Live data from Hacker News

Microsoft's global sprawl under fire from regulators after Windows outage

washingtonpost.com

51–60 of 104 posts

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#51
post #41
post #6

It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?

Is it baffling? Only windows computers were affected, so this provides ammunition for people who are already concerned about the prevalence of windows. I think this is more politically motivated than actually trying to address the real problem. However I do, think Microsoft deserves some blame, since if Windows was more secure by default there would be less need for 3rd party anti-malware software that can fail so ca…

>However I do, think Microsoft deserves some blame, since if Windows was more secure by default there would be less need for 3rd party anti-malware software that can fail so catastrophically.

There's actually a first-party product: https://learn.microsoft.com/en-us/defender-xdr/microsoft-365...

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#53
post #21
post #13

Earlier quoted context omitted.

>by approval is decentralized Translation: it's up to whoever is the sysadmin is, which probably was responsible for crowdstrike being installed in the first place. Such "approval" would have made no difference in preventing this disaster.

how 8.5M devices got approval to install? may they came with hard to disable windows autoupdate?

[deleted]

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#54
post #6

It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?

There is a frustrating amount of nuance being lost in this discussion, and as usual it's devolving into tribalism.

However, I'll say that, while this clearly is not Microsoft's fault, the realization of just how much critical infrastructure is running on Windows -- let alone Windows that's connected to the internet and has automatic updates enabled -- was sobering.

Are kernel mode drives maybe a bad idea? Yes! Should Windows be able to automatically roll back if a kernel mode driver fails? Yes! Should CrowdStrike have tested before pushing out the update? Yes! Should hospitals, police stations, airlines, etc be testing any and all updates that come their way prior to releasing them onto the rest of their fleets? Yes!

And so on and so on. The failures here are legion. I can at least say for myself that all of that (and more) is what I'm grappling with today, rather than the direct, root cause and content of the issue itself.

I say this entirely with as little tribalism or bias as I can muster: Windows should not be the foundation upon which critical infrastructure is built. It is a bad OS. It is a rickety, insecure mess; this observation (note that I did not say opinion) has only ever increased with time.

The NT kernel, I hear, is great. I generally trust those who say this, as they tend to be demonstrably much smarter than I am, especially with regards to kernel design, which is something I know next to nothing about.

But Windows? Nah man. Maybe there's a good kernel running the show, but the OS as a whole is a shitshow. Yes, this exact same problem could have (and has) happened on Linux; the OS is indeed not the culprit. But the understanding that this one, single, no good very bad OS is responsible for this much critical infrastructure going from an abstract worry to a real, concrete horror show has, I think, hit a lot of people, leading to a poorly-pivoted change of subject.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#55
post #6

It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?

Besides cloud outages, there's also been quite a few security disasters recently, one with the Russians all up in Uncle Sam's business.

There's no reason for MS to have such a lock on governments, when their security and reliability is worst in the industry among BigTech. Even "Blue Hat" could do better.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#56
post #6

It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?

Microsoft are signing kernel drivers for over-the-air updates pushed by vendors. Whilst telling their corporate customers that using Microsoft InTune will allow them to be in full control of their configuration management.

>Microsoft are signing kernel drivers for over-the-air updates pushed by vendors.

The crash was caused by a configuration update pushed by crowdstrike, not a new driver.

>Whilst telling their corporate customers that using Microsoft InTune will allow them to be in full control of their configuration management.

How is this relevant? This wasn't caused by some sysadmin that goofed a config change using intune, it's something pushed by crowdstrike itself.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#57
post #31

I’m not a regulator, but I think the solution may actually be to break up Microsoft. Right now, there is a product that is critical to the economy: Windows. By “Windows” I mean the OS, its security mechanisms, and its update mechanisms. Changing Windows to a multi-source model seems challenging, to say the least. Right now, though, Windows is not merely single-source, but that single source also makes OneDrive, Offic…

[deleted]

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#58
post #56

Earlier quoted context omitted.

Microsoft are signing kernel drivers for over-the-air updates pushed by vendors. Whilst telling their corporate customers that using Microsoft InTune will allow them to be in full control of their configuration management.

>Microsoft are signing kernel drivers for over-the-air updates pushed by vendors. The crash was caused by a configuration update pushed by crowdstrike, not a new driver. >Whilst telling their corporate customers that using Microsoft InTune will allow them to be in full control of their configuration management. How is this relevant? This wasn't caused by some sysadmin that goofed a config change using intune, it's so…

> The crash was caused by a configuration update pushed by crowdstrike, not a new driver.

Microsoft didn’t do enough due diligence on the behaviour of CrowdStrike updates. It shouldn’t allow out-of-band updates.

Third-parties should not be signing code that allows third-parties to reach into corporate services and push files.

Microsoft InTune is the mechanism that all configuration updates should use.

It appears to me that Microsoft makes it harder for third-parties to update an Xbox game, than the configuration of a kernel driver.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#59
post #31

I’m not a regulator, but I think the solution may actually be to break up Microsoft. Right now, there is a product that is critical to the economy: Windows. By “Windows” I mean the OS, its security mechanisms, and its update mechanisms. Changing Windows to a multi-source model seems challenging, to say the least. Right now, though, Windows is not merely single-source, but that single source also makes OneDrive, Offic…

This is the narrative that Crowdstrike wants the public to believe. Crowdstrike did the same thing to Debian machines running their software previously. The use of these kernel-level security software packages with arguably negligible benefit compared to the experienced risks could instead be reassessed.

Re: Microsoft's global sprawl under fire from regulators after Windows outage

#60
post #54
post #6

It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?

There is a frustrating amount of nuance being lost in this discussion, and as usual it's devolving into tribalism. However, I'll say that, while this clearly is not Microsoft's fault, the realization of just how much critical infrastructure is running on Windows -- let alone Windows that's connected to the internet and has automatic updates enabled -- was sobering. Are kernel mode drives maybe a bad idea? Yes! Should…

>There is a frustrating amount of nuance being lost in this discussion, and as usual it's devolving into tribalism.

It's ironic that you're saying this given the points you're making below. Let's go through them:

>Are kernel mode drives maybe a bad idea? Yes!

You can't have a EDR product that isn't kernel mode. Otherwise it's trivial for malware to evade (eg. by being kernel mode themselves).

>Should Windows be able to automatically roll back if a kernel mode driver fails? Yes!

see: https://news.ycombinator.com/item?id=41019743

>Should hospitals, police stations, airlines, etc be testing any and all updates that come their way prior to releasing them onto the rest of their fleets? Yes!

Getting companies to test updates is already like pulling teeth. Besides, crowdstrike said the update they pushed was "designed to target newly observed, malicious named pipes being used by common C2 frameworks in cyberattacks". Is this something you really want to sit on for testing, which might take weeks or months?

>Windows should not be the foundation upon which critical infrastructure is built. It is a bad OS. It is a rickety, insecure mess; this observation (note that I did not say opinion) has only ever increased with time.

>The NT kernel, I hear, is great. I generally trust those who say this, as they tend to be demonstrably much smarter than I am, especially with regards to kernel design, which is something I know next to nothing about.

>But Windows? Nah man. Maybe there's a good kernel running the show, but the OS as a whole is a shitshow.

What specific security issues do you think windows/NT kernel has? Moreover, how is windows being a "shitshow" relevant to the question of resiliency or dependence? Don't get me wrong, windows spying on you or using dark patterns to get you to use Edge or whatever isn't great, but it's a weird thing to bring up in a discussion about how airports run on windows, and reeks of "don't let a disaster go to waste" on the part of the anti-windows tribe.

Post reply on HN