Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

71–80 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#71
post #19

Somehow I feel those security companies are the source of the security problems.

Well in this case the vulnerability is the ability to uninstall the program when you're not supposed to be able to uninstall it.

So yes, if the program didn't exist at all, there would be no way to uninstall it in an unauthorized manor. So the vulnerability wouldn't exist. You wouldn't necessarily be any more secure though.

If you have 10 layers of security and 5 have holes in them, you have 5 vulnerabilities, but you're reasonably secure. If you have 0 layers of security and thus 0 holes in them, you might arguably say you have 0 vulnerabilities, but you would be less secure than the 5 vulnerability system. In the early days of computing you would log in with your username only, no password. Their threat model didn't consider intentional attacks, thus there were no vulnerabilities, but anyone could use anyone else's account.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#72
> The PoC that has been sent to CrowdStrike was flagged as malicious. The msiexec call of the deinstaller was also flagged as malicious.

As someone who was once part of an endpoint security team, I wouldn't be so quick to judge.

If CrowdStrike operates like any anti-virus software company, there are multiple teams. There would be a small engine team, a team that deals with Windows integration, then there would be a much much bigger malware analyst team(s), then another team that deals with 'active machine learning' (CrowdStrike's bread and butter). Then some senior managers oversee them all.

It's possible that the engine team and the analyst team have a case of 'left hand doesn't know what the right hand is doing.' They both got the report, and they behave differently as the engine team has a different goal from the analyst's team.

From the analyst team's point of view, their job is to detect all potentially malicious threat, sources be damned. While the engine team takes their sweet time, the analyst team just figures "hey this binary attacks our software. We don't know if the engine team would have fix the bug then, or if the bug is even real. We should blacklist it just-in-case or else when the binary in the public, some joker with an auto scanner will use this binary to show they got around our detection. Then our team would get blame for it. Better be safe than sorry."

Yes we all know detecting binary PoC are close to useless, but if you don't do it, then you'd get a flood of (useless) reports later...

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#73

> The PoC that has been sent to CrowdStrike was flagged as malicious. The msiexec call of the deinstaller was also flagged as malicious. As someone who was once part of an endpoint security team, I wouldn't be so quick to judge. If CrowdStrike operates like any anti-virus software company, there are multiple teams. There would be a small engine team, a team that deals with Windows integration, then there would be a m…

This doesn't really address the part where they then said the issue doesn't exist.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#74
post #73

> The PoC that has been sent to CrowdStrike was flagged as malicious. The msiexec call of the deinstaller was also flagged as malicious. As someone who was once part of an endpoint security team, I wouldn't be so quick to judge. If CrowdStrike operates like any anti-virus software company, there are multiple teams. There would be a small engine team, a team that deals with Windows integration, then there would be a m…

This doesn't really address the part where they then said the issue doesn't exist.

I am not defending CrowdStrike here (my work laptop, that I am typing this on, is molasse-like thanks to them), but their PSIRT team (they have one right?) is just another team in the corp machinery. What PSIRT team and the engine team decide to respond have no effect on what the analyst team decides to do.

Do no harm and cover your ass. No one is going to complain a false positive on a custom PoC binary....right?

Everything else, yeah those are pretty shitty.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#75

Earlier quoted context omitted.

The GrayZone has been impeccable in their reporting, with any errors quickly being admitted and disclosed. Of course many people disagree with them, and love to try character assassination and other ad hominems, but I've found them informative and having integrity. Maybe you should elaborate your reasoning. To elaborate further: "Leaked emails reveal British journalist Paul Mason plotting with an intel contractor to…

Paul Mason isn't a journalist. He was a journalist, then he left and swerved hard left into Momentum. He's previously been members of groups best described as Marxist or at least radical left.

He's a spy.

edit: cleared by MI5 just like every other BBC journalist in Britain, but moreso, seeing as he was the economics editor for BBC Newsnight, then for Channel 4 News.

https://www.cambridgeclarion.org/press_cuttings/mi5.bbc.staf...

https://www.cambridgeclarion.org/press_cuttings/mi5.bbc.page...

https://www.bbc.com/news/stories-43754737

edit: to be clear, when I say he's a spy, I mean that he is being paid by British intelligence to report on the operations of left wing organizations, sabotage them, push them into doing extreme and unpopular things which also hopefully constitute grounds for arresting targeted individuals, and to say obnoxious things that piss normies off as a representative of "the left" in mainstream media.

edit: allegedly.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#77
post #44

This seems extremely tame by vulnerability disclosure fuckup standards.

Seriously. I don't think the researcher realizes how many people try to bypass hackerone because H1 would have flagged their finding as invalid.

Using h1 isn't about bug bounties, it's about not having to spend a 1-2 of your team's full time engineers triaging security researcher reports.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#80
post #73

Earlier quoted context omitted.

This doesn't really address the part where they then said the issue doesn't exist.

I am not defending CrowdStrike here (my work laptop, that I am typing this on, is molasse-like thanks to them), but their PSIRT team (they have one right?) is just another team in the corp machinery. What PSIRT team and the engine team decide to respond have no effect on what the analyst team decides to do. Do no harm and cover your ass. No one is going to complain a false positive on a custom PoC binary....right? Ev…

you're dancing around the issue though, which is crowdstrike lying in saying there's no vulnerability when they clearly tested it and found there was one
Post reply on HN