Earlier quoted context omitted.
Yeah, but heads will have to roll for this one, the world will be calling for blood, so who better if not "the guy"?
the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks
Ask HN: What is in C-00000291*.sys?
41–50 of 104 posts
Re: Ask HN: What is in C-00000291*.sys?
#42Wouldn't want to be the guy who pushed this particular commit. It's ironic that the company that is supposed to prevent this sort of thing causes the biggest worldwide outage ever. Crowdstrike is finished. Let's hope this will result in at least a small increase in desktop Linux market share.
Re: Ask HN: What is in C-00000291*.sys?
#43Earlier quoted context omitted.
Yeah, but heads will have to roll for this one, the world will be calling for blood, so who better if not "the guy"?
the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks
Yeah, ideally management should know better. But management aren’t usually engineers. Even when they are, they don’t deal with the code on a day to day basis. They usually know much less about the actual processes and risks than the engineers on the ground.
Re: Ask HN: What is in C-00000291*.sys?
#44Earlier quoted context omitted.
the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks
More importantly, the companies that enabled auto update from a vendor to production rather than having a validation process. This sort of issue can happen with any vendor, penalising the vendor won't help with the next time this happens.
Re: Ask HN: What is in C-00000291*.sys?
#45Earlier quoted context omitted.
Just a small reminder that's it's never "the guy" and always "the process", or lack thereof.
Yeah, but heads will have to roll for this one, the world will be calling for blood, so who better if not "the guy"?
Re: Ask HN: What is in C-00000291*.sys?
#46https://cyberplace.social/@GossiTheDog/112812260542179660 > I've obtained copies of the .sys driver files Crowdstrike customers have. They're garbage. Each customer appears to have a different one. https://cyberplace.social/@GossiTheDog/112812454405913406 > The .sys files causing the issue are channel update files, they cause the top level CS driver to crash as they're invalidly formatted. It's unclear how/why Crowds…
They might just be encrypted with a customer-specific key. That wouldn't surprise me.
If you have a Crowdstrike customer ID (CID) — which you can pull from any device that has the implant — you can request any channel file you want from their file server.
Ask for metahash+/cfs/channelfiles/0000000291//C-00000291-00000000-00000001.sys and you should get something that starts with:
00000000: aaaa aaaa 0100 2301 0000 0500 0000 0000 ......#.........
00000010: 0100 0000 4808 0000 2c08 0000 0600 0004 ....H...,.......
That's a channel file, unencrypted.Re: Ask HN: What is in C-00000291*.sys?
#47The most successful malware of 2024, even though it only does denial of service.
Re: Ask HN: What is in C-00000291*.sys?
#48Earlier quoted context omitted.
the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks
It’s both. If you’re an engineer and you push out shitty code that takes down 911 systems and ambulances, you f’ed up. Push back against processes that cause harm, or have the potential to cause harm. You are ultimately responsible for your actions. No one else. The excuse of “I was just following orders” has been dead and buried since WW2. Yeah, ideally management should know better. But management aren’t usually en…