CTO, Developer, Agile Practitioner
- 13 Darvel Close , Woking , Surrey , GU21 4XG , United Kingdom .
- contact@alan-dean.com
- +44 (7960) 737 585
- alan.dean
- http://www.linkedin.com/in/alandean
Thursday, December 25, 2008
Tuesday, December 16, 2008
It’s not a Hack Day
Last week I went to the Cloud Gathering in London. Whilst there, I had a number of discussions about the forthcoming Open Spaces Coding Day and it became clear that I need to clarify the objectives:
- It isn’t a ‘Hack Day’ where there is a defined target such as “build a cool new app”.
- It isn’t a ‘Training Day’ where there is a curriculum or class-based training.
- It is a ‘Hands-on Learning Day’.
What do I mean by ‘Learning Day’? Well, for a start I want to make it clear that the attendees are not expected to create applications. The code that is produced must be checked in to the repository, but that is so we can all come by later a get a copy of it to learn ourselves or to remind ourselves what we did.
Let’s say that there is a session on NHibernate (which wouldn’t surprise me in the slightest). In six months time, one of the attendees is asked to do some work that involves NHibernate and thinks “this is what we were doing on the Coding Day”. The attendee can go and refresh their memory from code that they learnt with. I believe that this has value to the community.
Another example is that there may be a group of people who all know nothing about a subject, perhaps something new like Azure or something old like Mono. They can work to together to learn how to get on the first step of the ladder, which is often the hardest part of learning.
In summary, this is all about self-actualisation within a supporting group of like-minded individuals.
Sunday, November 30, 2008
"Open Space Coding Day"
Time for a little reflection. Over the last year, I think that a great deal has been achieved in the Alt.Net community in the UK. We have had two conferences and Sebastian Lambla has now ran four Alt.Net Beers. These have stimulated healthy discussion in the community which I am very happy to see and we should continue to nurture.
In the spirit of continual improvement, I have been thinking about how we can build on these successes and one question in particular comes to mind: "how do we move from talking to doing?". I would also like to foster a feedback loop into the conferences so that the conversation has forward motion.
My draft proposal to the community is to host a series of what I am currently calling "Open Space Coding Days". I would like these to be on a regular basis, rather like Alt.Net Beers. The focus should be on hands-on activity rather than general discussion but the Open Space philosophy still applies. Accordingly, the activities should be self-organizing. This is not about speakers or powerpoint. The only requirement we should have is to publish the code in an open repository and notes in a wiki.
Before I get tackled on the subject, for all I know this is a format that has been tried elsewhere. I suspect that the model might be very near to a BarCamp but as I haven't been to one, I don't know.
I am very interested in taking feedback. The following jump to mind but the list won't be exhaustive:
- Would you be interested in attending such an event?
- Would you or your company be interested in sponsoring?
- I have in mind to do this on Saturdays - do people think this is the right day?
- What is a reasonable number of people for a hands-on event like this (I suspect it will be fewer than for a conference)?
- How often should the event be run? Monthly? Every other month? Some other period?
- Should it run separately to Alt.Net Beers or seek to work together (perhaps planning events to coincide)?
- Is it reasonable to require attendees to bring their own laptops and have development software already installed? If not, what are the alternatives?
I am in discussions with Conchango to host the first of these as they were so supportive with our first Alt.Net UK Conference. Dates are still open as I write this.
Update (9th December)
Conchango have kindly agreed to be venue hosts for Open Space Coding Day 1. This will be on the 31st January at their London offices.
I was expecting to have to put up a reservation form, but in a flurry of tweets during today almost all of the places have been taken! Taking a leaf from Scoble, I thought I would see how effective twitter would be as an organising tool and I am very impressed! At the time of writing, there are a couple of places left. All the places have now been taken. If you wish to go on the waiting list please contact me either on twitter.com/adean or email alan.dean@gmail.com. If you can't make it on the 31st, don't worry - I will be running the event every other month, so you can always catch it next time around. People on the waiting list will be given first refusal on attending subsequent events so that there is a variation in attendees between events and that people don't feel left out. Therefore it is worth letting me know that you would like to come.
When I was at the PDC, I found it very annoying that there wasn't a consistent hashtag in use. Therefore, I would like to propose that we standardise on a single hashtag for these events. I have started using #openspacecode - the only other option that came to mind was #oscd, which (whilst shorter) just seemed too arcane to me.
Following the principle of 'golden hours', there will be two coding sessions of two hours in the day and a generous period of time for socialising over lunch:
The planning process will be as follows:
- Attendees put up the sessions they are interested in having
- Attendees put their names against sessions they are willing to host. No host means the session is dropped. Be aware: the host is not a presenter, the host is not expected to even know the subject. The host is simply someone to keep the session flowing effectively for the participants.
