Thursday, April 30, 2009

Grid security: A modest proposal

When the hacking of America's power grid came to light earlier this year, I just wanted to bang my head against the wall. Simply because it would feel better than watching history repeat itself. I mean, it was only nine years ago that I spent a good part of my (first) internship Y2K-checking the city government's computers. It wasn't a big city, so I don't like to think about how budget-busting it was to have all the extra emergency staff on duty New Year's Eve, waiting for the lights to go out.

Yet here we are, waiting for our old Cold War nemeses to take their pot-shots at our grid, simply because keeping the bloody lights on apparently isn't a top priority. Just like the sacred dictates of the so-called free-market were allowed to trample public welfare in California in the late '90s. In that case, it was only the financial overreaching that brought down Enron--not their criminally sociopathic behavior toward their fellow human beings. So it's not like you can expect folks like this to spend any money on effete trifles like security. That's the government's problem--because, after all, the game's always about privatizing profits and socializing costs.

Trust me--I totally understand the need for putting the power industry's feet to the fire on this issue, and it's one of the few times I can actually imagine the Department of Homeland Security--it just has such a lovely Orwellian ring to it, doesn't it?--justifying its existence. A smart grid is an inevitability, with or without New Deal-like funding. With any networked system, security is not something you hack in after the fact. If it takes the DHS to crack its knuckles and glower the power industry into doing what it should have been doing all along, so be it.

Yet, to spare us any more of Senator Lieberman's hyperventilating, how about a truly consumer-driven approach to fixing the problem? Simply put: For every outage that lasts over five minutes, the electric company is required by law to credit you for ten times what you would have paid for electricity. With a ten dollar minimum, just to cut out the quibblesome bean-counting. Smaller resellers who buy energy off the grids of larger companies are of course entitled to roll those costs upstream (with interest) if the outage was not their doing. Simple little system, right? No need for the taxpayer-consumer to ultimately foot the bill for reams of regulation--or legions of lawyers to suss out the loopholes to subvert the whole thing.

Somehow, though, I doubt that the champions of "deregulation" would line up behind a market that's "free" enough to give those downstream so much influence. Or--horrors!--make those upstream accountable for planning past the next reporting cycle.

Wednesday, April 29, 2009

Should HR be involved in hiring?

The HR-bashing that went in the comments of this Slashdot post ("Social Networking Sites Getting Risky for Recruiting") makes me think that HR in general is not doing a good job of marketing itself. I've had good experiences and mediocre ones with HR in the various companies for which I've worked. Understand that in the mediocre situations I've experienced, HR's staff has set itself up as one of the "gatekeeper" roles that I despise so much. That's symptomatic of a culture problem across the entire organization, so we won't go there.

But the substance of my questioning of HR's role in hiring comes from my head-scratching at the notion that a company gains any efficiencies by delegating even so much as the resume pile vetting to a centralized person or group. IMO, it becomes more of a liability as the company grows. To my mind, there's no reason why any team lead worth the title shouldn't be trained in (at a minimum) technical interviewing.

The bottom line is that team leads and first line managers know what skills they're looking for and have strong sense of the culture of their teams. Moreover, their understanding of what the resume actually says is considerably deeper than the buzzword bingo that so often is played when a non-technical professional is weeding the resume stack.

Mind you, an HR professional should attend every single interview to insure that nothing illegal happens, and (if necessary) to keep the interview from bogging down into minutia. If the professional's also been trained in reading non-verbal communication, by all means consider their opinion. But the hire vs. no-hire call must be made by the people who will be most closely affected. Anything less is a paint-by-numbers cop-out.

Tuesday, April 28, 2009

Why I sometimes can't believe it's 2009

First off, hat tip to Eliotte Rusty Harold's Java-blog Cafe Au Lait for the link to Bruce Schneier's blog post on Unfair and Deceptive Trade Practices.

Here's the take-home:

This may be fine -- the advantages might very well outweigh the risks -- but users often can't weigh the trade-offs because these companies are going out of their way to hide the risks.

Of course, companies don't want people to make informed decisions about where to leave their personal data. RealAge wouldn't get 27 million members if its webpage clearly stated "This information will be sold to pharmaceutical companies," and Google Docs wouldn't get five million users if its webpage said "We'll take some steps to protect your privacy, but you can't blame us if something goes wrong."

If it weren't for my inner cynic, I'd be wondering, "What year is it? Y'mean that a decade and a half into the Internet Age, we're still discussing this???"

Time and again, you hear the platitude that democracy cannot exist without an educated, informed public. By the same principle, neither can Adam Smith-style capitalism (not the collection of oligopolies that masquerade as such). As the recent scandals with tainted consumer products, children's toys, etc. have shown, truth in labeling can be a life-or-death situation. Not to mention that an entire industry can lose millions, if not more when consumers are spooked en masse.

That being said, you cannot always trust people to make decisions that are emotion-free, even when all the facts are at hand. Which is why I think that the sleazier online operators are getting off more lightly than they should (assuming they can be brought to justice). Why? Because most people don't look at information and hard goods as being in the same category of "property." Yet stealing and misusing information is still stealing and misusing someone's property. Just because information is intangible doesn't mean that the damage isn't. But that may be lost on some, if not most. Maybe we should start calling it "data-jacking" to get the point across.

From a customer service standpoint, that bias combined with the lack of accountability scares me. Frankly, every time I hear the software gurus go all hand-wavy about pushing our flagship applications--meaning our bread and butter--into a "cloud" platform, I fight the urge to both roll my eyes and cringe. If my client's data is stolen or vandalized, it'll be a lot harder to figure it out, much less fix, when it's somewhere in "the cloud," rather than twenty feet away from where I sit.

The irony of course is that with all the meddling that governments worldwide have done with the internet--from blocking to mining--the bureaucrats haven't put a whole lot of thought or resources, much less planet-wide regulatory policy-making into making it a safer place to do business. At least not the legitimate kind.

Monday, April 27, 2009

Humble pie a la mode

Well, I feel a little more than chagrined. Last week, my most immediate boss sent me on a quest for a web browser plug-in capable of dishing out SQL Server Reporting Services reports, one that didn't depend on Microsoft Internet Explorer on the Windows platform.

After most of my many and varied incantations to The Almighty Google lead to dead-ends, I put the question to the mailing list where the local Linux illuminati visit. I also pinged the email addresses of two possible vendors.

Ideally, you're supposed to write so that you cannot possibly be misunderstood. Wow, did I ever fall short of the ideal in all three cases!

Looking back, my foremost mistake was obsessing about the technical requirements/restrictions without ever thinking to mention what, exactly, we're actually trying to do with the technology. A little context would have saved more than a little time and typing, particularly b/c one of the vendors lives sixteen or seventeen time zones away from me.

That being said, there is a glass ceiling of sorts to the afore-mentioned ideal. (Ideals are prone to that, I've noticed.) Without mentioning any names, I'm pretty convinced that one vendor did not entirely want to understand the requirements, or maybe figured that they were someone else's problem after the sale. When even a relatively clueless key-banger like myself has the feeling of being hustled, I think we can safely say that the product probably wouldn't cut it.

I'm not sure what penance tech. writers are supposed to do for their sins. I'll figure something out. In the meantime, though, I thought I'd pass along the lessons learned, to hopefully spare others the wasted time and bad karma.

Sunday, April 26, 2009

A "not safe for work" (NSFW) post

Your one and only warning: If you're squeamish about venturing into "adult" themes, however intellectually, please leave now. kthxby.

Still here? Let's get to it, then.

I don't have children--the human kind, anyway. But that doesn't mean that I'm not disgusted to the point of wanting to sack those responsible for the "Baby shaker" (ahem!) "game" available for sale at Apple's App. Store. Particularly in light of the fact that Apple rejected another "game" that involved making a set of breasts jiggle (on grounds of inappropriateness--for its business image).

But that doesn't mean that I'm not surprised that something like this would happen. Two reasons:
  1. Whatever the "rules," someone will always find a way to exploit them.
  2. People (in the main) can emotionally process violence better than they can sex.
Humor me by noodling this scenario for a bit: Suppose that an "extracurricular" tackle at Superbowl XXXVIII results in a full-on brawl with multiple injuries. You would have seen footage on ESPN all the way up to the Pro Bowl. The teams and players would be fined and disciplined, certainly, but the networks would happily use clips from the brawl while reporting on those sanctions, with nary a repercussion all the while.

But one inadvertent breast-baring--inadvertent on the part of the breast's owner, apparently--and the network is hit with a record fine, and the term "wardrobe malfunction" enters the national lexicon amid absolute hysteria from the self-appointed morality police.

Let's give Apple credit where it's due: It pulled the app. within hours. And, to be fair, a quick consultation with The Google yielded more than a few "An apology isn't enough" results. But until I see the deluge of 99-cent donations to various shaken baby syndrome foundations, I'm assuming that it's "business as usual" for our culture's incomprehensible priorities. And in the meantime, Apple will continue to decide for its customers what's most "appropriate" for them.

Saturday, April 25, 2009

Another reason why Gallipoli should be remembered

I'm kicking myself because today is April 25th, but I forgot to wish my old pen-pal in New South Wales "Happy ANZAC Day" yesterday. Because his time zone is sixteen hours ahead of mine, it would have been too late by the time I was awake this morning.

