Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

11–20 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#11
Working as a developer inside large enterprise is increasingly intolerable by the day, made possible by tools such as crowdstrike falcon. By the time your workstation is saddled with endpoint security, DLP, zero trust networking, antivirus, etc. it barely functions. And you can get in trouble for doing anything. Installing tree from homebrew can get you flagged on some naughty list where you have to justify why you needed tree of all things.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#12
post #4

This all seems a bit silly, and could easily be attributed to a communication issue. On CrowdStrike's end, it's much more likely that their systems changed a few heuristics so now it flags certain msiexecs as malicious. Most anti-virus type software are highly nondeterministic in the way they operate, with tiny changes in detection engines able to cause large changes in the way some threats are detected. Even modzero…

> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sur…

possibly the origin of named and marketed vulnerabilities.

Heartbleed is older (2014).

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#16
post #10
post #2

That doesn't give me the impression of a company focussed on security. That they marked the installer of the PoC as "malicious" shows they do have a process, but don't take it seriously.

It’s the snake oil industry. They don’t sell security, they sell CISO get out of jail cards in the form of client agents that constantly remind you of their divine presence by being on top of the CPU utilization sorted process list.

There is a LOT of snake oil in the industry, but endpoint protection IS useful. Not every person is a Hacker News reading tech enthusiast. People download and do dumb shit. That is not to say every device needs it and at a max “check every process/file activity” level, though.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#17

Working as a developer inside large enterprise is increasingly intolerable by the day, made possible by tools such as crowdstrike falcon. By the time your workstation is saddled with endpoint security, DLP, zero trust networking, antivirus, etc. it barely functions. And you can get in trouble for doing anything. Installing tree from homebrew can get you flagged on some naughty list where you have to justify why you n…

Exactly. For competent developer, such tool is nothing but wasting time. The reason is simple: if they don't know what they are doing or cannot be trusted, they shouldn't be hired in the first place.

But I do understand why those are in place:

1. There are lots of those who have no idea what they are doing in the organization. And/or

2. Some high up who have no idea what they are doing want to show their value. Such move typically happens after someone with Chief Security Officer or similar get hired. Or they do know but simply don't care.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#18
post #10

Earlier quoted context omitted.

It’s the snake oil industry. They don’t sell security, they sell CISO get out of jail cards in the form of client agents that constantly remind you of their divine presence by being on top of the CPU utilization sorted process list.

There is a LOT of snake oil in the industry, but endpoint protection IS useful. Not every person is a Hacker News reading tech enthusiast. People download and do dumb shit. That is not to say every device needs it and at a max “check every process/file activity” level, though.

10% of Falcon is blocking dumb shit people do. 90% is blocking things people are supposed to be doing, and have been doing successfully so far.

Nothing starts your week better than "After the latest definitions update, Falcon heuristic started quarantining your core business tools as suspicious".

Post reply on HN