{"id":1422,"date":"2008-07-05T12:00:00","date_gmt":"2008-07-05T12:00:00","guid":{"rendered":"http:\/\/orcldoug.com\/blog\/?p=1422"},"modified":"2008-07-05T12:00:00","modified_gmt":"2008-07-05T12:00:00","slug":"server-technology-conundrums","status":"publish","type":"post","link":"http:\/\/orcldoug.com\/blog\/2008\/07\/05\/server-technology-conundrums\/","title":{"rendered":"Server Technology Conundrums"},"content":{"rendered":"<p>[<i>The following is a guest blog post courtesy of <a href=\"http:\/\/www.justsql.co.uk\/index.htm\">Peter Robson<\/a>, prompted by <a href=\"http:\/\/18.133.199.212\/?p=1421\">this event<\/a> that we both attended. Peter&#8217;s a good friend, I love his writing style and he&#8217;s expressed similar opinions in the past to me, so I asked if he would write them down for a wider audience. See what you think. Thanks, Peter.<\/i>]<\/p>\n<p>Recently I attended an Oracle User Group meeting on server technology. The speakers were excellent, the topics highly relevant to a contemporary interest in server technology, and the audience receptive and appreciative. But there was something wrong \u2013 each speaker was showing the audience how to address the failings or weaknesses of the Oracle database system. Given the very high initial purchase price of the product, and the equally daunting annual maintenance costs, this seemed something of an unsatisfactory juxtaposition. <\/p>\n<p>There are three topics I want to address, tuning, upgrades and security.<\/p>\n<p>On tuning. Attendees at this meeting were presented with a veritable avalanche of slides, showing graphs, both 2D and 3D, tables, even 4-dimensional matrices, all illustrating just how many variables can be measured and adjusted in Oracle. Specialists have carried out much serious work and research in this area. Customers in particular get enormous benefit from taking the advice of these highly skilled specialists. Indeed, the proliferation of technical gurus skilled in many of the arcane characteristics of Oracle is a further indirect endorsement of the product itself. <\/p>\n<p>There are winners and losers here. Oracle wins \u2013 they need to spend less time on perfecting their product. The consultants win; because of the position Oracle adopts, they are guaranteed a job for as long as Oracle pursues this strategy. The cost of both the product (which one might perhaps begin to suggest is unfinished) and the cost of the down-stream consultancy advice is all born by the customer. In fact, it\u2019s not just the price of purchase, but ongoing maintenance that irks many users. At something like 15 to 20% of the purchase price every year, the customer must pay this price to ensure they receive corrections (euphemistically entitled patches), as well as retain the right to receive the next major release. These privileges are generally described as \u2018support\u2019. One might just begin to wonder which party is actually being supported in this situation. It\u2019s a beautiful catch-22 revenue stream, and once again the loser pays all.<\/p>\n<p>Oracle provide some tools (AWR) to assist with tuning the database \u2013 but as an extra cost option. They tend to be inserted during the main installation, even if they are not explicitly licensed. It is quite easy to accidentally access one of these components (perhaps by looking at a dictionary view), resulting in the internal logging which Oracle have installed on the customer system recording the event. This will prompt an additional cost being charged to the customer..<\/p>\n<p>But is it acceptable that a vendor should install a product on one\u2019s own hardware, which generates logs using disk space and cpu resources, which the owner of those resources are not permitted to access without paying extra?<\/p>\n<p>One used to have to use a PL\/SQL package licensed as part of the Diagnostics pack in order to disable the Diagnostics pack, to ensure that accidental access to one of the monitoring dictionary views was prevented. Only after uproar in the user community was this anomaly resolved. This was a bizarre revenue stream \u2013 a costed item to make sure one does not use a cost item. In any event, one has to ask why should one have to pay extra to monitor and adjust the product already paid for? It\u2019s tantamount to buying a car, and being told the dashboard instruments are extra. Worse than that, in fact \u2013 it\u2019s like paying extra for the on-board computer that monitors and controls the engine management system.<\/p>\n<p>A talk on upgrades described many of the difficulties in moving from one version to another, including most astonishingly the total corruption of data during its migration from one version of Oracle. The only way to avoid this situation is, apparently, a) don\u2019t upgrade, or b) test, test and test again before going live with a new version. But why should the customer have to test a product so exhaustively for which they pay so much? Does the manufacturer have a lack of confidence in the suitability of a new release? One could be forgiven for believing that Oracle is in fact using the customer base as a means of final testing of new versions. It must explain why many customers are reluctant to buy into the first version of a new release. Of course many installations will upgrade without any problems, but the very fact that problems have to be anticipated is unacceptable given the investment involved in this product.<\/p>\n<p>But the whole issue begs the question of why upgrades appear so thick and fast. I would suggest that this happens for two reasons \u2013 income stream, and the drive to develop technology for its own sake. Note the vested interest in the guru community of seeing their clients upgrade. Note also the way in which the underlying architecture of the database seems to change subtly with each new release, requiring a new edition to the guru handbook \u2018How to Tune Oracle Version xx\u2019. I do not believe that this is an environment in which the end user is best served. Unless there are particularly strong business reasons to do so, no organisation should ever upgrade just for the sake of it. In fact, I would say that the constant tinkering of the kernel by Oracle with each new release, probably by different, even competing coders within Oracle Corp, militates against the basic stability of the product. If so much testing is required following each new version, then too much must have been changed. Why?