Live data from Hacker News

Crowdstrike: What % of sys admins can remotely boot to safe mode, given BSOD?

news.ycombinator.com

1–10 of 13 posts

Re: Crowdstrike: What % of sys admins can remotely boot to safe mode, given BSOD?

#4

I suspect that deploying a new image via PXE will be the fastest resolution. Ideally one you just built without crowdstrike. If you have important data trapped in userspace, print out some bitlocker keys and get in the car lmao.

I'm not a Windows user anymore but have seen references to bitlocker. For any others curious its disk encryption, so users with it cannot apply the fix because booting into safe mode to delete a file requires unlocking the disk encryption. I'd imagine safe mode doesn't have networking? That doesn't sound too safe so yeah this is an IT nightmare logistics issue for remote workers with encrypted drives.

Re: Crowdstrike: What % of sys admins can remotely boot to safe mode, given BSOD?

#6

I suspect that deploying a new image via PXE will be the fastest resolution. Ideally one you just built without crowdstrike. If you have important data trapped in userspace, print out some bitlocker keys and get in the car lmao.

Wait, does this mean if all your machines had Windows and Crowdstike installed, and you had no backups off site, all your data would essentially be wiped out?

Re: Crowdstrike: What % of sys admins can remotely boot to safe mode, given BSOD?

#7
post #3

For any remote workers - send laptop to HQ and get it back a few days/weeks later. IT Support depts are going to be overwhelmed.

My ex company just moved all IT to India. Good job.

So what you are saying ... Karma struck ... could be weeks...

I was thinking I could go around to companies doing their updates, for a fee of course. Waste a weekend, but make a bunch o money. But then it struck, how will I find the customers as their computers are down ...

Re: Crowdstrike: What % of sys admins can remotely boot to safe mode, given BSOD?

#8

I suspect that deploying a new image via PXE will be the fastest resolution. Ideally one you just built without crowdstrike. If you have important data trapped in userspace, print out some bitlocker keys and get in the car lmao.

Wait, does this mean if all your machines had Windows and Crowdstike installed, and you had no backups off site, all your data would essentially be wiped out?

[dead]

Re: Crowdstrike: What % of sys admins can remotely boot to safe mode, given BSOD?

#9
Oh, below 20%, I'd wager. The kinds of sysadmin skills people used to have that would allow that to happen (PXE, serial over LAN, etc) have atrophied quite a bit in the last ~decade. Maybe around 20% if you limit it to people whose titles actually are "System Administrator" (which implies an older, steady-as-she-goes IT dept) instead of e.g. also lumping in DevOps or SRE or cloud people.

But probably above 1%, given that it's a serious enough tail risk that you might keep an old geezer around who remembers how to do it just in case something mission critical happens.

Re: Crowdstrike: What % of sys admins can remotely boot to safe mode, given BSOD?

#10

I suspect that deploying a new image via PXE will be the fastest resolution. Ideally one you just built without crowdstrike. If you have important data trapped in userspace, print out some bitlocker keys and get in the car lmao.

I'm not a Windows user anymore but have seen references to bitlocker. For any others curious its disk encryption, so users with it cannot apply the fix because booting into safe mode to delete a file requires unlocking the disk encryption. I'd imagine safe mode doesn't have networking? That doesn't sound too safe so yeah this is an IT nightmare logistics issue for remote workers with encrypted drives.

Microsoft added 'safe mode with networking' a long time ago.
Post reply on HN