I thought that BT and Virgin Media were the only 2 providers which run cables to your house...

Remember the IT rule....none, one or many...

I notice Oracle is not on the list.

All affected people (including on Azure) over to Oracle Cloud.

When that is added then over to Rackspace's Cloud then to...then to..all the way to Dave's Cloud aka Billy Bob's Cloud...aka...keep changing the name/owner every week!

"Well,shucks...sure we can move them there VM's to Suzie's Cloud for yer, yeeee-haw!"

Not that any of the smaller Cloud providers are cowboy's...perish the thought!

Only had to do this once...my reply (shouted across machine room)..."Who was the last person to make X mistake"...turns to the complainer..."ooh, someone now in your team!"...nuff said!

If you have it, why is it not listed at top500.org?

Bubblewrap jumpsuits!

I still remember entering lots of license keys for a full text database in the early 90's.

The license keys came via fax!

Luckily we worked out that zeros had a slash as did Z's, there were no lower case I's and my collegue worked out there were no lower case L's!!

Are BT and Talk talk really seperate?

When I spoke to the BT engineer ~7 years back they said that Virgin Media was the only one with separate cables to the exchange.

[ Currently have BT and Virgin Media fibre with iPhone as backup!!]

The idea is to put your decryption code in the enclave and then then send encrypted text and a description of the operation you want to perform to the enclave.

The unencrypted data never leaves the enclave, not even the hypervisor sees the unencrypted data.

E.g. to search encrypted data in sql server


What I do not get is how you get the decryption keys into the enclave securely!

"The client driver sends the column encryption keys required for the operations to the secure enclave (over a secure channel)."

What secure channel which the hypervisor cannot see? Hmmm..

I was able to walk across the road blindfolded between 3am and 4am hence I can walk across the road blindfolded anytime...go head! The stock market has been going up all year hence will always go up...hhmmm!

Exactly, you need and off-site AIRGAPPED backup....tapes anyone?

These days people seem to want everything online and lost interest in AIRGAPPING!

Also Dave's rule 1 : Test your restores not your backups!

"The Daily WTF happened last night".....after you drink it you need a (P)ersonal (I)njury (S)upport (S)ystem!

Sounds like "Always Encrypted with Enclaves http://smooth1.co.uk/sqlbits2018/sqlbits2018roundup.html#2

1. Is this protected against https://www.theregister.co.uk/2018/03/28/intel_shrugs_off_new_sidechannel_attacks_on_branch_prediction_units_and_sgx/ with "utilization of an appropriate side channel attack-resistant crypto implementation inside the enclave"

2. has it been rebuilt with https://www.theregister.co.uk/2018/03/01/us_researchers_apply_spectrestyle_tricks_to_break_intels_sgx/ " Enclave code will need to be rebuilt and redeployed using the updated development kit to be protected from malicious sysadmins."

3. As per my blog entry above "On first use the client driver and enclave negotiate a shared secret and then setup the secure tunnel" Surely to negotiate a shared secret there is a small initial window where you first have to trust the hypervisor?

"Do you test your backups?"


"What? You have to test your backups"

"...We test our restores!"

Yes but you are summing an infinite series....endless!

Downloading Software, I have 330Mb and get around that when downloading Microsoft SQL Server or Windows 10 related preview updates which seem to appear every few days.



"In a production environment, we recommend that you use static IP addresses in conjunction the virtual IP address of a Failover Cluster Instance. We recommend against using DHCP in a production environment. In the event of down time, if the DHCP IP lease expires, extra time is required to re-register the new DHCP IP address associated with the DNS name. "

Windows+Ctrl+C - turn screen black and white or color !

Just checking Wikipedia https://en.wikipedia.org/wiki/Software_Guard_Extensions#cite_note-14 we see that

a) There was a Prime+Probe attack which used "certain CPU instructions in lieu of a fine-grained timer to exploit cache DRAM side-channels" and a coutermeasure was published

b) The LSDS group at Imperial College London showed a proof of concept that the Spectre speculative execution security vulnerability can be adapted to attack the secure enclave and the code is dated 2 months ago.

I wonder if the "compiler-based tool, DR.SGX" which was a coutermeasure for Prime+Probe could be extended to handle Spectre?

6000 machines...so run 200 machines at a time for 30 times.

What is this obession with 10,100,2000,rest and doing a massive population in 5 steps?

Even if 2110 machines worked fine how long would it take to fix the last 3900 machines if enough of them broke?

For failures it is not the number of times you have done it before but the size of the failure domain and how long it takes to fix.

it should be possible to rollout automatically in small batches and even had multiple upgrades rolling out at the same time on an automatic schedule, ripple across the farm!

If it is automated and scheduled who cares how many batches of upgrades are run?

You would catch errors with less impact that way as the failed batch size would be smaller and it would be minimal extra work if designed correctly.

This is the next stage in cloud service design - being able to have slower rolling upgrades with smaller batches!


1st prompt

This will shutdown 1040 servers, please type 1040 to continue.

2nd prompt

This will reduce capacity enough to cause a service failure for the following 8 services




Please type "8 SERVICE FAILURES" to continue.

Hi Intel,

I am CEO of a company which is about to become a "PC/server maker", how will we get the fixes?

David Williams


Blue Rose Quantum Consulting

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 includes Windows 7/8.1

Also see https://portal.msrc.microsoft.com/en-us/security-guidance


Meltdown exploit - https://github.com/IAIK/meltdown

Videos of Meltdown in action - https://spectreattack.com/

True, I am covering almost all of these at SQL Saturday Exeter my "SQL Server 2014 (not Hekaton)" talk.


Hmm. went to event where I heard more nodes than that being used in the Microsoft cloud, of course at that scale you need to talk to Microsoft first..


(Transactions) or (integrity checks).

Integrity checks i expect are unique/primary/check/foreign key constraints. We used to disable them when doing data migrations until the end.

"You can't disable logging on mssql.".

Pity, you can on Informix!


Already there is 2012 SP1 CU2 - Backup to Azure via Powersheel, T-SQL and SMO only.

2014 adds backup and restore via SSMS.


... I felt a tremor in the force!

Welling - where i get Virgin Media 100MB AND BT up to 80 MB.



I am se of london and get www.speedttest.net 80mb down 4.89 mb up from my virgin media connection,

Have not checked my other Fibre connection from BT yet...



Funny I gave up 2 BE lines in E14 when I moved out of Poplar, that was almost 2 years agoand then exchange was ful then!