<\/p>\n<p>Finally, the issue of security was the subject of another interesting presentation. It recently emerged into the public domain (following the MacKinnon hacking trial and other sources) that there are copies of Oracle embedded in the most secure sites in the US military and security sectors which still have not properly implemented password security. Anyone with a modicum of knowledge of Oracle default passwords can walk right in to many of these databases. As many competent hackers have done from all round the world (and countries from the Far East are notable here). One has to ask what sort of company is it that even allows a foolish customer to install their database product without FORCING them to impose the most fundamental of security constraints \u2013 primary password access. This rather worrying gap in basic security has to pose the question of how fit for purpose the Oracle dbms is for installation into a secure environment run by not quite competent users. Downstream security may indeed be excellent, but if the front door is left wide open, that downstream security is somewhat compromised.<\/p>\n<p>So, great product, but it could be so much greater if more effort were directed to improvements truly for the benefit of customers, and not simply to maintain an income stream based on a technological merry-go-round.<\/p>\n<p>Peter Robson<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[The following is a guest blog post courtesy of Peter Robson, prompted by this event that we both attended. Peter&#8217;s a good friend, I love his writing style and he&#8217;s expressed similar opinions in the past to me, so I asked if he would write them down for a wider audience. See what you think.&hellip; <a class=\"more-link\" href=\"http:\/\/orcldoug.com\/blog\/2008\/07\/05\/server-technology-conundrums\/\">Continue reading <span class=\"screen-reader-text\">Server Technology Conundrums<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1422","post","type-post","status-publish","format-standard","hentry","category-uncategorized","entry"],"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":1042,"url":"http:\/\/orcldoug.com\/blog\/2006\/08\/04\/log-buffer-4\/","url_meta":{"origin":1422,"position":0},"title":"Log Buffer #4","date":"August 4, 2006","format":false,"excerpt":"Welcome to the fourth edition of Log Buffer.Maybe it's the summer holiday season and DBA-land is a little quiet, but navel-gazing seems popular this week. During a conference keynote speech by Ray Lane I attended earlier this year, he highlighted how much the software industry likes to talk about itself\u2026","rel":"","context":"With 7 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":936,"url":"http:\/\/orcldoug.com\/blog\/2005\/10\/05\/oug-scotland-2005-conference\/","url_meta":{"origin":1422,"position":1},"title":"OUG Scotland 2005 Conference","date":"October 5, 2005","format":false,"excerpt":"Yesterday I attended the one day OUG Scotland conference in Glasgow. I think there must have been 200-300 attendees and there were three streams of presentations. I was immediately impressed at the organisation and venue. It felt like a proper conference rather than just a slightly bigger user group meeting.After\u2026","rel":"","context":"Similar post","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1466,"url":"http:\/\/orcldoug.com\/blog\/2009\/01\/27\/adding-a-new-oracle-host-to-audit-vault\/","url_meta":{"origin":1422,"position":2},"title":"Adding a new Oracle host to Audit Vault","date":"January 27, 2009","format":false,"excerpt":"This one's been outstanding for a while. After my presentation on Audit Vault at UKOUG, the AV Product Manager Tammy Bednar sent me a couple of corrections to the configuration section. Rather than just amend the slides, I was keen to wait until I had another chance to configure a\u2026","rel":"","context":"Similar post","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1339,"url":"http:\/\/orcldoug.com\/blog\/2007\/11\/06\/the-reality-gap-3-a-single-instance-per-server\/","url_meta":{"origin":1422,"position":3},"title":"The Reality Gap (3) &#8211; A Single Instance per Server","date":"November 6, 2007","format":false,"excerpt":"There will probably be about four or five of these posts in total. This is one I didn't mention in the original presentation because I didn't feel I could do it justice and because there was someone I wanted to have the right to reply. Step forward Tom Kyte.By coincidence,\u2026","rel":"","context":"With 15 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1122,"url":"http:\/\/orcldoug.com\/blog\/2006\/11\/06\/ukoug-agenda-2\/","url_meta":{"origin":1422,"position":4},"title":"UKOUG Agenda","date":"November 6, 2006","format":false,"excerpt":"Another late shift today followed a busy weekend attending an evening wedding reception on Friday and a friend's 40th birthday party in Newcastle on Saturday night, so that closing part of the Recovery Design series might have to wait for a day or two. I'm also in a growing panic\u2026","rel":"","context":"With 10 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":881,"url":"http:\/\/orcldoug.com\/blog\/2006\/01\/15\/peter-robson-on-the-temporal-database-seminar\/","url_meta":{"origin":1422,"position":5},"title":"Peter Robson on the Temporal Database seminar","date":"January 15, 2006","format":false,"excerpt":"It's a bit of a blog frenzy today!On the 3rd November last year, immediately after the UKOUG conference, there was a seminar in Edinburgh to discuss temporal databases. (Mogens blogged about it here and I'd mentioned some of Rob Squire's work here.) I had planned to go initially but was\u2026","rel":"","context":"With 7 comments","img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/posts\/1422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/comments?post=1422"}],"version-history":[{"count":0,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/posts\/1422\/revisions"}],"wp:attachment":[{"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/media?parent=1422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/categories?post=1422"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/orcldoug.com\/blog\/wp-json\/wp\/v2\/tags?post=1422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}