Problems displaying this newsletter? View online.
SQL Server Central
Featured Contents
Question of the Day
 
The Voice of the DBA
 

A Security and AI Fail

The AI boom is still growing like crazy. Many organizations are trying to learn how they can use AI to improve operations and become more efficient, at a reasonable cost. Plenty of companies are spending crazy amounts of AI tokens, sometimes blowing their yearly budgets in months and not necessarily receiving substantial value back. Some companies are trying to train AIs to understand their operations and perhaps reduce their other costs, primarily labor. Still others are tip-toeing in the waters of AI LLM use and conducting smaller experiments, with limited access to AI technology.

Meta has been a company on the forefront of trying to train AI based on the work employees already perform. There has been plenty of concern that their efforts are designed to lower headcount and replace humans with AI agents. That might or might not work, though I don't expect a lot of organizations to do this. It's likely harder than any of the hype suggests, and most organizations have much more complex types of operations than Meta.

However, in collecting this data, Meta has had other issues. Notably, they have had security problems with all the data they are trying to collect. Some of this data was exposed and they have paused the data collection for now. They were trying to move fast, likely cutting corners or not thinking things through and had issues. Hackers are constantly looking for holes and the quicker anyone moves to change their software and processes, the more likely that security holes slip by them.

Plus, data governance and protection is hard. Most developers really don't think through data protection and security well. They're focused on software and assume the data store (RDBMS, NoSQL, data lake, etc.) is handled by someone else.

Data is hard. Especially at scale.

While I'm sure most companies aren't looking to track employee's every move (That's a big uplift), they will be trying to move data around and use it for AI purposes. With RAG, with model training, who knows how, but they are just as likely to cause a security incident if they are not careful.

Think data governance and data security early. Develop patterns with DBAs and InfoSec alongside software engineers to ensure that as you stand up new agents, systems, and data stores, you aren't asking for trouble. Re-using existing data is fine, but if you assume that your development team automatically knows about data security, you're going to have issues. They likely don't, and if you or they think they do, make them prove it.

AI is amazing, but it's also easy to mess up the data part of this. Everyone I deal with at Redgate Software is concerned about data governance, and more so all the time. For good reason. Meta made the headlines, but a lot of us aren't better at securing our systems. We just aren't as much of a media target.

Steve Jones - SSC Editor

Join the debate, and respond to today's editorial on the forums

 
 
 Featured Contents
SQLServerCentral Article

How Clustering can be Used as a Preprocessing Technique for Classification in Azure Machine Learning

Dinesh Asanka from SQLServerCentral

Learn about using classification as a technique to prepare your data for additional machine learning analysis.

Technical Article

Confession Time: I Never Taught You About B-Trees.

Additional Articles from SQLServerCentral

I work with databases for a living. I teach people, and I help them via consulting. And as far as I can remember, I’ve never written something about how b-trees work.

Blog Post

From the SQL Server Central Blogs - Reflections on the Life of a DBA

MarlonRibunal from Marlon Ribunal - SQL, Code, Coffee, etc.

The DBA life is fraught with pain. Those battles that we endure are mostly invisible to many. Those countless sleepness nights are a testament to our dedication. Whether that...

Blog Post

From the SQL Server Central Blogs - Moving On-Prem PostgreSQL to the Cloud: Picking the Right Path for Big Tables

epivaral from SQL Guatemala

Every PostgreSQL migration eventually hits the same fork in the road. The database is small enough to dump and restore in a maintenance window, or it isn't. Once you...

Refactoring Databases cover

Refactoring Databases: Evolutionary Database Design

Site Owners from SQLServerCentral

Refactoring has proven its value in a wide range of development projects–helping software professionals improve system designs, maintainability, extensibility, and performance.

 

 Question of the Day

Today's question (by Steve Jones - SSC Editor):

 

Moving the Error Log

How can I change the location in which the SQL Server error log is written in SQL Server 2025?

Think you know the answer? Click here, and find out if you are right.

