Live data from Hacker News

Preliminary Post Incident Review

crowdstrike.com

11–20 of 227 posts

Re: Preliminary Post Incident Review

#12
post #3

This reads like a bunch of baloney to obscure the real problem. The only relevant part you need to see: >Due to a bug in the Content Validator, one of the two Template Instances passed validation despite containing problematic content data . Problematic content ? Yeah, this is telling exactly nothing. Their mitigation is "ummm we'll test more and maybe not roll the updates to everyone at once", without any direct exp…

> fixing whatever made it possible for "problematic content" to cause "ungraceful" crashes Better not only fix this specific bug but continuously use fuzzing to find more places where external data (including updates) can trigger a crash (or worse RCE)

That is indeed necessary.

But it seems to me that putting the interpreter in a place in the OS where it can cause a system crash with the be the behavior that it's allowed to do is a fundamental design choice that is not at all addressed by fuzzing.

Re: Preliminary Post Incident Review

#14
post #7
post #3

This reads like a bunch of baloney to obscure the real problem. The only relevant part you need to see: >Due to a bug in the Content Validator, one of the two Template Instances passed validation despite containing problematic content data . Problematic content ? Yeah, this is telling exactly nothing. Their mitigation is "ummm we'll test more and maybe not roll the updates to everyone at once", without any direct exp…

>Add additional validation checks to the Content Validator for Rapid Response Content. A new check is in process to guard against this type of problematic content from being deployed in the future. >Enhance existing error handling in the Content Interpreter. They did write that they intended to fix the bugs in both the validator and the interpreter. Though it's a big mystery to me and most of the comments on the topi…

What validates the Content Validator? A Content Validator Validator?

Re: Preliminary Post Incident Review

#15
Such a disingenuous review; waffle and distraction to hide the important bits (or rather bit: bug in content validator) behind a wall of text that few people are going to finish.

If this is how they are going to publish what happened, I don't have any hope that they've actually learned anything from this event.

> Throughout this PIR, we have used generalized terminology to describe the Falcon platform for improved readability

Translation: we've filled this PIR with technobable so that when you don't understand it you won't ask questions for fear of appearing slow.

Re: Preliminary Post Incident Review

#16
post #10
post #7

Earlier quoted context omitted.

>Add additional validation checks to the Content Validator for Rapid Response Content. A new check is in process to guard against this type of problematic content from being deployed in the future. >Enhance existing error handling in the Content Interpreter. They did write that they intended to fix the bugs in both the validator and the interpreter. Though it's a big mystery to me and most of the comments on the topi…

>They did write that they intended to fix the bugs I strongly disagree. Add additional validation and enhance error handling say as much as "add band-aids and improve health" in response to a broken arm. Which is not something you'd want to hear from a kindergarten that sends your kid back to you with shattered bones. Note that the things I said were missing are indeed missing in the "mitigation". In particular, addi…

> people were writing that ridiculous SLA's, such as "4 hour response to a vulnerability

I didn't see people explaining why this was ridiculous.

> make it practically impossible to release well-tested code

That falsely presumes the release must be code.

CrowdStrike say of the update that caused the crash: "This Rapid Response Content is stored in a proprietary binary file that contains configuration data. It is not code or a kernel driver."

Re: Preliminary Post Incident Review

#18
post #10
post #7

Earlier quoted context omitted.

>Add additional validation checks to the Content Validator for Rapid Response Content. A new check is in process to guard against this type of problematic content from being deployed in the future. >Enhance existing error handling in the Content Interpreter. They did write that they intended to fix the bugs in both the validator and the interpreter. Though it's a big mystery to me and most of the comments on the topi…

>They did write that they intended to fix the bugs I strongly disagree. Add additional validation and enhance error handling say as much as "add band-aids and improve health" in response to a broken arm. Which is not something you'd want to hear from a kindergarten that sends your kid back to you with shattered bones. Note that the things I said were missing are indeed missing in the "mitigation". In particular, addi…

It's not your kid, so "improve health" is the industry standard response here.
Post reply on HN