Sunday, October 23, 2005
Oktoberfest in Tulsa
The Tulsa Oktoberfest celebration is one of the top 10 in the country according to USA Today. That distinction is rightly earned. It's cheap to get in, it's huge, authentic yet diverse, and even with a 7-year-old in tow, it's quite a lot of fun.
If you find yourself with the hankering to drink great German beer (Spaten lager is quite good), eat sausages and gigantic desserts, and do the chicken dance every 10 minutes, you'll find a few thousand other like-minded individuals on top of the picnic tables under the big tent in Tulsa each year around this time. It's over far too quickly.
Oh well, back to the grindstone.
Wednesday, October 12, 2005
The Great Java Lie
The oft-touted Sun cliche' "Write once, run anywhere" should be followed by an asterisk.
*Depending on the version of JVM on your customer's PC.
I'm not quite certain if the blame can be placed solely on one entity, but in my mind, most of the blame falls on Sun Microsystems - Scott McNealy and Eric Schmidt, specifically - for being either very dishonest or very inept.
What we in the enterprise are seeing is an increasing number of vendor websites that carry with them exacting requirements for the JVM they expect to be installed on local PC's. As it happens, most of the requirements are for fairly old versions of the JVM. In other instances, vendors require versions of Microsoft's JVM - not Sun's, even though Sun wrote the damn thing to begin with.
Want proof? FedEx's website will not print to a locally attached label printer without JVM v1.3.x. Two other insurance websites require varying versions of 1.3.x - not the same as FedEx, mind you - in order to process employee benefit claims. McGraw-Hill requires Microsoft JVM version 3805 to be installed on your Windows 2000 SP4 PC if you wish to access their Construction Dataline service.
These companies are unabashed in dictating technology requirements to me, their customer. They "wrote once"...So if you want to "run it anywhere", you're damn well going to use the JVM around which their code was written.
Somehow it's my fault - the customer - that my company uses more than one vendor for unrelated services, and that they can't figure out how to architect a website with simple old HTML and server-side code.
They were told to use Java - they were sold a lie, and they bought it whole hog. They were told, "People can use your web services at home, at work, on their phone, on their refrigerator, their TV, everywhere!" While that may not be false, it's certainly not completely true.
Let's face facts.
95% or more of all internet traffic originates from or is destined for a PC. Not a toaster. Not a phone. Not an E15000.
Just a simple, standard, utterly ubiquitous Personal Computer.
So the problem is, I can't manage more than one version of JVM on a PC to be used by the browser - any browser. Nor should I have to.
The reason this problem exists, in my opinion, is because Sun has been utterly incompetent. With regard to managing features and functionality as they expand and refine Java, backwards compatibility is a phrase they've never heard.
Vendors specify a version of client-side Java software to access their website, not because they like it more, but because it's the only one that works. Sun hung these companies out to dry, by making significant-enough alterations to the JVM that a developer's code no longer works.
Who is to blame? Tough to say. The code can't be that bad, it works with a certain JVM right? If it doesn't work with a later version, how is it the developer's fault? Even so, who am I (a single customer) to tell them get their act together? It's easier for me to install a different JVM than it is for them to completely rewrite their website.
I admit that I've considered the problem to be our fault...maybe the issue is a combination of factors under my control - Windows 2000 SP4 and a million patches, Internet Explorer 6 and all it's patches, Windows entropy, etc. Maybe we won't have this issue on our new Windows XP machines (although I have no idea why not - the vendors are specific in telling us what JVM we need).
I just know that I should be able to download the latest JVM, install it on my new PC's using a standard image, and anything developed in Java up to that point in time should work.
It doesn't though. And when it doesn't, it's not my fault...just my problem.
I really and truly feel sorry for Google. Eric Schmidt has a history of turning everything he touches into finely polished, almost gilded, pieces of crap.
Take Novell for instance.
Schmidt made Novell relevant again by making TCP/IP a native protocol in NetWare. Then, in one fell swoop, he set it marching off the cliff by forcing Novell's internal developers to use Java for new products. The result? Servers that crash more than ever. Separate pools of memory for Java that are nearly impossible to manage. Products that can't co-reside with one another on the flagship NetWare platform. Customers who have cried for and lacked a unified administration console for upwards of 7 years. The list goes on and on.
