Problems displaying this newsletter? View online.
Database Weekly
The Complete Weekly Roundup of SQL Server News by SQLServerCentral.com
Hand-picked content to sharpen your professional edge
Editorial
 

No Defaults Passwords Ever

I appreciate default passwords on systems. Often, for routers or other devices, I might need a way to connect initially. Or, if I perform a hardware reset, I want some password that I can use to reconfigure things. However, I am pretty good (not perfect, but really good) at changing those passwords to something else. It drives my wife slightly crazy at times, but I save the passwords and stick them in a manager I share with her periodically.

SQL Server doesn't store a default password when you install it. If you enable the sa account, you need to create your own password. I primarily deal with containers, and I always set one, usually my own default. However, lots of software either allows a blank password or has a default password set on installation. Oracle even lists theirs in docs. That's not the worst idea if sysadmins change them, but if they don't, it's a threat vector for attackers. I was working with a customer last year who had an Oracle database. I asked them to try a default user/pwd as a test and it worked. I think my head was slowly shaking for the rest of the call.

Recently, Silicon Valley saw the result of a default password not being changed when someone hacked the crosswalk signals and uploaded fake audio files that played when the signals changed. The vendor (not surprisingly) advised the city to change the passwords to something strong. A somewhat harmless prank, but it's possible that someone might have made a more nefarious change.

It's 2026. We know there are people out there with malicious intentions, as well as those whose prank goes sidesways and have unexpected side effects. There isn't a good reason to keep default passwords anywhere, including in your own personal devices. These days, connectivity among many systems is a reality with network, Bluetooth, NFC, and who knows what other connections are possible. Your personal devices ought to have defaults changed for your own protection.

Inside organizations, it can be worse as the weakest link can be exploited to gain access to other systems. Quite a few hacks started in test systems and progressed to accessing production data. Even places we might not expect to be problematic, such as version control systems, have been used by hackers to gain access.

To me, finding a default password is worthy of a reprimand and a note in whoever's file forgot to change it. A second offense ought to lead to a suspension at a minimum and possibly termination. This is such a low bar of required security that I can't think of a good excuse to allow it anywhere.

Steve Jones - SSC Editor

Join the debate, and respond to the editorial on the forums

 
The Weekly News
All the headlines and interesting SQL Server information that we've collected over the past week, and sometimes even a few repeats if we think they fit.
Vendors/3rd Party Products

Redgate Flyway Product Updates – January 2026

Redgate Flyway’s January update brings faster drift resolution, AI-powered deployment descriptions, and a look back at everything we shipped in 2025. Plus, we want to hear from you about how you’re managing database changes.

SQL Prompt Product Updates – January 2026

SQL Prompt’s January release brings support for Microsoft Fabric and an exciting new preview feature.

Simple Workflows for Flyway and Entity Framework Code First

Entity Framework Code First is great for development, but its abstractions can hide risky database changes until deployment. This article explores three practical EF–Flyway hybrid workflows that add visibility and control, helping teams stabilize deployments for complex, legacy databases such as monoliths.

AI/Machine Learning/Cognitive Services

AI and the Corporate Capture of Knowledge

From Schneier on Security

More than a decade after Aaron Swartz’s death, the United States is still living inside the contradiction that destroyed him. Swartz believed that knowledge, especially publicly funded knowledge, should be...

GPT-5.2 Just Solved a 30-Year Math Problem

From Past News - RSS Feeds

GPT-5.2 Pro delivers a Lean-verified proof of Erdo...

Runing tSQLt Tests with Claude

From SQLServerCentral Blogs

Running tSQLt unit tests is great from Visual Studio but my development workflow isn’t just write tests, run tests, fix tests, run tests anymore, it is 2026 and... The...

Administration of SQL Server

SQL Server Error 9002: Your Transaction Log Is Full

It's 2am. Your phone wakes you. Rub your eyes, check your email, and there it is:

Common SQL Server Problems: Invalid Length

This is another part in my series designed to offer guidance around common issues in SQL Server. Today, let’s talk about the all-too-common error: invalid length.

SQL Server Case of the Week: Windows Server 22 Update Possibly Breaking SQL Agent & SSIS Packages

From StraightPath Solutions SQL Blog

We started receiving alerts that a client’s SQL ...

Testing SQL Server 2025 Resource Governor tempdb Limits with a Query that Spills a Terabyte

From Kendra Little's Blog

SQL Server 2025 introduces a new Resource Governor...

Upgrading to SQL Server 2025: Three Lessons Learned

From SQLBlog.org

I detail issues we experienced (and maybe should have expected) while upgrading to SQL Server 2025.

SQL Server 2025 Upgrade: Three Errors That Will Ruin Your Day - How to Fix Them?

From SQLFingers

SQL Server 2025 went GA in November. The upgrades ...

Storage structures 1 – On-disk rowstore

From SQL Server Fast

When a query is slow, it is often caused by inefficient access to the data. So our tuning work very frequently comes down to figuring out how data was...

Azure Databricks, Spark and Snowflake

AI Guardrails in Snowflake: Keeping LLMs From Going Full Skynet on Your Data

From Sherpa of Data

AI in Snowflake is powerful.AI in Snowflake withou...

Azure SQL

Options for Migration to Azure SQL

With the retirement of the Data Migration Assistant (DMA) on July 16, 2025, and the retirement of Azure Data Studio in February 2026, what tools do we use to assess and migrate databases to Azure SQL?

Azure SQL Managed Instance

Azure SQL Managed Instance Next-Gen: Bring on the IOPS

From DCAC

If you’ve used Azure SQL Managed Instance Genera...

Career, Employment, and Certifications

21 Lessons from 14 Years at Google

From O'Reilly Radar - Insight

The following article originally appeared on Addy Osmani’s Substack newsletter, Elevate, and is being republished here with his permission. When I joined Google ~14 years ago, I thought the...

