Live data from Hacker News

CrowdStrike Update: Windows Bluescreen and Boot Loops

old.reddit.com

161–170 of 1001 posts

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#164

This gem from the ABC news coverage has my mind 100% boggled: "711 has been affected by the outage … went in to buy a sandwich and a coffee and they couldn’t even open the till. People who had filled up their cars were getting stuck in the shop because they couldn’t pay." Can't even take CASH payment without the computer, what a world!

Technically a payment terminal can go into island mode and take offline credit card transactions and post them later. PIN can be verified against the card.

Depends if the retailer wants to take the chance of all that.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#165

High time to stop using Microsoft Windows/Azure which is full of security tech debt, that you need all these tools which themselves brick the computer

If anyone feels like disagreeing about Azure, here's a comment of mine from a few months ago:

A random selection of serious security incidents from Azure:

just from Wiz from the past 2-3 years, and of course they aren't the only ones:

https://www.wiz.io/blog/secret-agent-exposes-azure-customers...

https://www.wiz.io/blog/storm-0558-compromised-microsoft-key...

https://www.wiz.io/blog/azure-active-directory-bing-misconfi...

https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-o...

https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-v...

Of course Microsoft AI researchers sucking at security: https://www.wiz.io/blog/38-terabytes-of-private-data-acciden...

Nice overview from Corey Quinn that predates some of those but things were already horrifically bad: https://www.lastweekinaws.com/blog/azures-terrible-security-...

Go and look for similar things for AWS and GCP, and there's nothing on this level (cross-tenant, trivial to exploit).

Oh and there's also this, them selling your usage patterns to partners (hopefully they've stopped): https://twitter.com/QuinnyPig/status/1359769481539506180

Oh and another one where they bungled the response: https://twitter.com/QuinnyPig/status/1536868170815795200

I find it impossible to believe that Azure as a whole organisation takes security seriously. There might be individuals that do, but definitely nobody with decision making power. Half of the above described exploits are trivial and should have never passed any sort of competent review process.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#169
post #117

Can someone explain what Crowdstrike actually is? Reading Wikipedia it seems to be some sort of anti-virus software?

It’s watching the system for events like “file was opened” and “process started”, and looking for patterns resembling hackers/malware.

It’s different from AV in that it mostly looks at runtime behavior and not signatures.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#170

I just skimmed through the news. A lot of airports, hospitals, and even governments are down! It's ironic how people are putting their eggs in one basket, trying to avoid downtime caused by malware by relying on a company that put their system down. A lot of lessons will be learned after this for sure.

Unless you run half your devices on one security vendor and half on another surely there is no way round it? Companies install this stuff over "Windows Defender" so they can point fingers at the security vendor when they get hacked, this is the other side of the coin.

It has happened before where security software has unwanted effects, can't say i remember anyone else managing to blue screen Windows and require a safe mode boot to fix the endpoints though.

Post reply on HN