The apple doesn't fall too far from the tree, and the tree from which he fell and has lived his life is one that's hell-bent on ruining Microsoft. He's not interested in making things great, he's interested in being better than Microsoft (which, incidentally, any great organization could do handily).
That said, I'm smart enough to see Java for what it means - and I'm not a developer. Java applications need to relegated to the intranet. Keep it out of the DMZ. Keep it off my PC's. Let me decide when my company needs an application built on Java - not the other way around.
Do you hear me FedEx????
Friday, October 07, 2005
Centralized Shared File Access
This group has requested that we develop a centralized location for this standard, and further allow them to centrally share these files. Given their size, and the fractional-T1 frame relay links we have connecting locations, the request has not been feasible.
However, I've recently read of a technology that may have some applicability here. We use NetWare and Nterprise Branch Office, which does provide sync capabilities via RSYNC. RSYNC doesn't provide for an elegant solution, nor one that is capable of resolving write collisions. Furthermore, the 'solution' should be transparent to our end-user community - a consistent standard we set for ourselves when improving on or replacing technologies.
The iServer solution from Tacit Networks however, appears that it may largely solve the problem for us. It lacks eDirectory integration, but it very intelligently handles file synchronization and caching over WANs in an appliance footprint. It's caching and sync engines are very intelligently designed, and they advertise functionality & performance that are LAN-like over WAN links. This will be a product I continue to investigate and watch.
If it weren't for ComputerWorld, I might not know this company existed. If you can only subscribe to and read one industry publication on IT, ComputerWorld should probably be it.
Wednesday, October 05, 2005
Sweating the small stuff
We're trying to simplify and consolidate our eDirectory tree, and make our remote sites easier to manage. The product we've been piloting is Novell's Nterprise Branch Office (NBO or BOMA if you will) v2.0. It has so much potential, yet it falls short in small areas that are important - and would be easy for Novell to fix.
One issue we have, is that it's very difficult to manage PC's and application distribution at sites running NBO. This is because, despite the marketing hype, NBO doesn't actually "cache the corporate tree's eDirectory". It maintains it's own separate tree, and populates it with user and group information from the corporate eDirectory tree - nothing more.
What's worse, if you use PC's with the Novell client at NBO sites, it's even harder to get that PC connected to your corporate tree via ZENworks. (We eventually found an undocumented, unsupported method for doing this, and are testing it now).
The other big problem is that NBO doesn't handle password changes or password policices in the corporate tree very well at all. We should be able to change a password in the main eDirectory tree, and that change should be immediately recognized by NBO - that's not the way it happens. If someone changes it at the far site via NBO's "Virtual Office" portal, that change should make its way to eDirectory.
The reality is that not many users actually use password self service tools proactively- certainly not in our environment, or many that I've seen as a consultant. This means the HelpDesk does a lot of password resets reactively. They can either do this from their admin console, or by opening up a web session to each server where the problem may occur (sounds like the bindery in NetWare 3.x, doesn't it?).
eDirectory and NetWare 4.x were supposed to save us from this mess. You log into the network, not the server. It was a tough concept to grasp at first, but it makes a lot of sense. NBO breaks all of that, sending us back in time some 15 years.
So much for technology making our lives easier...
Sunday, October 02, 2005
Follow-up - Certifiable
In her article, she says:
"I have found not only that a computer science degree is optional, but also
that many successful technologists don't have any degree at all. I've had great
employees who never finished college, and I've had wonderful employees who have multiple master's degrees."
The point, as she succinctly puts it - "I've found no correlation between degree and competency" - is that the pieces of paper by themselves aren't important.
In fact, by themselves, they're not even relevant.
I'm fairly confident she believes as I do, that attitude and aptitude are the most meaningful factors in evaluating candidates. This is encouraging, because she's the CIO and Managing Director at Chela Education Financing in San Francisco, and we share an important belief for managers & executives who endeavor to build great organizations.
Certainly its easier for hiring managers to look for nice certifications, and nobody gets fired for hiring MBA's or MCSE's, but how often does taking the easy road lead to the best possible outcome?
Personally, I view companies that require degrees or certifications of their employees as types of bigots. They're effectively pre-judging candidates before they've met them, based on superficial and demonstrably irrelevant standards. (Ever met a "paper-CNE" or "paper-MCSE"? I have.)
I don't think they need to be tried in a court of law, but I do think they need to be called to the mat for this practice - publicly - and that self-respecting technology professionals should avoid them like the plague.
If you're on the wrong side of this fence (be honest with yourself) - keep in mind that people like me could work wonders for your company; and we won't come near you until you wake up and realize that talented people don't come with easy to read labels...You actually have to talk to us.
Friday, September 30, 2005
The news of late / on race & entitlement
"I think it may be fair at this point to say that the governments of New
Orleans and Louisiana will be found utterly incompetent at best, and
irreversibly corrupt at worst."
With the recent resignation of the New Orleans Chief of Police and a probe into allegations of looting by NOPD officers, I think it's now fair to say that he doesn't want to stick around to be drilled by the press about his department's handling of post-hurricane security. The reality may be worse. If they suspect more severe - even criminal - repercussions as a result of their negligence, it's likely that more of those in positions of responsibility may take a similar exit.
On another note, I'm sometimes forced to watch "Dr. Phil" in the mornings on videotape - my wife owns the remote before work, and she catches up on a few shows each A.M. I at least appreciate that he finds very tactful ways to give very confused people a reality check, and am comforted that his views and advice are consistent with (or better than) my own opinions on a given subject.
The last show of which I saw a part, was on the topic of race. One of his guests was a black man that was perceived by his black friends as "too white". There were some humorous bits of video to establish both sides of the argument, but the thing that stood out was the guest's comments on Affirmative Action. I don't have the exact the exact quote, but he was very much opposed to the premise on which Affirmative Action is based. He said (paraphrasing) "I want to be advanced based on my merits."
I had written - and Blogger.com had lost - a very eloquent dissertation entitled "Mourning the Death of the American Meritocracy". It was inspired by weeks of headscratching and frustration with the overall lack of accountability and presence of an entitlement mindset in America.
In the wake of that exercise, this man's words struck a chord of hope with me - that despite his friend's allegation that you become a democrat based on the color of your skin, there are people of all backgrounds who still believe that the entitlement society is an inherently evil thing.
I no more believe that the crime and drug problem in this country is linked to race than I believe one's ability to succeed is based on it. There are statistics galore that paint the American drug problem as a predominantly caucasian issue (for instance, 80% or more of users aren't black).
However, if your only news sources are broadcast television and the local paper, it's easy to believe that black people are the main problem with crime & drugs, and that white people control the world.
This type of journalism is certainly sensational, but it does a terrible disservice to the American citizenry. It's not complete. It's often unfair. It seems to always favor the angle over the truth, because it's more interesting that way (pay attention to the Tom DeLay developments and see if you feel the same).
On the whole, American journalists hold themselves to standards for entertainment value instead of standards for integrity (legitimacy, accuracy, and fairness). I, for one, think it should be the other way around.
Thursday, September 29, 2005
...then Microsoft gets it all wrong
While I earlier commended Microsoft - specifically, the Office product team - for getting it right, the remainder of Microsoft is still getting it all wrong.
A couple of months ago, we signed up for a new Microsoft licensing agreement covering our Office products. We opted for Software Assurance - which means whenever Office revs again, we'll get it for free. But Software Assurance also provides some very enticing benefits. In particular, the TechNet Concierge Chat was of interest to me. I would love for my HelpDesk to get an MS rep on-line when troubleshooting an Office issue for a customer.
I looked into getting us registered & signed up, and this is when the allegations against & stereotypes of Microsoft's security ineptitude took on a very real, very accurate palor.
I learned that this benefit had in fact already been activated for us. Furthermore, an e-mail was sent to me with instructions on using it - an e-mail I never received, because it was sent from Microsoft's mail servers using my boss' e-mail address. That's right. The process Microsoft uses to notify customers of benefit activation involves purposefully sending masqueraded e-mail messages using its customers' own addresses - instead of a Microsoft-owned address.
Any e-mail admin worth their salt won't allow someone to spoof their domain name for incoming messages. We use Postini (you should too), which blocks incoming mail sent from one of our domain names if it doesn't originate from a trusted IP address - Microsoft is not among our trusted addresses, for very obvious reasons.
Microsoft's licensing customer service reps know of this practice, but are powerless to do anything about it. What they will do, however, is verbally give you those credentials if they can speak to the person they believe is the benefit administrator. Very secure indeed.
It gets better.
Assuming you have your login information, you need to use the oft maligned Passport login service to access your benefits. Again, from a security standpoint, there are significant issues here.
First of all, I'm not Ma or Pa Kettle trying to get to my Hotmail account, or the 'Zone to play some stupid version of solitaire or gems or whatever. I'm a paying business customer. If my credentials are compromised, the attacker gets access to some better-than-average stuff.
Second of all, it's not as hard as one believes for your Passport credentials to be obtained maliciously. This is because Microsoft trusts Windows and Internet Explorer cookies to remember your password, etc. more than it trusts you to manage it. Interestingly, last I checked, there weren't any security patches released for my brain to keep me from blurting out my passwords if someone talked to me long enough.
Lastly, around two years ago, an Indian hacker proved he was smarter than the Redmond developers who wrote Passport. To prove it, he compromised literally the entire Passport database in Microsoft's data center.
The original damage estimates were hyperbolic, but it further proved that Microsoft is not very good at security architecture. Even Windows Server 2003, which was redesigned with a strict security focus, is prone to attacks that affect OS versions back to NT4. So much for the story of it having been 'completely re-written'.
Every other enterprise vendor's support and entitlement website requires simple user ID and password authentication. It's a model that is familiar to everyone. For some reason, Microsoft decided to overcomplicate it for the only customers that matter - the ones that pay for services.
To their credit, the people I've spoken to in my account team have taken my concerns very seriously, and are championing my cause within Microsoft in an effort to provide me some form of satisfactory resolution. I'll be sure to publicly commend them for anything they achieve in this regard.
In the mean time, I will remain ever skeptical of Microsoft's claims to be security-minded. The conservative IT manager will be well advised to do the same.
Thursday, September 15, 2005
Health Kick
So, I've eaten smarter over the past three weeks. Less intake. No soda or sweet drinks, just water & tea. I'm down 15 pounds, and can actually begin to see it. I'll start exercising now that I have my first ever piece of home gym equipment, and hope for the best.
What's killing me is the almost constant feeling of hunger - no matter how much water I take in. One of my employees used to run long-distance in college at OSU. He said my body knows it's losing weight (which is healthy but not normal), and is trying to provoke me into filling the furnace. Resisting it takes discipline, or chewing on straws - whichever works.
I still have an urge to snack, however, and now that I'm paying attention to Nutrition Labels, what I've found is very interesting. 3 "Snyders of Hanover" pretzels (in a bag) is roughly equivalent to 1/4 cup of peanut M&M's, which is roughly equivalent to 12 Lay's "Stax" potato 'crisps', which is roughly equivalent to a single Hostess cinnamon streussel cake...all of which have more calories (and less substance) than a good ol' pint of Guinness Draght.
Good thing I like Guinness. Anything that's been around for over 230 years has got to be good, right? Don't believe me? If you're one of those people who enjoys using statistics to justify an otherwise indefensible position, you'll appreciate the benefit Arjen's Beer Page offers up.
Beer me!
Tuesday, September 13, 2005
Holistic Meltdown
Holistic Meltdown.
I think it may be fair at this point to say that the governments of New Orleans and Louisiana will be found utterly incompetent at best, and irreversibly corrupt at worst. There is simply no way you can justify the complete lack of cohesion and response in New Orleans. Mississippi and Alabama - while spared perhaps the worst - have no such similar issues. No, it's New Orleans that has shamefully - singularly - failed to take care of its residents following a natural disaster that could have - should have - been expected to have happened during any Autumn in the past 40 years.
To make matters even worse, amidst all of the ridiculous allegations that race (rather than incompetence) were behind the abysmal treatment New Orleans' residents received at the hands of the motley crew of first responders, here now stands FEMA pouring salt into the wounds of the survivors.
You'd think something as important as disaster aid, which is only really useful to people who have been in a disaster, should be as easy to register for as possible.
However, if you visit http://disasteraid.fema.gov with anything other than Internet Explorer 6 w/ JavaScript enabled, you're not going to have much luck applying for relief funds appropriated by your federal government. Somehow, your browser version is important in applying for relief. I'm not sure why your browser version matters to FEMA. In reality, it probably wasn't an intentional act. Maybe it's because the government has bought licenses for a bajillion copies of Windows XP w/ IE6, so they figure everyone has it. Unlike AOL, it doesn't come in boxes of cereal. Libraries, etc. with internet-connected computers may not actually have IE6.
It's almost comical in a Douglas Adams kind of way. Bumbling bureaucrats who have nothing left but policies & processes. A careless decision by disinterested employees of a mega-establishment, blissfully unaware of the consequences of their actions. It's almost surreal.
This however is the least of the survivor's problems. There are too many people who could really use clean clothes, a good meal, and a bottle of water that don't give a damn about a FEMA website.
Perhaps the most disturbing stories are those recounted by people very close to those providing relief. A co-worker's brother is a Pastor in the Dallas area, and helped to establish a facility where survivors could stay, be clothed and fed, etc. People have driven from thousands of miles to offer assistance to families there. One after the other, they offer housing and personal aid to as many people or families as they can.
Here's what's disturbing. One gentleman came from Mississippi, offering to take up to 15 families back with him. He would house them, feed them, help them re-establish their wardrobes & dignity, and pay $200 per day (equivalent of $50,000 / year) to the able bodied for assistance in cleaning up his home town.
Nobody came forth.
The offer was repeated over the PA system that so many before him had used.
Again, no-one came forth.
If there was ever a question that the entitlement mentality engulfing this nation's poor - fueled by the misguided, affluent liberal contingency - is a downward spiral, this situation should put it to rest for good. These people would rather live in squalor than go to work for $50k per year. LOTS of them. Even those with nothing left to lose would rather beg than earn.
Can someone from the left please read The Dream and the Nightmare with an open mind, and re-evaluate the real consequences of bleeding heart liberalism?
Thursday, September 08, 2005
Being Certifiable
I've not had to adjust the theory much over the 15 years I've been doing this. The theory goes as follows:
- In technology, education does not equal employability.
This is a "pet" theory, because it's one that I live and prove every day. I am not proud that I dropped out of high-school at 16, but it's the truth. I got my GED, at my then girlfriend & now wife's insistence, at about 20 years old - shortly before my first step off the "IT Worker" platform and onto the "IT career" train. I've never been to college except to see people or watch events.
An employer did send me to training, and I did begin passing some certification exams. Then I failed one, despite knowing my stuff inside and out. It was the stuff nobody used anymore that I wasn't familiar with, and didn't care to spend time learning, that caused me to fail the last exam I ever took.
And that's where the theory was born. I didn't know enough about obscure networking hardware to pass a test, but I did know enough to get hired, promoted, and sent to training by a Fortune 50 company. That being the case, what is the value of a certification?
I still find it to be a fair question, and a difficult one for anyone to answer convincingly.
I went on to enjoy some good success - both at that company, and others - despite my lack of certifications. In fact, Novell hired me to be a field Consultant without being a CNE. They didn't value certifications either - not even their own.
What I have found is that companies - good ones anyway - value people in any discipline that exhibit two primary traits. Attitude, and aptitude.
Degrees and certifications aren't relevant by themselves. Companies or managers that require them before they'll interview someone are nearsighted - period. If you find a candidate who passes the sniff tests - appears apt, is personable, speaks to things such as organization & work ethic, etc., the degrees & certifications they carry should serve to set them above the rest of the crowd. They help to fill in the details of a candidate's overall picture - not draw the entire thing by themselves.
I wouldn't want to work somewhere that pre-determined the benefit a prospective employee might contribute based on degrees or certifications. When I look for jobs and see postings that require Bachelor's degrees, I kind of chuckle to myself. What the hell good is a Bachelor of Arts degree if you want to be a technologist? What if they studied Marine Biology? How can that be relevant?
I've worked beside people with enough certifications after their name to require a 10" long business card - and I didn't trust them to be behind a keyboard. I'll employ someone with boatloads of the right attitude and raw aptitude right this minute, regardless of how much experience they have or certifications they carry in tow.