- Attendees vote on which proposed sessions get the go-ahead.
The only exception to this process will be that I am going to try to have one 'keynote' session per event. On the 31st January, Barry Dorrans (Security MVP) has kindly agreed to host a session on "Hands-on secure development". It's certainly one session that I want to be part of!
Please remember to bring your laptop. If you don't have one, then you will have to share. There will be WiFi access available. I will be putting together trial Virtual Machines for anyone who isn't an MSDN subscriber or hasn't got Visual Studio installed. Important: if you want to propose a session using a different development environment, for example using Mono on Ubuntu, please contact me so that we can arrange a VM. These session are about doing, not presenting, and so any proposed sessions that attendees cannot participate in will be dropped before voting.
Monday, November 24, 2008
Partnership or Company?
At DDD7, I had an interesting discussion about the question of whether a partnership or a company is the better model for a consultancy.
I think that the accepted practice is to incorporate as a limited company. Certainly I can see advantages in doing so: in tax treatment and the limited liability that it offers.
However, I wonder if partnership is a more appropriate model; even potentially a more ethical model.
The joint and several liability of partners requires that they treat business with care. It is interesting to note that both lawyers and accountants, both classes of fee-earning professionals, either often use partnership or are even required by law to do so. I don't know what the practice is for other types of fee-earning professionals, but I would be interested to find out.
Looking at the current devastation in our financial markets, I ask myself if the mighty investment banks would have placed such huge and arguably unwarranted risks if they had remained the partnerships that they were, rather than change to corporations. Similarly, would the UK Building Societies which relinquished their mutual status during the 1990s have fared better if they had not done so?
My thoughts on this subject are not fully formed but I do have a nagging suspicion that we ought to consider which is the appropriate model.
I would be very interested to hear what people think - especially those who are customers of consultancies. Would you have more or less faith in a business where the partners did not have limited liability? Perhaps you prefer dealing with companies? Either way, what would be your rationale?
For quite some time I have had a feeling that we need to mature as a profession, that there will come a time when our customers will expect the same level of professional certification and regulation that they have with other service providers such as lawyers, accountants and engineers. Perhaps the kind of organisations we work for will be part of this maturation.
DDD7
I thought that Developer Day 7 was another resounding success. As usual, the organisers deserve kudos for arranging what has to be the premier UK Community event.
If you were an attendee, please take the time to fill in the feedback - the speakers all appreciate this a great deal.
I was in the first tranche of presentations in Memphis at 09:30 and all the seats were taken (typically a good sign). It was the first time I have given the "Separating REST Facts from Fallacies" talk to an audience and was pleased that I timed it right, completing it with a little under 5 minutes for questions. It is a bugbear of mine when speakers overrun their timeslot so I take this very seriously in my own presentations.
There were surprisingly few questions at the end but those that were asked were good. I had prepped for a number of questions that I had expected to be faced with, but wasn't. One of my friends who was in the audience reported overhearing a conversation where the comment was made that the presentation was 'religious'. If that meant that they could tell that I believe in REST where appropriate, then that is good. If that meant that they felt that the presentation was unbalanced, that is not so good and would be surprising as I made a particular effort in the talk to avoid setting up the typical dogma of "REST Good, WS-* Bad".
In any event, the Channel 9 folk were there to video all the sessions this time so you will be able to judge for yourself. Historically, only a limited number of sessions were recorded. I don't yet know where the videos will be hosted but I will announce when I find out. It is going to be interesting, to say the least, to see myself giving a presentation as I haven't previously done so. I imagine that I will be squirming in my seat and will be my own worst critic.
The Geek Dinner in the evening was great fun. Thanks to Zi Makki for organising that. The conversation is always stimulating and I had a couple of very interesting discussions about REST and other subjects. I really do enjoy the networking aspects of these conferences - a chance to meet and talk with others who are as passionate about technology and self-improvement as I am.
Phil Winstanley and Craig Murphy have both pushed up their photos to Flickr (I didn't take any).
Friday, November 21, 2008
developerday.co.uk error
There appears to be some kind of problem with the DDD website right now.
Don't fret! You can still reach it at http://216.247.126.58/DDD/
Thursday, November 20, 2008
"Windows Live Sync replacing FolderShare"
I have been a long-term user of FolderShare from before Microsoft bought it in 2005. Indeed, it is central to my personal backup strategy. FolderShare seemed to languish for quite some time but unlike OneCare, it isn't going to die but is going to be re-born as Windows Live Sync instead. Watching the progress of Live Mesh, I've been expecting something like this for a while and it makes sense to have a common platform for this kind of functionality from Microsoft.
