Why Zoom?

I have posted a blog on Why Zoom? has become so popular in terms of getting consumer mind share.

I wonder if it’s based on Microsoft forgetting its history. I am sure the ultra low cost of using Zoom helps but Microsoft’s entry cost for Skype is the same and at the end, someone has to pay for the server room cycles.

Perhaps in the hypergrowth stage best of breed works but I suspect that an integrated offering will win out in the end.


Where is BS20001 when you need it?

I have been looking at my CISSP notes on Business Continuity and they all state that getting your people into work is as important as ensuring the IT can survive the disaster. Also, people have been reducing the likelihood of a data centre loss and to be frank that’s not what’s happened. No question but that much planning has been found wanting as companies whose strategy in terms of meeting their public duty in the case of a disaster has been to allow competitors to step in. Both Waitrose and Laithwaite’s web sites have failed over the last seven days; these will probably be because of both staff nonavailability and insufficient capacity to cope with increased demand.

I also wrote a piece on my linkedin blog about the vulnerabilities that a sudden switch to mass working from home may cause, looking at vulnerability management, data leakage protection and obliquely vendor management. …


It seems some people are trying to distinguish between the meanings of DaaS and VDI. Looks as if DaaS is a cloud offering and VDI is on-prem. This really isn’t helpful as so often the architecture is identical! …

Google, the GDPR and Brexit

Google are going to move their UK users data from Ireland to the USA. I wrote a little note on my linkedin blog. I headline it as

Google are moving UK data from Ireland to the US … what does this say about UK/EU/US dataflows and ompliance with the GDPR and the world’s data protection laws.

I also point out the need for robust legal redress to comply with the GDPR, which the UK and USA may not meet and that the UK will lose access to the US Privacy Shield arrangements. I note that the UK will lose its member state privileges and powers under the GDPR when the transition period ends and that RIPA 2016 and the immigration exception of the DPA 2018 may cause the Commission some problems with respect to “Adequacy”.

I note that model clauses and binding corporate rules will remain in place and I wonder if this is a business opportunity for a European based phone operating system author as people choose to withdraw from Android? Nokia? Canonical? …

Snowflake SQL & Big Data

Yesterday, I attended Snowflake's World Summit yesterday. My experience of working for US companies has taught me some cynicism about the naming of such events, but both the CTO and business founder are both French and ex-Oracle employees. They have obviously caught a mind share, the meeting was heaving and very heavily overbooked. I attended the plenary sessions, which consisted of a reference story and during the break spoke to one of their pre-sales engineers who was very helpful. This article looks at the architecture, examines its scalability design, the hardware solutions underpinning the solution and comments on the accuracy of Stonebraker's predictions. For more, use the "Read More" button ...

Digital Democracy

One of the motions proposed but not debated at the CLPD AGM was called “Digital Democracy & the need for greater voter participation”. It’s quite long at over 550 words and I planned to speak against it, by saying something like,

This motion, despite its length, says only two things: that we’ve read Corbyn/Barbrook’s Digital Democracy Manifesto and that we approve of a digital identity card as part of a system of access to e-voting in public elections.

I have read the manifesto and believe it is flawed, most importantly in it postpones the consideration of what human rights looks like in an age of the ultimate surveillance machine until after the election of a Labour Government, when it proposes a consultation. It proposes a People’s Charter of Digital Liberties but makes no mention of the work other campaigners for digital liberty have done in defining new Human Rights needs in a connected world and old Rights that need defending. These campaigning bodies include Liberty, the Open Rights Group, the Electronic Frontier Foundation and Labour’s members on the European Parliament’s LIBE committee.

But we can’t talk about e-voting without talking about Estonia, the poster child of e-voting, and its failed audits, and its proof that e-voting does not increase turnout, and its alleged failure to meet European data protection standards.

We can’t talk about e-voting without talking about the Surveillance State and its private corporate arm. It’s bad enough that the datenkraken can use our phones to spy on us, but I suppose the fact that the US government has access via them to all they know perhaps should reassure us that there is no risk to making a short cut to British Intelligence of our internet usage records, they already have it.

We can’t talk about e-voting without talking about the digital divide.

We can’t talk about e-voting without looking at whether the ERS removed votes from the 2015 Labour Leadership elections, a fact if true showing the vulnerability of the “transparency of the result” to insider attack.

We can’t talk about e-voting without talking about Russia’s interference in the US, British elections and the Brexit referendum through their advanced hacking capability.

We can’t talk about e-voting without noting that Verify, the current Government identity portal has been criticised as a failure by the Public Accounts Committee and now looks likely to be privatised.

We can’t talk about e-voting without looking at the fundamental criticisms of such systems, that they are hard to build, and it may be impossible to resolve the conflict between having a transparent result and a secret ballot; this is before we address the issues of coercion,  impersonation and 2nd party verification i.e. how to implement polling/counting agents in a proprietary software system.

In the US, engineers and electoral administrators are developing the systems to make this easier, requiring physical receipts of the cast vote, which are then electronically counted with statistical control samples manually counted.

This motion is technically premature at best and otherwise dangerous populist nonsense.

Please remit or oppose.


Interestingly, DARPA have announced an e-voting proof of concept, I am pointed at it by Bruce Schneier. …

Data and Versions

I am trying to write an article for my linkedin blog for which I needed to revisit something I wrote for Citihub. I decided to create a comment & mirror on this site, as my blog has outlasted seemingly mightier organisations then them. I originally commented on it as follows,

why encrypt inside the firewall, and why applications logs are important

On revisiting the article, the need to keep versioned copies of the data, like a wiki or a write-ahead log become more obvious, or I recognise as under emphasised in the original article. I also, this time, consider the inappropriate demise of “Entity Life History” analysis. …

Do the right thing!

A new linkedin blog by me on the fine print of the GDPR’s “legitimate interest”. The print is not so fine, and in summary, you don’t need to read the fine print to do the right thing.

When claiming a legitimate interest, the privacy rights of data subjects are established as controlling the data processor/controller’s legitimate interest by the requirement to recognise the “fundamental rights and freedoms” of the data subject. The “fundamental rights and freedoms” are defined in the Charter of Fundamental Rights

Due to indirection and thus undocumented nature of the data subject’s consent inherent in legitimate interest, I’d advise finding another lawful purpose. …

Looking back about Data Centre location

I just came across some writing I did while working at Sun Microsystems; they/we were considering building a cloud platform in Europe and I was part of the team evaluating the potential location. (This would have been 2008/2009.

The key driver for locations was thought to be firstly the IT infrastructure i.e. networks and power, an EU compliant data protection regime, and political stability, with skills supply coming a 4th.

We argued for London or Amsterdam, which is quite funny 10 years later as London looks to leave the EU and there are growing doubts about its GDPR compliance.

I argued that Sun needed to avoid dis-intermediation and retain brand loyalty; this may have been impossible as part of a Cloud offering but it had the world’s leading software superstructure products at the time. I argued that IaaS was not enough to make it work for Sun and thus initiatives like Project Kenai (a predecessor to GitHub) were important indicators of what we should do, although the font in which I did it was quite small. I didn’t see that this was crucial, but when Sun announced its cancellation, I knew that this was part of the end and a decision taken by those that fetishised hardware. Interestingly Oracle reversed this decsion, and it staggered on for another eight years. It was one of a huge number of destructive decisions taken by a management who won by luck until it ran out.

Interesting to see where I was right and where I was wrong and just how much has changed in 10 years. …