Live data from Hacker News

Ask HN: What is in C-00000291*.sys?

news.ycombinator.com

41–50 of 104 posts

Re: Ask HN: What is in C-00000291*.sys?

#41
post #27

Earlier quoted context omitted.

Yeah, but heads will have to roll for this one, the world will be calling for blood, so who better if not "the guy"?

the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks

More importantly, the companies that enabled auto update from a vendor to production rather than having a validation process. This sort of issue can happen with any vendor, penalising the vendor won't help with the next time this happens.

Re: Ask HN: What is in C-00000291*.sys?

#42

Wouldn't want to be the guy who pushed this particular commit. It's ironic that the company that is supposed to prevent this sort of thing causes the biggest worldwide outage ever. Crowdstrike is finished. Let's hope this will result in at least a small increase in desktop Linux market share.

Yes indeed. That's kind of how Chernobyl happened.

Re: Ask HN: What is in C-00000291*.sys?

#43
post #27

Earlier quoted context omitted.

Yeah, but heads will have to roll for this one, the world will be calling for blood, so who better if not "the guy"?

the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks

It’s both. If you’re an engineer and you push out shitty code that takes down 911 systems and ambulances, you f’ed up. Push back against processes that cause harm, or have the potential to cause harm. You are ultimately responsible for your actions. No one else. The excuse of “I was just following orders” has been dead and buried since WW2.

Yeah, ideally management should know better. But management aren’t usually engineers. Even when they are, they don’t deal with the code on a day to day basis. They usually know much less about the actual processes and risks than the engineers on the ground.

Re: Ask HN: What is in C-00000291*.sys?

#44
post #27

Earlier quoted context omitted.

the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks

More importantly, the companies that enabled auto update from a vendor to production rather than having a validation process. This sort of issue can happen with any vendor, penalising the vendor won't help with the next time this happens.

Was there a way to not enable these channel updates? If so, would you still check all the mandatory security measures when being audited?

Re: Ask HN: What is in C-00000291*.sys?

#45
post #17

Earlier quoted context omitted.

Just a small reminder that's it's never "the guy" and always "the process", or lack thereof.

Yeah, but heads will have to roll for this one, the world will be calling for blood, so who better if not "the guy"?

When the world calls for blood against your organization, it's a test of the organization's character: will they throw a scapegoat under the bus (even if there is a directly responsible person) or will they defend their staff, accept fault, and demonstratively improve process?

Re: Ask HN: What is in C-00000291*.sys?

#46
post #36

https://cyberplace.social/@GossiTheDog/112812260542179660 > I've obtained copies of the .sys driver files Crowdstrike customers have. They're garbage. Each customer appears to have a different one. https://cyberplace.social/@GossiTheDog/112812454405913406 > The .sys files causing the issue are channel update files, they cause the top level CS driver to crash as they're invalidly formatted. It's unclear how/why Crowds…

They might just be encrypted with a customer-specific key. That wouldn't surprise me.

They weren't last time I looked. They seem to contain a bunch of different things, but you can absolutely download and parse them without needing to decrypt anything.

If you have a Crowdstrike customer ID (CID) — which you can pull from any device that has the implant — you can request any channel file you want from their file server.

Ask for metahash+/cfs/channelfiles/0000000291//C-00000291-00000000-00000001.sys and you should get something that starts with:

    00000000: aaaa aaaa 0100 2301 0000 0500 0000 0000  ......#.........
    00000010: 0100 0000 4808 0000 2c08 0000 0600 0004  ....H...,.......
That's a channel file, unencrypted.

Re: Ask HN: What is in C-00000291*.sys?

#48
post #43
post #27

Earlier quoted context omitted.

the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks

It’s both. If you’re an engineer and you push out shitty code that takes down 911 systems and ambulances, you f’ed up. Push back against processes that cause harm, or have the potential to cause harm. You are ultimately responsible for your actions. No one else. The excuse of “I was just following orders” has been dead and buried since WW2. Yeah, ideally management should know better. But management aren’t usually en…

if one of the people i manage is not up to the task the fault is mine. I've hired them. I should setup a system of hard gained trust and automation to avoid or at least minimize them fucking up. When fuckups happen, they are my fuckups. Critical systems don't survive only on trust, obviously. If I don't setup the teams and the systems properly, my bosses will also take the blame for having put me in that position. I'm not advocating for lower layers to avoid responsabilities. But if an head needs to roll you should look above. That said, peole are hardened by fuckups, so there are better solutions than rolling heads, usually.

Re: Ask HN: What is in C-00000291*.sys?

#49

Earlier quoted context omitted.

Crowdstrike is finished? Ha! SolarWinds got the US government hacked by the Russians and they still exist.

Interestingly SolarWinds is headquartered in Austin and CrowdStrike recently moved there too.

Why is that interesting?
Post reply on HN