Live data from Hacker News

Ask HN: What is in C-00000291*.sys?

news.ycombinator.com

91–100 of 104 posts

Re: Ask HN: What is in C-00000291*.sys?

#91

Wouldn't want to be the guy who pushed this particular commit. It's ironic that the company that is supposed to prevent this sort of thing causes the biggest worldwide outage ever. Crowdstrike is finished. Let's hope this will result in at least a small increase in desktop Linux market share.

> Crowdstrike is finished.

We thought about Microsoft the same way, some 15 years ago. /s

Re: Ask HN: What is in C-00000291*.sys?

#92
post #43
post #27

Earlier quoted context omitted.

the management that enabled the process. And follow the chain to the top, they are paid very well to own the risks

It’s both. If you’re an engineer and you push out shitty code that takes down 911 systems and ambulances, you f’ed up. Push back against processes that cause harm, or have the potential to cause harm. You are ultimately responsible for your actions. No one else. The excuse of “I was just following orders” has been dead and buried since WW2. Yeah, ideally management should know better. But management aren’t usually en…

> The excuse of “I was just following orders” has been dead and buried since WW2.

Only for the loosers.

Re: Ask HN: What is in C-00000291*.sys?

#93

Earlier quoted context omitted.

Why the fuck didn't MSFT just do blue/green canarying? No update should be rolled out to a billion devices at once until it's baked in a million devices for a bit, and that only after baking in 10,000 devices for a bit.

CrowdStrike is not MSFT. This also affected Linux installations with CrowdStrike installed, from what I've read.

Source? I have not seen any thing about that and CS themselves say it's Windows only.

Re: Ask HN: What is in C-00000291*.sys?

#96
post #75
post #38

Earlier quoted context omitted.

It's not an anti-virus, it's intended to monitor all and everything on the machine. You^WAn attacker might want to hide what you're doing and thus it runs at that level.

You may be right but they do market it as "Next-Generation Antivirus (NGAV)"/"Antivirus with Threat Intelligence" probably because it's a word people are familiar with [CrowdStrike Falcon® Pro: Antivirus with Threat Intelligence]( https://www.crowdstrike.com/products/bundles/falcon-pro/ )

I understand that these "NGAV" must be in ring 0 (device driver) because they want to inspect more things directly. And be more protected there, avoiding being attacked. I'm not sure they can achieve this.

Re: Ask HN: What is in C-00000291*.sys?

#97
post #44

Earlier quoted context omitted.

More importantly, the companies that enabled auto update from a vendor to production rather than having a validation process. This sort of issue can happen with any vendor, penalising the vendor won't help with the next time this happens.

Was there a way to not enable these channel updates? If so, would you still check all the mandatory security measures when being audited?

The way is to not install third party software with kernel level access that you can't stop pulling remote updates.

How does that pass a security audit in the first place?

Re: Ask HN: What is in C-00000291*.sys?

#98
post #48
post #43

Earlier quoted context omitted.

It’s both. If you’re an engineer and you push out shitty code that takes down 911 systems and ambulances, you f’ed up. Push back against processes that cause harm, or have the potential to cause harm. You are ultimately responsible for your actions. No one else. The excuse of “I was just following orders” has been dead and buried since WW2. Yeah, ideally management should know better. But management aren’t usually en…

if one of the people i manage is not up to the task the fault is mine. I've hired them. I should setup a system of hard gained trust and automation to avoid or at least minimize them fucking up. When fuckups happen, they are my fuckups. Critical systems don't survive only on trust, obviously. If I don't setup the teams and the systems properly, my bosses will also take the blame for having put me in that position. I'…

Right. In one sense, what we're talking about is different ideas on how companies / teams work. There's a wonderful book called "Reinventing Organizations" by Laloux that I recommend to basically everyone. In the book, the authors lay out a series of different organisational structures which have been invented and used throughout the ages. The book talks about early tribes where the big man tells everyone what to do (eg mobsters), to rigid hierarchies + fixed roles (the church, schools) to modern corporations with a flexible hierarchy, and some organisation structures beyond that.

The question of "who is ultimately responsible" changes based on how we see the organisation. In organisations where the chief decides everything, its up to the chief to decide if they should place blame on someone or not. In a modern corporation, people at the bottom of the hierarchy are shielded from the consequences of their actions by the corporation. But there's also a weird form of infantilisation that goes along with that. We don't actually trust people on the ground to take responsibility for the work they do. All responsibility goes up the management hierarchy, along with control, power and pay. Its sort of assumed that people who haven't been promoted are too incompetent to make important choices.

I don't think thats the final form of how high functioning teams should work. Its noble that you're willing to put your head on the chopping block, but I think its also really important to give maximal agency to your employees. And that includes making people feel responsible and empowered to fix problems when they see them. You get more out of people by treating them like adults, not children. And they learn more, and I think that's usually, in the long run, better for everyone.

I agree that if a company has a bad process, employees shouldn't be fired over it. But I also think if you're an employee in a company with a bad process, you should fight to make the process better. Never let yourself be complicit in a mistake like this.

Re: Ask HN: What is in C-00000291*.sys?

#99
post #93

Earlier quoted context omitted.

CrowdStrike is not MSFT. This also affected Linux installations with CrowdStrike installed, from what I've read.

Source? I have not seen any thing about that and CS themselves say it's Windows only.

Crowdstrike broke the update for Windows only this time. Although look around, they did a bad update on Linux earlier this year (although that only broke some of the Linux installs).
Post reply on HN