One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…
CrowdStrike to Delta: Stop pointing at us
51–60 of 76 posts
Re: CrowdStrike to Delta: Stop pointing at us
#52I'm not familiar with how CrowdStrike updates typically roll out, are they not phased?
Re: CrowdStrike to Delta: Stop pointing at us
#53It sounds a lot like CrowdStrike is saying "Delta should have known better than to rely on our software for critical functions." Which may be a fair statement, but I think it's also fair to litigate whether or not this post-incident statement is consistent with how CrowdStrike sold their software to Delta.
Did CS claim that their software is infallible? Sales isn't shy to take liberties but this would surprise me.
Re: CrowdStrike to Delta: Stop pointing at us
#54One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…
Relevant to dave plummer: https://news.ycombinator.com/item?id=39813625 > Now, as to the tidbit. Dave Plummer ran a scam company that was sued by Washington State in 2006, "SoftwareOnline.com, Inc. ". He actually left Microsoft specifically to run this company. > Court documents can be seen here: https://www.atg.wa.gov/news/news-releases/attorney-general-s ... You can find David W. Plummer listed in the court complai…
Re: CrowdStrike to Delta: Stop pointing at us
#55Earlier quoted context omitted.
Crowdstrike is not handling critical infrastructure. Delta is. The reality is the industry wants its cake and eat it too. No one forced Delta to buy a software which could force upgrades in their production fleet. They're a billion dollars company, and should put their big boys pants on.
> No one forced Delta to buy a software which could force upgrades in their production fleet. Except this update was one from CrowdStrike that would ignore Delta's stated update policy. And they literally said "Oh, yeah, we can configure some updates to bypass your policy". I wonder how well this was communicated to those customers.
The update policy may work for the client version updates, but not for the "policy definition", otherwise delta won't get the sweet "all vulns mitigated with a 4h SLA" they crave.
Re: CrowdStrike to Delta: Stop pointing at us
#56Earlier quoted context omitted.
Did CS claim that their software is infallible? Sales isn't shy to take liberties but this would surprise me.
There's quite some distance between "infallible" and the kind of failure mode CS's error induced. Be that as it may, I don't think the question is about infallibility, though. The question is, was the software fit for the purpose Delta used it for? And the follow-on question is whether CrowdStrike sold it for the purpose Delta used it for.
Software fails, machines fail, we all know this. The technical leadership at Delta should know this. Do we think software vendors should be responsible for ensuring their customers safely deploy their software? I can't imagine that playing out well.
Re: CrowdStrike to Delta: Stop pointing at us
#57The Microsoft part of this I find interesting, I mean I guess it would be standard legal practice to also go after them even if it is thrown out. But that one is weird. Maybe Microsoft encouraged Delta to use Crowdstrike, then ok I could see the case. But if it is anything related to how Windows works, that seems like a stretch. Yes Windows could be better, but I don't like the idea that the OS provider could be sued…
> While I am sure that Delta's IT department was understaffed, this was also a unique situation. If you spent the time to make a well optimized machine for rolling out updates, things were automated, and you expected things to go wrong but I would have never anticipated every Windows machine being unable to boot. That is an extra-ordinary situation. I doubt any IT department is really staffed to be able to handle tha…
I think that is where this is going to get more complicated, I think that this has broadened what we traditionally think about when it comes to what we consider a single point of failure.
I would wager that most people would not have considered something like Crowdstrike to be a single point of failure. It is not what you would generally think of.
From what sounds of the bits and pieces of Delta that came out, it sounds like the biggest issue they had was that so many of these systems were not together. It required physical access to systems that were in many different locations (I would love to be corrected on this). Under normal circumstances that would cover you in the case of an outage in a particular location. If you built your system to handle entire areas going down, adding in redundancy.
But this was very much a unique situation. We really shouldn't pretend otherwise. It wasn't an external service going down, or AWS going down, loss of internet connection, or other things going down that we would normally account for in disaster recovery. Hell I would argue that in this particular situation, you could have the best disaster recovery but it wouldn't have done anything since Crowdstrike was probably baked into your images. So have fun bringing up an instance that was going to instantly brick. Yeah eventually that would have been a non issue, but I can not imagine a scenario that I would have ever thought that I had a baked image and assuming I still had access to it and I could assure that it was the image that I made, that it somehow would itself be a problem.
Before a couple weeks ago if we had built a system that was redundant enough to handle parts going down, different geographical locations, etc etc with, maybe things slow down but still works. All of the standard things that we talk about.
It isn't absurd to think that your entire system going down in a situation where you don't think you have a single point of failure, is nearly impossible or if it happens there is something outside of your company seriously bad.
Re: CrowdStrike to Delta: Stop pointing at us
#58One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…
Relevant to dave plummer: https://news.ycombinator.com/item?id=39813625 > Now, as to the tidbit. Dave Plummer ran a scam company that was sued by Washington State in 2006, "SoftwareOnline.com, Inc. ". He actually left Microsoft specifically to run this company. > Court documents can be seen here: https://www.atg.wa.gov/news/news-releases/attorney-general-s ... You can find David W. Plummer listed in the court complai…
That doesn't invalidate the parent comment tough
Re: CrowdStrike to Delta: Stop pointing at us
#59Earlier quoted context omitted.
Maybe as an operating system that Delta purchased, its kernel should not crash when a 3rd party software receives a faulty update?
I really dislike this line of thinking because it assumes that Microsoft is responsible for anything you run on your Windows machine. I should be able to do whatever I want with a computer I buy, but that doesn't mean Microsoft should hold any liability for it. What am I missing here?
Re: CrowdStrike to Delta: Stop pointing at us
#60Earlier quoted context omitted.
Relevant to dave plummer: https://news.ycombinator.com/item?id=39813625 > Now, as to the tidbit. Dave Plummer ran a scam company that was sued by Washington State in 2006, "SoftwareOnline.com, Inc. ". He actually left Microsoft specifically to run this company. > Court documents can be seen here: https://www.atg.wa.gov/news/news-releases/attorney-general-s ... You can find David W. Plummer listed in the court complai…
The term “ad hominem” gets casually thrown around quite a bit in these parts, but boy howdy this is the literal textbook case of it. Plummer’s not one of the good guys, noted. Is he factually wrong?