be used for other purposes in the application. In the example I showed, the proxy class was internal to the class it was substituting for in the debug windows, but that isn&amp;rsquo;t a requirement; it is usually more convenient though.&lt;/p&gt;
&lt;p&gt;For the compiler to exclude the class from the assembly, it would have to look at the DebuggerTypeProxy attribute and remove the code before compiling. But that raises all sorts of dependency issues that I&amp;rsquo;d rather not rely on the compiler to handle. Instead, a developer could use conditional compilation directives to remove the code, if it wasn&amp;rsquo;t needed in the release build.&lt;/p&gt;
&lt;p&gt;A tip of the anorak to Ken for a great question!&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=92280" width="1" height="1"&gt;</description></item><item><title>World's Simplest Recursive CTE?</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/11/05/82559.aspx</link><pubDate>Mon, 05 Nov 2007 13:17:28 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:82559</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/82559.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=82559</wfw:commentRss><description>&lt;p&gt;At SQL PASS this year, I did a session about Common Table Expressions in SQL Server 2005. I had endeavored to come up with an extremely simple recursive CTE, but wasn&amp;rsquo;t creative enough at the time. &lt;/p&gt;
&lt;p&gt;But I revisited the problem in preparation for an updated CTE session at &lt;a href="http://www.devconnections.com/shows/FALL2007SQL/default.asp?s=106"&gt;DevConnections&lt;/a&gt; this week, and came up with this:&lt;/p&gt;&lt;font color="#0000ff" size="5"&gt;
&lt;p&gt;&lt;font size="2"&gt;WITH&lt;/font&gt;&lt;/font&gt; SimpleCTE&lt;font color="#808080"&gt;(&lt;/font&gt;Number&lt;font color="#808080"&gt;)&lt;/font&gt; &lt;font color="#0000ff"&gt;AS&lt;br /&gt;&lt;/font&gt;&lt;font color="#808080"&gt;(&lt;br /&gt;&lt;/font&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SELECT&lt;/font&gt; 1&lt;br /&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UNION ALL&lt;br /&gt;&lt;/font&gt;&lt;font color="#0000ff"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SELECT&lt;/font&gt; &lt;font color="#808080"&gt;*&lt;/font&gt; &lt;font color="#0000ff"&gt;FROM&lt;/font&gt; SimpleCTE &lt;font color="#0000ff"&gt;WHERE&lt;/font&gt; 0&lt;font color="#808080"&gt;=&lt;/font&gt;1&lt;br /&gt;&lt;font color="#808080"&gt;)&lt;br /&gt;&lt;/font&gt;&lt;font color="#0000ff"&gt;SELECT&lt;/font&gt; &lt;font color="#808080"&gt;*&lt;/font&gt; &lt;font color="#0000ff"&gt;FROM&lt;/font&gt; SimpleCTE&lt;/p&gt;
&lt;p&gt;No guarantees that I couldn&amp;rsquo;t get it even simpler, but this is probably what I&amp;rsquo;ll show this week. There may be another option for the SELECT * part of the CTE, but I&amp;rsquo;m not seeing it right now.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;BUT! Obviously, this is the result of a thought experiment, and is not practical for anything else I can think of. Don&amp;rsquo;t take this as any kind of recommended practice!&amp;rsquo;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=82559" width="1" height="1"&gt;</description></item><item><title>SQL Injection and Motherhood</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/10/11/73189.aspx</link><pubDate>Thu, 11 Oct 2007 17:11:00 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:73189</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/73189.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=73189</wfw:commentRss><description>Okay, this is just too funny!&lt;br&gt;&lt;br&gt;
&lt;img src="http://imgs.xkcd.com/comics/exploits_of_a_mom.png"&gt;

&lt;br&gt;&lt;br&gt;From &lt;a href="http://xkcd.com/"&gt;XKCD, a webcomic of romance, sarcasm, math, and language&lt;/a&gt;.&lt;br&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=73189" width="1" height="1"&gt;</description></item><item><title>Fall Comes to Fairbanks</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/09/16/64944.aspx</link><pubDate>Sun, 16 Sep 2007 23:17:11 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:64944</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/64944.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=64944</wfw:commentRss><description>&lt;p&gt;Fall hasn&amp;rsquo;t just come to Fairbanks, Fall is almost over. Tonight we should get the first frost here in the hills outside town. It&amp;rsquo;s been a wet, rainy day, so the dog yard is pretty muddy. Snow level is supposed to be about 2,000 feet, still well above us.&lt;/p&gt;
&lt;p align="center"&gt;&lt;img src="http://www.sqljunkies.com//WebLog/photos/donkiely/images/64942/281x375.aspx"&gt;&lt;/p&gt;
&lt;p&gt;Carol and I spent a lot of time this summer building two free-run pens on either side of our main dog yard. We&amp;rsquo;re gradually building up the number of dogs in each, with the goal that ultimately everyone will be loose, at least when we&amp;rsquo;re home. (Since I work at home, it is relatively few hours each week that we&amp;rsquo;re both gone.) I took the picture above from the newest pen, and the photo looks from it through the dog yard and beyond into the other free-run pen. You can just see Crowe&amp;rsquo;s head at the bottom, with Irish looking toward me. Misty is the white dog looking from the dog yard, along with several other indoor dogs. &lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=64944" width="1" height="1"&gt;</description></item><item><title>Share with Family and Friends: SecurityCartoon.com</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/09/16/64793.aspx</link><pubDate>Sun, 16 Sep 2007 15:52:12 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:64793</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/64793.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=64793</wfw:commentRss><description>&lt;p&gt;There&amp;rsquo;s a cool new cartoon series that deals with security for end users, &lt;a href="http://cgi.cs.indiana.edu/~markus/cartoon/"&gt;SecurityCartoon.com&lt;/a&gt;. It&amp;rsquo;s sometimes silly, but it gives good explanations of email, phishing, and general malware for non-tenchical people. It comes from Drs. Sukamol Srikwan &amp;amp; Markus Jakobsson&amp;nbsp;of the computer science department of Indiana University. Based on their bios, they have some pretty solid security credentials.&lt;/p&gt;