In history, Gallipoli is pretty much textbook definition--maybe even the ANSI standard--of what happens when SNAFU devolves into FUBAR. (As if WWI didn't have enough of that.) To hear my Australian pal tell it, the mythos is that the British officers sipped their tea in safety whilst the regular soldiers were slaughtered in droves. Indeed, a distinct lack strategic leadership at the point of attack is documented. From John Julius Norwich's The Middle Sea (Doubleday: New York, 2006), pp. 580 - 581:
The Allied troops fought equally bravely, but their task was made harder by the extraordinary preference of Hamilton and his two subordinate generals, Aylmer Hunter-Weston and Sir William Birdwood--commanding the British and the Anzacs, respectively--to remain at sea throughout the vital first hours after the landing. Thus, when the signaling arrangements began to fail and there was an almost immediate breakdown of Allied communications, each individual unit was left to look after itsel, with no knowledge of what was happening on the next beach to its own.
Add to this that some of the landing areas--most notably what's known on the history book maps as "Anzac Cove"--were unknown. And that the British had loaded down an already discombobulated supply effort with trucks for an area that had no roads and forgotten little niceties like landing craft. To be fair, the British could not have foreseen the extraordinary leadership and initiative of Ataturk. Nor could they have known that within months they would also be facing the worst blizzard in forty years.

When the Allied position became untenable enough to trump the egos of those championing the campaign, the prospects for evacuation were grim. Hamilton--not that his opinion should have been trusted--estimated that only one in two men would survive the withdrawal. Inclement weather and the expected difficulties of smuggling people, pack animals, artillery, transport and other equipment off to the rescue ships were compounded by the fact that Allied and Turkish trenches were in some places no further than ten yards apart. During the evacuation, those remaining had to give the impression of being a larger force than they actually were; otherwise, the would be overrun.

Yet the soldiers managed to maintain the subterfuge long enough make it work. Casualties and loss of life were almost nil, and--almost as important--the weapons magazines were blown up so that they could not fall into the hands of the enemy. It's probably the closest thing you'll get to a happy ending when war is involved. At least for the Allies.

What does this all have to do with business or software or even people in general? Nothing specifically, except to demonstrate that leadership does matter--but that leadership doesn't count for much without a strong command of the minutia at hand.

Friday, April 24, 2009

Meanwhile, back at the addiction...

A very frivolous post tonight, in honor of the warm, lazy-feeling evening that the storm front has left at its back. In fact, I think that I might just make a tradition of "Frivolous Friday."

But about that addiction. I've gone more or less dormant for 20 days in Facebook's "Medieval Empires," mainly because I was on the cusp of leveling up, and didn't want to do so without considerably more firepower. That meant salting away income at a punishing 10% penalty. There was a short skirmish with my conscience a few days ago when I saw that my one and only "ally"--whom I consider an adversary, really--had made huge gains on my attack level. But patience paid off and I again command in excess of a 3:1 advantage. Whew! Glad to know that the Universe has been restored to its rightful proportions... [eyeroll]

One thing that bugs me about "Medieval Empires" is that the profile page for any player includes buttons for repeatedly attacking them and even "raiding" them (which actually reduces their current attack level). I see people do that all the time. I see that it's happened to me when I log in, and I see on the "recent activity" pages that others (including my so-called ally) do it to others. That's just cheesy, in my considerably-less-than-humble opinion.

But the phenomenon prompts an idea: Why not use a relatively simple text-based game like "Medieval Empires" as part of the job interview process? I'm thinking that you could set it up to be available on the off-hours, so interviewees don't have to take time off from work to "play" the game. The key is that you can't make the objectives known. Because you're not really interested in how many bazillion bling-y gold tchotchkes anyone racks up. You're interested in how quickly they latch on to the rules--written and un-. You're interested in whether they find the cheats--and whether or not they use them when they do. You're interested in how hard they push back against constraints. And you're particularly interested in whether or not they will screw over their "allies" if they think they can get away with it.

Now, undoubtedly, this sort of "game" would take considerable programmer-hours as well as beaucoup consulting hours (from your local psychologist) to set up. Additionally, a certain percentage of folks will always shy away from the competitive aspects, which undermines the value of the exercise. Truth be told, I'm not much of a gamer unless the alchemy of personality is involved. Aside to K.S.: One day, I will crush you at "Settlers of Catan!" Mark my words: Victory will be mine, I tell you! Mine!!! ;-)

Ahem.

Most importantly, you need to understand precisely what traits you're looking for. And I do mean precisely: gnothi seauton is the operative phrase here. But for cryin' in yer' beer, the absolute last thing you want to do is allow the archetypal HR Dept. anywhere near the scores. This sort of thing is intended to be a supplement--actually, make that an antidote--to the usual Buzzword Bingo and B.S. Bossa Nova that pass for vetting your co-workers.