The messy life skills of a very organized database designer DBA (S01:E05)

From Dr SQL

After a bit of a holiday break, the podcast is back. And today’s episode explains it pretty well why I took a month off. My physical life is a...

Learn Better: Pause to Review More

From SQLServerCentral Blogs

 

Announcing the 2026 Data Professional Salary Survey Results, And They’re Great!

From Brent Ozar Unlimited

 

Cloud - AWS

Opening the AWS European Sovereign Cloud

From AWS News Blog

Deutsch | English | Español | Français | Italiano As a European citizen, I understand first-hand the importance of digital sovereignty, especially for our public sector organisations and highly...

Amazon EC2 X8i instances powered by custom Intel Xeon 6 processors are generally available for memory-intensive workloads

From AWS News Blog

AWS is announcing the general availability of Amazon EC2 X8i instances, next-generation memory optimized instances powered by custom Intel Xeon 6 processors available only on AWS. X8i instances are...

Computing in the Cloud (Azure, Google, AWS)

Reduce Your Cloud Storage Costs by Storing Files and Metadata in Parquet Files

 

Data Privacy, Compliance, and Governance

Who Decides Who Doesn’t Deserve Privacy?

From Troy Hunt

 

HA/DR/Always On/Clustering

The SQL Server Database Application Security & High Availability Checklist by Sarpedon Quality Lab

As a database application vendor, the security and...

Microsoft Fabric ( Azure Synapse Analytics, OneLake, ADLS, Data Science)

Fabric Patterns: Solution Architecture & the Role of the Analyst Engineer

From Paul Turley's SQL Server BI Blog

This post is part of a series of excerpts from my forthcoming book “Microsoft Power BI Data Analyst Associate Study…

Performance Tuning SQL Server

Fun Query Plan Friday

From Erik Darling Data

Fun Query Plan Friday   Going Further If this is the kind of SQL Server stuff you love learning about, you’ll love my training. I’m offering a 25% discount...

Stored Procedure IF Branching and Deferred Compilation In SQL Server

From Erik Darling Data

Stored Procedure IF Branching and Deferred Compilation In SQL Server Going Further If this is the kind of SQL Server stuff you love learning about, you’ll love my training....

How indexes are used with COUNT in SQL Server

From Dr SQL

 

A New Query Hint to Override Batch Mode on Row Store Heuristics

From Erik Darling Data

 

PowerPivot/PowerQuery/PowerBI

Comparing Microsoft Direct Lake vs Import– Which Semantic Model performs best?

From FourMoo

I was recently part of a discussion (which I have ...

Performance of limited and regular relationships in Power BI

From Sqlbi

 

Product Reviews and Articles

Flyway Tips: AI Generating Migration Script Names

From SQLServerCentral Blogs

AI is a big deal in 2026, and at Redgate, we’re experimenting with how AI can help developers and DBAs become better at their jobs. One of the areas... The...

Got Drift? Redgate Flyway now helps you resolve it quicker

From Blog – Redgate Software

Teams work on databases across multiple environmen...

SQL Prompt Product Updates – January 2026

From Blog – Redgate Software

SQL Prompt’s January release brings support for ...

Redgate Flyway Product Updates – January 2026

From Blog – Redgate Software

Redgate Flyway’s January update brings faster drift resolution, AI-powered deployment descriptions, and a look back at everything we shipped in 2025. Plus, we want to hear from you about...

Setting PK Names in Redgate Data Modeler

From SQLServerCentral Blogs

 

SQL Server News

SQL Server 2022 Cumulative Update 23

From Glenn Berry

On January 15, 2026, Microsoft released SQL Server 2022 Cumulative Update 23. This is Build 16.0.4235.2. By Microsoft’s count, there are 15 public fixes and improvements in this CU,...

SQL ConstantCare® Population Report: Winter 2026

From Brent Ozar Unlimited

 

T-SQL and Query Languages

Common SQL Server Issues: "An invalid length was passed…"

From SQLBlog.org

In this series on common SQL Server problems, I provide some guidance around the error message "An invalid length was passed to the LEFT or SUBSTRING function..." errors.

Common SQL Server Problems: Invalid Length

From Simple Talk

Learn why SQL Server throws the invalid length err...

SQL, MDX, DAX – the languages of data

From SQLServerCentral Blogs

Ramblings of a retired data architect Let me start...

A Neat Trick with Using SELECT to Assign Variable Values

From Erik Darling Data

A Neat Trick with Using SELECT to Assign Variable ...

Tech News

US, Taiwan Sign $250B AI Chip Deal

From Past News - RSS Feeds

Taiwan has pledged at least $250 billion in direct U.S. investments for semiconductor, energy, and AI production. The post US, Taiwan Sign $250B AI Chip Deal appeared first on eWEEK.

The Lighter Side

Error'd: Chicken Feed

From Daily WTF

"Zero balance due now!" shouted davethepirate "To be fair, I had disputed a charge on a bill and they finally relented which should have actually resulted in them owing me $1.01,...

 
RSS FeedTwitter
This email has been sent to {email}. To be removed from this list, please click here. If you have any problems leaving the list, please contact the webmaster@sqlservercentral.com. This newsletter was sent to you because you signed up at SQLServerCentral.com. Note: This is not the SQLServerCentral.com daily newsletter list, and unsubscribing to this newsletter will not stop you receiving the SQL Server Central daily newsletters. If you want to be removed from that list, you can follow the instructions on the daily newsletter.
©2019 Redgate Software Ltd, Newnham House, Cambridge Business Park, Cambridge, CB4 0WZ, United Kingdom. All rights reserved.
webmaster@sqlservercentral.com

 

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -