Live data from Hacker News

Microsoft's global sprawl under fire from regulators after Windows outage

washingtonpost.com

11–20 of 104 posts

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#11
post #8
post #6

It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?

is not it the case that kernel drivers are signed and approved by microsoft?

Would the disaster have been prevented if there was no code signing? Or are you arguing that Microsoft should scrutinize code even harder?

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#12
post #9

Do some of these news agencies own Crowdstrike stock? How can you blame Windows here? For simply allowing an application that can crash the OS? I truly don't understand the angle here, besides ignorance.

not only allowing, but approving? they signed driver, right? linux also allows, by approval is decentralized

Based on a simular comment you've made, I think there is some confusion for you as to what driver signing actually is. It's a certificate of Authority to identify the Distributer of the driver as legitimate or not.

Indeed, this messup was signed, so correctly it was signed. As for the code/behaviour. It's nothing to do with signing.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#13
post #9

Do some of these news agencies own Crowdstrike stock? How can you blame Windows here? For simply allowing an application that can crash the OS? I truly don't understand the angle here, besides ignorance.

not only allowing, but approving? they signed driver, right? linux also allows, by approval is decentralized

>by approval is decentralized

Translation: it's up to whoever is the sysadmin is, which probably was responsible for crowdstrike being installed in the first place. Such "approval" would have made no difference in preventing this disaster.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#14

Do some of these news agencies own Crowdstrike stock? How can you blame Windows here? For simply allowing an application that can crash the OS? I truly don't understand the angle here, besides ignorance.

[flagged]

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#15

It was inevitable that something like this would happen sooner or later, either through security complacency or sheer bad luck. We were just fortunate it only happened to Windows.

I'm of two minds on this one personally. I see simular `single points of failure` potentials with CloudFlare for example. Sometimes it highlights this topic. But at the same time, I really do feel more comfortable with a large experienced company being responsible for some of that infrastructure that is expensive to maintain correctly..

I don't know what the solution is, but it's something that needs to be figured out.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#16
post #3

>In a blog post Saturday, Microsoft estimated that the update affected 8.5 million devices, which amounts to less than 1 percent of computers running Windows Cute, but the 1% were the systems that matter most, who cares if people could still watch LOL Cat Videos at home. No one I know who works at a company using a Windows system was unaffected. Actually wrong, 1 person was fine, he got a brand new PC the day before,…

That's probably a very low estimate. Many hospitals and government agencies were virtually crippled.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#18
post #11
post #8

Earlier quoted context omitted.

is not it the case that kernel drivers are signed and approved by microsoft?

Would the disaster have been prevented if there was no code signing? Or are you arguing that Microsoft should scrutinize code even harder?

Microsoft isn’t scrutinizing this code, at all, right? It’s not like they’re doing code reviews of every vendor that does code signing in Windows.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#19
post #8
post #6

It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?

is not it the case that kernel drivers are signed and approved by microsoft?

You are confusing notarized (what Apple does) and signed (what both do). The latter just allows to confirm legitimacy.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#20
post #18
post #11

Earlier quoted context omitted.

Would the disaster have been prevented if there was no code signing? Or are you arguing that Microsoft should scrutinize code even harder?

Microsoft isn’t scrutinizing this code, at all, right? It’s not like they’re doing code reviews of every vendor that does code signing in Windows.

Not code reviews but the driver is tested

https://en.wikipedia.org/wiki/WHQL_Testing

Post reply on HN