Friday, 8 March 2013

Book Review: The Phoenix Project

Everyone who attended the “Rugged Devops” panel at RSA this year received a free copy of The Phoenix Project (by Gene Kim, Kevin Behr and George Spafford – the authors of Visible Ops), the fictional story of the education and transformation of an IT manager, an IT organization, and eventually of an entire company.



I'm not sure why they wrote the Phoenix Project as a novel. But they did. So I’ll review it first as a piece of story telling, and then look at the messaging inside.



The reason that I don’t like didactic fiction is that so much of it is so poorly written – generally forced and artificial. I was pleasantly surprised by the Phoenix Project. The first half of the novel tells a story about an IT manager forced into taking on responsibility for saving his company. Our well-meaning hero, an ex-marine sergeant (for some reason unclear to me, the hero, the CEO, and even the mysterious guru all have a military background) with an MBA but without any ambition except to quietly provide for his family. He has been successfully running his own little part of the IT group, so successfully that he is dramatically promoted to take over all of IT operations (and so successfully that his own group is never mentioned again in the story – it seems to run on auto-pilot without him). For a successful manager, our hero knows alarmingly little about how the rest of the IT organization works, or about the business, and so is unprepared for his new responsibility. He reluctantly accepts the big job, and then regrets it immediately as he realizes what a shit storm he has walked into.



It’s a compelling narrative that draws you in and is seems realistic even with the stock characters: the sociopathic SOB CEO, the unpopular everything-by-the-book CISO, the Software Development Manager who only cares about hitting deadlines (but not about delivering software that works), the Machiavellian Marketing executive, and the autistic genius that the entire IT organization of several hundred people all depend on to get all the important stuff done or fixed.



As a pure piece of story telling, things start to unravel in the second half with the emergence of the IT / Lean Manufacturing guru – when the story ends and the devops fable begins. From this point on, the plot depends on several miraculous conversions: everyone except the marketing exec sees the light and literally transform overnight. They even start to groom themselves nicely and dress better. Lifetime friendships are made over a few drinks, and everyone learns to trust and share: there’s a particularly cringe-inducing management meeting in which people bare their souls and weep. Conflicts and problems disappear magically usually because of the guru’s intervention – including an unnecessary scene where the guru shows up at a crucial audit meeting and helps convince the partner of the audit firm (an old buddy of his) that there aren't any real problems with the company’s messed up IT controls (“these aren't the droids you’re looking for”).


But the real heroes are the people running the manufacturing group: the one part of this spectacularly mismanaged company that somehow functions perfectly is a manufacturing plant where everyone can all go to learn about Kanban and Lean process management and so on. Without the help of the smug and smart-alecky guru - who apparently helped create this manufacturing success - and his tiresome Zen master teaching approach (and sometimes even with his help), our hero is unable to understand what’s wrong or what to do about it. He doesn't understand anything about demand management, how to schedule and prioritize project work, that firefighting is actual work, how to get out of firefighting mode, how to recognize and manage bottlenecks in workflow, or even how important it is to align IT with business priorities (where did he get that MBA any ways?). Luckily, the factory is right there for him learn from, if he only opens his eyes and mind.



What will you learn from The Phoenix Project?



The other problem with this story telling approach is that it takes so damn long to get to the point – it’s a 338 page book with about 50 pages of meat. Like Goldratt's The Goal (which is referenced a couple of times in this book), The Phoenix Project leads the reader to understanding through a kind of detective story. You have to be patient and watch as the hero stumbles and goes down blind alleys and ignores obvious clues and only with help eventually figures out the answers. Unfortunately, I'm not a patient reader.



This is a gentle introduction to Lean IT and devops. If you've read anything on Kanban and devops you won’t find anything surprising, although the authors do a good job of explaining how Lean manufacturing concepts can be applied to managing IT work. The ideas covered in the book are standard Lean and Theory of Constraints stuff, with a little of David Anderson’s Kanban and some devops – especially Continuous Deployment as originally described by John Allspaw and Continuous Delivery.



The guru’s lessons are mostly about visualizing and understanding and limiting demand – that you should stop taking on more work until you can get things actually working so that you’re not spending all of your time task-switching and firefighting; identifying workflow bottlenecks and protecting or optimizing around them; how reducing batch size in development will improve control and to get faster feedback; that in order to do this you have to work on simplifying and standardizing deployment; and how valuable it is to get developers and operations to work together.



My complaints aren't with the ideas – I buy into a lot of Devops and agree that Kanban and Lean have a lot to offer to IT ops and support teams (although I'm not sold on Kanban by itself for development, certainly not at scale). But I was disappointed with the unrealistic turnaround in the second half of the book. It’s all rainbows and unicorns at the end. IT, the business, development and security all start working together seamlessly. Management is completely aligned. Performance problems? No problem – just go the Cloud. And they even bring in the famous Chaos Monkey in the last couple of pages just because.



Spoiler Art: Everything goes so well in a few months that the company is back on track, plans to outsource IT and to break up the company are cancelled, the selfish head of marketing is canned, and our hero is promoted to CIO and put on the fast track to corporate second in command. Sorry: nothing this bad gets that good that easily. It is a fable after all, and too hard to swallow.



The Phoenix Project is a unique book – when was the last time that you read an actual novel about IT management?! It was worth reading, and if it introduces devops and Lean ideas to more people in IT, The Phoenix Project will have accomplished something useful. But it’s not a book that you can use to get things done. There are lessons and recipes and patterns but they take work to pull out of the story. There’s no index, no good way to go back to find things that you thought were useful or interesting. So I am looking forward to the Devops Cookbook: something practical that hopefully explains how these ideas can work in businesses that don’t look all like Facebook and Twitter.


Thursday, 7 March 2013

Timeline interattiva di PlayStation





























In allestimento...

Peer reviews for security are a waste of time?

At this year’s RSA conference, one of the panel’s questioned whether software security is a waste of time. A panellist, John Viega, said a few things that I agreed with, and a lot that I didn't. Especially that

“peer reviews for security are a waste of time.”



This statement is wrong on every level.



Everyone should know by now that code reviews find real bugs – even informal, lightweight code reviews.



“Reviews catch more than half of a product’s defects regardless of the domain, level of maturity of the organization, or lifecycle phase during which they were applied”. What We Have Learned About Fighting Defects



Software security vulnerabilities are like other software bugs – you find them through testing or through reviews. If peer code reviews are a good way to find bugs, why would they be a waste of time for finding security bugs?



There are only a few developers anywhere who write security plumbing: authentication and session management, access control, password management, crypto and secrets handling. Or other kinds of plumbing like the data access layer and data encoding and validators that also have security consequences. All of this is the kind of kind of stuff that should be handled in frameworks anyway – if you’re writing this kind of code, you better have a good reason for doing it and you better know what you are doing. It’s obviously tricky and high-risk high-wire work, so unless you’re a team of one, your code and decisions need to be carefully reviewed by somebody else who is at least as smart as you are. If you don’t have anyone on the team who can review your work, then what the hell are you doing trying to write it in the first place?



Everybody else has to be responsible for writing good, defensive application code. Their responsibilities are:

  • Make sure their code works – that the logic is correct

  • Use the framework properly

  • Check input data and return values

  • Handle errors and exceptions correctly

  • Use safe routines/APIs/libraries

  • Be careful with threading and locking and synchronization



A good developer can review this code for security and privacy requirements: making sure that you are masking or encrypting or – even better – not storing PII and secrets, auditing, properly following access control rules. And they can review the logic and workflow, look for race conditions, check data validation, make sure that error handling and exception handling is done right and that you are using frameworks and libraries carefully.



This is what code reviews are for. To look for and find coding problems. If you find these problems – and code reviews are one of the most effective ways of doing this – your code will be safer and more secure. So I don’t get it. Why are peer reviews for security a waste of time?

Wednesday, 20 February 2013

Speciale: PlayStation Meeting 2013 - Streaming Live






Ci siamo, PlayStation Meeting 2013 è arrivato! Lo show inizierà allo scoccare della mezzanotte di oggi e potrete assistere allo streaming live proprio qui, direttamente da questo post oltre che sulla nostra Pagina Facebook. Potrete anche commentare l'evento grazie al box commenti di Facebook integrato. Sarà possibile vedere lo streaming se preferite anche su PlayStation Home.