&lt;p&gt;Check it out, then share with family and friends!&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=64793" width="1" height="1"&gt;</description></item><item><title>HTML 5 Working Group</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/06/13/36764.aspx</link><pubDate>Wed, 13 Jun 2007 23:43:23 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:36764</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/36764.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=36764</wfw:commentRss><description>&lt;p&gt;Wow. I just joined the World Wide Web Consortium&amp;rsquo;s HTML 5 Working Group as an &amp;ldquo;Invited Expert.&amp;rdquo; I had no idea that mere mortals could partake, particularly without being a member of a W3C member organization. &lt;/p&gt;
&lt;p&gt;Should be interesting, but I have no idea what I&amp;rsquo;m in for. All I know so far is that all of a sudden far more emails are making their way through my inbox.&lt;/p&gt;
&lt;p&gt;You can see the current state of the spec &lt;a href="http://www.whatwg.org/specs/web-apps/current-work/"&gt;here&lt;/a&gt;. Definitely a work in progress, one that won&amp;rsquo;t be finished for a couple of years.&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=36764" width="1" height="1"&gt;</description></item><item><title>Geeking Out on SQL Server 2005 Security at DevConnections</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/06/11/36222.aspx</link><pubDate>Mon, 11 Jun 2007 21:40:53 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:36222</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/36222.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=36222</wfw:commentRss><description>&lt;p&gt;I just found out that I&amp;rsquo;ll be doing a full day, post-conference session on SQL Server 2005 security at SQL Server Magazine Connections at &lt;a href="http://www.devconnections.com/"&gt;DevConnections&lt;/a&gt; in Las Vegas this November.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m excited beyond words! I&amp;rsquo;ve wanted to do this for a long time, and we&amp;rsquo;re going to geek out on keeping data safe from villans.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s the draft description:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;There are few corporate assets as valuable in the information age as data. Enterprises spend billions to collect and generate it, slice and dice it in every conceivable way to mine marketplace intelligence from it, and replicate and back it up using elaborate, redundant schemes. Yet it is all too common to slack on security. Sure, SQL Server 2005 is designed to be "secure by default," but once you add databases and start letting users and their applications access the server you have already poked holes in the security. SQL Server comes with plenty of features that let you secure data, but it can be hard to get a handle on the right ones to use in your environment. During this day of security, we'll explore myriad security features in SQL Server 2005, including granular permissions and how to design an effective authorization system, owners and schemas, and how they can help secure a database, the security issues and dangers with running SQL-CLR code, how to run T-SQL code in different security contexts, the comprehensive encryption features that can protect data, creating and enforcing password policies, how SQL Server protects catalog views and secures metadata, protecting against SQL injection attacks on the server, and more. You'll see lots of code and get lots of practical ideas for how to secure your database. Prerequisites: You'll need to have a good understanding of the basic database features and functions of SQL Server for this workshop, and it helps to have butt heads with SQL Server a time or two trying to get something to work without completely disabling security.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;I&amp;rsquo;ll post more later as I develop the outline and contents.&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=36222" width="1" height="1"&gt;</description></item><item><title>OWASP Top Ten, 2007 Edition</title><link>http://sqljunkies.com/WebLog/donkiely/archive/2007/06/11/36187.aspx</link><pubDate>Mon, 11 Jun 2007 16:55:51 GMT</pubDate><guid isPermaLink="false">d2584c15-f6ef-46f7-a2d4-24fc0e143e76:36187</guid><dc:creator>donkiely</dc:creator><slash:comments>0</slash:comments><comments>http://sqljunkies.com/WebLog/donkiely/comments/36187.aspx</comments><wfw:commentRss>http://sqljunkies.com/WebLog/donkiely/commentrss.aspx?PostID=36187</wfw:commentRss><description>&lt;p&gt;&lt;a href="http://www.owasp.org/index.php/Main_Page"&gt;OWASP&lt;/a&gt;, the Open Web Application Security Project, has finally released its updated list of &lt;a href="http://www.owasp.org/index.php/Top_10_2007"&gt;Top 10 critical Web application security flaws&lt;/a&gt;. If you do Web development, I rather stronly suggest that you be familiar with all the vulnerabilities on the list and how to avoid them. If you take care of all 10, you&amp;rsquo;ll have a reasonably secure site. It won&amp;rsquo;t be totally secure because new attacks appear every week, and security takes vigilence.&lt;/p&gt;
&lt;p&gt;Practice safe computing!&lt;/p&gt;&lt;img src="http://sqljunkies.com/WebLog/aggbug.aspx?PostID=36187" width="1" height="1"&gt;</description></item></channel></rss>