Wednesday, April 29, 2009
Sunday, March 29, 2009
Monday, March 16, 2009
Sunday, February 08, 2009
Yes Its Tucson!
May be not exactly Tucson, its 25 miles from Tucson.

And yes the real Tucson is one in the backdrop of pic below

And yes the real Tucson is one in the backdrop of pic below
Labels:
Life
Monday, December 08, 2008
Monday, November 10, 2008
175 random ilayaraja hitz (mostly melodies)
Years of collecting songs, song db has bloated big enuf, that i play mostly the playlists in shuffle mode. Here is the dump of one of the IR playlist (mostly melodies), not by any means complete IR collection.

Track list >>>
IR_Hitz_1.rar
IR_Hitz_2.rar
IR_Hitz_3.rar
IR_Hitz_4.rar
IR_Hitz_5.rar
IR_Hitz_6.rar
IR_Hitz_7.rar
IR_Hitz_8.rar
---------------------------------------------------------------
PS: Here is link to album Vatsalyam by Bombay S. Jayashri. A Collection of Traditional Indian Lullaby.
Track list >>>
IR_Hitz_1.rar
IR_Hitz_2.rar
IR_Hitz_3.rar
IR_Hitz_4.rar
IR_Hitz_5.rar
IR_Hitz_6.rar
IR_Hitz_7.rar
IR_Hitz_8.rar
---------------------------------------------------------------
PS: Here is link to album Vatsalyam by Bombay S. Jayashri. A Collection of Traditional Indian Lullaby.
Tuesday, October 14, 2008
Strange circle around moon
.
Labels:
Life
Tuesday, October 07, 2008
George W Bush: Go Fish!
US Gross Federal Debt, unadjusted for inflation.

National debt when president George W Bush Jr. took office at the beginning of 2001 was about $5.6 trillion and it is close to 10.2 trillion as of today.
"Humble foreign policy" anyone?
Reminds me a line from Jurassic Park, "I don't blame people for their mistakes. But I do ask that they pay for them."
யார் யாருகோ டாக்டர் பட்டம் குடுகிறிங்கோ, இவருக்கு குடுங்கப்பா டபுல் டாக்டர் பட்டம்.

National debt when president George W Bush Jr. took office at the beginning of 2001 was about $5.6 trillion and it is close to 10.2 trillion as of today.
"Humble foreign policy" anyone?
Reminds me a line from Jurassic Park, "I don't blame people for their mistakes. But I do ask that they pay for them."
யார் யாருகோ டாக்டர் பட்டம் குடுகிறிங்கோ, இவருக்கு குடுங்கப்பா டபுல் டாக்டர் பட்டம்.
Labels:
Scraps
Wednesday, August 20, 2008
Authentication & Authorization
Use AD for authentication and DB for authorization
I'm trying to reason out the above statement with best of my knowledge, this may be specific to windows environment. Do leave your thoughts if you know of better reasons.
A company intranet website application can be open to entire domain users and hence don't need any authentication at all. But we may need to restrict access to a phone list application to certain groups, this application may include additional authorization restrictions like certain group of users should not be able to view some section of data say for example "personal mobile numbers". Best approach is to authenticate all users with a AD group and use different authorization data store like a database.
Can we not use db for authentication, like use "authorization data store" and check if user is not authorized to do any steps in the application and redirect to access denied page? Though its a technically possible option, in this case, control on who gets access to phone list application is thro' db. Everyone will agree, access to that is weaker compared to a secure AD group membership which are restricted to AD administrators hands. Inherently. access to application db has wider spread, compared to AD. Also AD authentication blocks unauthorized users at the gate i.e stopped even before entering into application.
In other end of spectrum, why we should not use AD for authorization. For simplicity sake, if we have 3 authorization groups for each application and we have 10 applications and toss in 2 environments (dev/prod), we end up with 60 AD groups. Its work on AD admins that in course of time will become un-manageable, worst-case scenario, someone getting access which they shouldn't.
That said, there is room for all shades of grey, for example any enterprise has to maintain AD groups for something or other, like share folder access. Using the same phone list application, if there is a requirement to restrict users from viewing sr. mgmt contacts. I'd rather make that authorization against AD than have it inside my application db.
I'm trying to reason out the above statement with best of my knowledge, this may be specific to windows environment. Do leave your thoughts if you know of better reasons.
A company intranet website application can be open to entire domain users and hence don't need any authentication at all. But we may need to restrict access to a phone list application to certain groups, this application may include additional authorization restrictions like certain group of users should not be able to view some section of data say for example "personal mobile numbers". Best approach is to authenticate all users with a AD group and use different authorization data store like a database.
Can we not use db for authentication, like use "authorization data store" and check if user is not authorized to do any steps in the application and redirect to access denied page? Though its a technically possible option, in this case, control on who gets access to phone list application is thro' db. Everyone will agree, access to that is weaker compared to a secure AD group membership which are restricted to AD administrators hands. Inherently. access to application db has wider spread, compared to AD. Also AD authentication blocks unauthorized users at the gate i.e stopped even before entering into application.
In other end of spectrum, why we should not use AD for authorization. For simplicity sake, if we have 3 authorization groups for each application and we have 10 applications and toss in 2 environments (dev/prod), we end up with 60 AD groups. Its work on AD admins that in course of time will become un-manageable, worst-case scenario, someone getting access which they shouldn't.
That said, there is room for all shades of grey, for example any enterprise has to maintain AD groups for something or other, like share folder access. Using the same phone list application, if there is a requirement to restrict users from viewing sr. mgmt contacts. I'd rather make that authorization against AD than have it inside my application db.
Labels:
Security
Saturday, August 02, 2008
BBC - The Story of India
Six part BBC series which attempts to cover the story of India from past to current. I felt they mostly covered Aryan part, shadowing Dravidian side of history.
Subscribe to:
Posts (Atom)