E nell'attesa vi segnaliamo la serie di video "PlayStation Evolution" realizzati e rilasciati nei giorni scorsi da Sony per raccontare l'evoluzione di PlayStation.

Sono disponibili a questo LINK.



















Saturday, 16 February 2013

Speciale: PlayStation Evolution






Sony ha rilasciato, in attesa del PlayStation Meeting del 20 febbraio dove è stata svelata la nuova PlayStation 4, una serie di video realizzati per raccontare l'evoluzione di PlayStation!


































































































Tuesday, 5 February 2013

Recensione Utente: Syphon Filter 2 - (PSone)
















Disponibile per: PSone

Data di uscita: 2000

Genere: Sparatutto in terza persona, Stealth

Sviluppatore: Eidetic

Produttore: SCEA


















Recensione inviata da: Salvatore Winchester | Inserita il: 05/02/2013













E’ passato un anno da quando la saga Syphon Filter è entrata a far
parte della nostra console Play Station e oserei dire anche con
grandissimo successo visto che, come tutti sappiamo, il maggior rivale
del nostro famigerato Gabe Logan è l’indiscusso Solid Snake di Metal
Gear Solid. Syphon Filter 2 ci ha impiegato un anno ad uscire ma, nel
gioco sono passate solo pochissime ore dalla distruzione del missile che
doveva inondare il virus Syphon Filter nell’atmosfera.

Anche questa volta Syphon Filter 2 è stato sviluppato dalla SCE Bend Studio e pubblicato dalla 989 Studios. La trama è la continuazione del primo capitolo di Syphon Filter.



Gli agenti  Gabe Logan e Lian Xing, i due agenti segreti che hanno
scoperto il complotto del virus, stanno cercando di svelare l’identità
dei creatori del virus Syphon Filter. Gabe Logan scopre alcuni file segreti di Jonathan Phagan, Direttore
Generale della Pharcom, ma Lian Xing, infettata dal virus Syphon Filter,
viene rapita dall’Agenzia per essere usata come cavia.



Il gameplay è rimasto pressochè identico al primo Syphon Filter. Per quanto riguarda la parte grafica ha avuto un lieve miglioramento,
la visualizzazione dei filmati è migliorata grazie alla particolarità
delle telecamere viste in maniera dinamica e, particolare importanza
alle luci che hanno fatto modo di godersi meglio i filmati.  Purtroppo
anche in questo secondo capitolo capiterà di vedere qualche sgranata dei
volti però i filmati sono davvero impeccabili. Il doppiaggio l’hanno
migliorato molto, soprattutto le voci dei personaggi.



Tra i personaggi principali abbiamo come sempre gli agenti Gabe Logan, Lian Xing e una nuova entrata Teresa Lipan.

Gabe Logan è uno dei migliori agenti operativi dell’Agenzia, ora
ricercato della sua stessa organizzazione. Mentre era sulle tracce dei
responsabili della creazione del virus Syphon Filter, Gabe ha sventato
un disastro internazionale distruggendo un missile interbalistico
puntato contro il Kazakistan.

Lian Xing è un agente operativo dell’Agenzia dal 1995. Assegnata alle
operazioni sul campo al fianco di Gabriel Logan, Lian era inizialmente
un agente operativo dei servizi segreti cinesi ma venne poi reclutata
dall’Agenzia nel 1996 con una nuova identità e nuovi dati anagrafici.
Ora l’Agenzia la accusa di essere una terrorista. Contagiata dal virus
Syphon Filter, Lian Xing è stata rapita dall’Agenzia per servire da
cavia di laboratorio.







Teresa Lipan è un Ex Agente Operativo Speciale, nazionalità
Americana. Teresa dirige una rete di spionaggio indipendente dal suo
caravan nascosto nel deserto dell’Arizona. Il suo compito è quello di
coordinare segretamente le operazioni sul campo di Gabe Logan e Lian
Xing.

In Syphon Filter 2 abbiamo ben 21 livelli caratterizzati anche da
lunghi filmati che spiegano la trama e, che risulta essere decisamente
più avvincente e adrenalinica rispetto al capitolo precedente.  Al
contrario del primo Syphon Filter in questo secondo capitolo abbiamo la
possibilità dei checkpoint così, quando vi capiterà di morire, avrete la
possibilità di tornare all’ultimo checkpoint senza affrontare lo stesso
livello svariate volte.



Con Syphon Filter 2 è stato introdotto  la possibilità di giocare in
multiplayer in modalità split-screen; gli schermi sono divisi
verticalmente, si possono utilizzare tutti i personaggi di questo
capitolo tra cui: protagonisti, nemici, terroristi, inoltre si avrà la
possibilità di rigiocare col compagno i diversi luoghi visti in modalità
singolo/storia.














E’ sicuramente un bellissimo gioco dal punto di vista di trama e
giocabilità, vi prende dall’inizio alla fine; per chi volesse
riassaporare il 2 capitolo o chi ancora non l’ha giocato, questo è il
momento giusto per iniziarlo. Purtroppo nel PSN non l’hanno ancora
aggiunto però, per chi ha il gioco originale non ci saranno problemi.
Personalmente è un gioco emozionante che  trasmette veramente emozioni a
non finire e, ogni volta che lo rigioco è sempre stupendo, per non
parlare della trama che come detto prima è favolosa e ricca di colpi di
scena. Da grandissimo fan della saga e a chi piace il genere lo
consiglio vivamente!


























    DISCLAIMER: Questo articolo è stato scritto da un utente di PlayStation Generation e non dalla nostra Redazione. Le opinioni qui espresse appartengo esclusivamente a questo utente.




    Main menu







    Sunday, 3 February 2013

    Lista modelli PSP































    I Codici hardware di PSP:

    Ogni PSP ha un suo nome in codice, utile ad
    identificarne il modello. Sicuramente avrete notato questo codice
    impresso sulla confezione della vostra PlayStation Portable, composto da lettere
    e numeri. Cosa rappresenta? Di seguito lo schema:











    Il Codice Regione, fornisce anche la colorazione della specifica console e viene espresso tramite 2 o più lettere extra poste alla fine. Sotto, la lista completa dei colori di PS2:



    IN COSTRUZIONE





    Nello specifico esistono 5 modelli di PSP rilasciati dal 2004 al 2011:



    ► PSP-10xx Series (PSP Fat)

    Questa è la PSP originale rilasciata nel 2004



    ► PSP-20xx Series (PSP Slim and Light)

    Questa è la versione "Slim e Light" di PSP uscita nel settembre del 2007. Ha aggiunto alcune caratteristiche mancanti alla versione "Fat", in particolare, l'uscita video, la ricarica via USB, maggiore memoria flash e memoria principale. L'uscita video è di tipo progressiva a 720x480p (NTSC) e 720x576p (PAL) compatibile per giochi e applicazioni.



    ► PSP-30xx Series (PSP Brite)

    Questo modello di PSP è stato rilasciato nell'ottobre del 2008. Ha aggiunto un microfono incorporato e un migliore display LCD. Ha inoltre aggiunto il supporto per l'uscita TV interlacciata (in aggiunta a quella progressiva).



    ► PSP-N10xx Series (PSP Go)

    Questo modello di PSP è stato rilasciato nel 2009. Ha aggiunto 16GB di memoria flash interna e il supporto bluetooth, ma ha rimosso il drive UMD. Inoltre, la Memory Stick Duo è stata modificata per supportare le schede M2.



    ► PSP-E10xx Series (PSP Street)

    Ultimo modello di PSP rilasciato esclusivamente in Europa dal 26 ottobre 2011. Questa nuova PSP non offre connettività Wi-Fi, dispone di audio mono ed ha un'estetica leggermente differente con una finitura nero carbone opaca ma consente di accedere nuovamente all'intero catalogo software di PSP su dischi UMD oltre che su PlayStation Store.












    Per ulteriori dettagli sulle differenti caratteristiche, di seguito
    trovate la lista dei modelli di PSP rilasciati nel corso della
    storia. Cliccate le schede per la descrizione completa.



























    Main menu