OneCare, RIP
I was very sad to hear of the impending demise of OneCare. I am quite a fan of it and have licensed it on all of my own machines and those of my family. It is unobtrusive, unlike so many of the alternatives and has the quality of 'it just works'. I can only assume that it hasn't made enough money. Microsoft are dressing the decision up as "Improving Global Access to Core PC Protection" but I can't see that offering "Morro" requires the cessation of OneCare. Occam's Razor therefore indicates a financial motive. It isn't going to die immediately, but subscriptions will be cease to be available from June 30th 2009.
P.S. It seems that a 'morro' is "a rocky outcrop in the shallow waters of a harbour, often round in shape and sometimes very high". It is also the name of the harbour fortress of Havana, Cuba.
Saturday, November 15, 2008
Federated HTTP Authentication
One of the questions that has not had much discussion recently in the REST community is authentication and authorization.
Cookies should not be used by a system which is to be considered RESTful. Roy has explained why a number of times.
I have looked at both OAuth and OpenID, but they do not seem to have a good story for automated agents as they focus on having human interaction in a browser session.
What would be ideal is a standardized authentication mechanism that supports federation. The obvious candidate is HTTP Digest Authentication (the specification isn't the easiest read, I have to admit, so you might find the wikipedia entry more understandable). Granted, it doesn't have a pretty logo. But it is supported by every user agent that I know of that is HTTP-aware. What isn't clear, however, is if it can be federated to permit user agents to employ a separate Identity Provider, reducing the need for multiple online identities.
This is an itch that I have been scratching in my mind for a while and I brought it up in conversation with Steve Bjorg yesterday. This gives me a reason/excuse to post where my thoughts are on the subject right now. Please note that these thoughts may well change and I do not consider myself a security expert.
The following diagram outlines the sequence diagram that I have in mind. Important: There is a precondition that the Server already has knowledge of the location of the Identity Provider for the user. This would probably be achieved manually in the same way that OpenID does, including an 'allow access' screen.
This is what the HTTP messages might look like:
The Client makes an ordinary GET request to a resource that happens to be protected.
GET /dir/index.html HTTP/1.1 |
The Server crafts a fresh WWW-Authenticate header and sends it to the Client with a 401 Unauthorized status code.
HTTP/1.1 401 Unauthorised |
The Client crafts an Authorization header by hashing the user credentials with the parameters of the WWW-Authenticate header in the normal fashion and resends the original request.
GET /dir/index.html HTTP/1.1 |
Here is the cunning part. The Authorization header contains enough information that a hash comparison can be carried out by anyone who has the correct credentials at hand. It doesn't have to be the Server. Therefore, the Server passes the Authorization header to a previously stored Identity Provider URI for validation (in this case, on http://example.org).
GET /user/Mufasa?domain=example.com HTTP/1.1 |
The Identity Provider retrieves the password of the user and performs the hash comparison. If validation fails, a 401 Unauthorized is returned to the Server. If it succeeds, a 200 OK is returned.
HTTP/1.1 200 OK |
The user is now authenticated. The Server can check permissions and respond with the representation requested, if permitted. A 403 Forbidden would be sent if the authenticated user is not permitted.
HTTP/1.1 200 OK |
There are some optimizations that could be employed. The Identity Provider could issue validation for a given period by setting the Expires header on the validation response, indicating that the Server can cache the authentication for a period. Similarly, the other conditional HTTP headers could be employed for more complex caching.
The communication between Client and Server and between Server and Identity Provider does not need to be encrypted because the credentials are always hashed on the wire, mitigating a man-in-the-middle attack.
The Client does not need to know anything about the Identity Provider. So far as the Client is concerned, this is a perfectly ordinary HTTP Digest Authentication mechanism which gives two benefits:
- There is no need for a complex set of Client HTTP requests to achieve authentication.
- The REST Layered System constraint is not violated.
I am interested to hear feedback from my audience if this is an authentication model that would be useful. As I said at the top, I am not a security expert so there may be flaws in my thinking.
Blog Archive
- November 2011 (2)
- October 2011 (2)
- February 2011 (2)
- June 2010 (11)
- April 2010 (3)
- May 2009 (1)
- April 2009 (1)
- March 2009 (2)
- February 2009 (7)
- January 2009 (5)
- December 2008 (2)
- November 2008 (20)
- October 2008 (8)
- September 2008 (3)
- August 2008 (2)