 

 

 Yesterday's Question of the Day (by Steve Jones - SSC Editor)

DBCC CHECKDB Limits II

I have a SQL Server 2025 database that I want to check for corruption every night. One of the things we do is disable indexes used for ETL loads during the weekend and re-enable them on Monday morning.

If we run DBCC over the weekend, are our disabled indexes checked for consistency?

Answer: No

Explanation: No, DBCC CHECKDB doesn't check disabled indexes. Ref: DBCC CHECKDB - https://learn.microsoft.com/en-us/sql/t-sql/database-console-commands/dbcc-checkdb-transact-sql?view=sql-server-ver17

Discuss this question and answer on the forums

 

 

 

Database Pros Who Need Your Help

Here's a few of the new posts today on the forums. To see more, visit the forums.


SQL Server 2019 - Development
cons for a dev machine in a different version of sql from our prod server - hi, im not a dba. For a couple of years our dev sql server has been a 2022 vm std instance with varying levels of horsepower depending on how loudly we objected.   For many years our prod , 2019 on prem std.  both have ssas, ssis, ssrs and of course the engine. We are looking […]
Editorials
SSRS Reminded Me of the Time Microsoft Retired TMG - Comments posted to this topic are about the item SSRS Reminded Me of the Time Microsoft Retired TMG
I Can't Make You Learn - Comments posted to this topic are about the item I Can't Make You Learn
A Quick Second Opinion - Comments posted to this topic are about the item A Quick Second Opinion
Article Discussions by Author
BIT_COUNT II - Comments posted to this topic are about the item BIT_COUNT II
Why Your SQL Permissions Disappeared - Comments posted to this topic are about the item Why Your SQL Permissions Disappeared
Why Your SQL Permissions Disappeared - Comments posted to this topic are about the item Why Your SQL Permissions Disappeared
Five Intelligent Query Processing Features in SQL Server 2022 That Quietly Tune Your Workload - Comments posted to this topic are about the item Five Intelligent Query Processing Features in SQL Server 2022 That Quietly Tune Your Workload
Checking the Error Log I - Comments posted to this topic are about the item Checking the Error Log I
Calculating Geometric Mean in Power BI - Comments posted to this topic are about the item Calculating Geometric Mean in Power BI
SQL Server 2022 - Administration
Alamat Kantor Bank BCA KCP Lomanis Telp:08218154393 - WA:08218154393 Jl. Gatot Subroto No.080A, RT.001, Cigobang, Gunungsimping, Kec. Cilacap Tengah, Kabupaten Cilacap, Jawa Tengah 53224
Upgrade 2016 Standard to 2022 Express - Title pretty much says it all - can this be done? I've tried several paths and always come up against some failure in the installation process. I can install a new version of 2022 Express, but that means also porting all my logins and roles, as well as restoring every database. I would much prefer […]
Inquiry – Enforcing ApplicationIntent=ReadOnly via GPO - Hello, I would like to ask whether it is technically possible to redirect a specific list of client machines by forcing their SSMS to automatically use the ApplicationIntent=ReadOnly option when connecting to SQL Server. The goal is to apply this behavior through an Active Directory Group Policy (GPO), ensuring that all SQL connections initiated from […]
SQL Server 2022 - Development
Alamat Kantor Bank BCA KCU CILACAP Telp:08218154393 - WA:08218154393 Jl. Jend. Ahmad Yani No.118, Sidakaya Dua, Sidakaya, Kec. Cilacap Sel., Kabupaten Cilacap, Jawa Tengah 53212
Getting results from a Procedure to join to a query - I have a need to execute a stored procedure and return the results to something I can join to in a query. I am trying to execute a Trial balance from our ERP and get those balances and account numbers to correlate to another table with new account numbers. So my stored procedure execution looks […]
 

 

RSS FeedTwitter

This email has been sent to {email}. To be removed from this list, please click here. If you have any problems leaving the list, please contact the webmaster@sqlservercentral.com. This newsletter was sent to you because you signed up at SQLServerCentral.com.
©2019 Redgate Software Ltd, Newnham House, Cambridge Business Park, Cambridge, CB4 0WZ, United Kingdom. All rights reserved.
webmaster@sqlservercentral.com

 

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -