Earlier quoted context omitted.
> Architects likely do not have a choice. Architects don't have a choice, CTO are well paid to golf with the CEO and delegate to their teams, Auditors just audit but are not involved with the technical implementations, Developers just develop according to the Spec, and Security team just are a pain in the ass. Nobody owns it... Everybody get's well paid, and at the end we have to get lessons learned...It's a s*&^&t s…
Seems like everyone thinks that Execs play golf with another Execs to seal the deal regardless how b0rken the system is. That CTO's job is on the line if the system can't meet the requirement, more so if the system is fucked. To think that every CTO is dumbass is like saying "everyone is stupid, except me, of course"
Preliminary Post Incident Review
101–110 of 227 posts
Re: Preliminary Post Incident Review
#102Earlier quoted context omitted.
> Architects likely do not have a choice. Architects don't have a choice, CTO are well paid to golf with the CEO and delegate to their teams, Auditors just audit but are not involved with the technical implementations, Developers just develop according to the Spec, and Security team just are a pain in the ass. Nobody owns it... Everybody get's well paid, and at the end we have to get lessons learned...It's a s*&^&t s…
Some industries are forced by regulation or liability to have something like crowdstrike deployed on their systems. And crowdstrike doesn't have a lot of alternatives that tick as many checkboxes and are as widely recognized.
Re: Preliminary Post Incident Review
#103Earlier quoted context omitted.
> After internal QA, you release to small internal dev team, then to select members of other depts willing to dog-food it, then limited external partners then GA What about AV definition update for 0day swimming in the tubes right now?
Sure, those have happened before, but nothing with an impact like last weekend. That's inexcusable. At least definitions can update themselves out of trouble.
Isn't that what happened? Not a software update, not an AV-definition update but more so an AV-definition "data" update. At least that's how I interpret "Rapid Response Content"
Re: Preliminary Post Incident Review
#104There’s only one sentence that matters: "Provide customers with greater control over the delivery of Rapid Response Content updates by allowing granular selection of when and where these updates are deployed." This is where they admit that: 1. They deployed changes to their software directly to customer production machines; 2. They didn’t allow their clients any opportunity to test those changes before they took effe…
Unfortunately, putting the onus on risk adverse organizations like hospitals and governments to validate the AV changes means they just won't get pushed and will be chronically exposed. That said, maybe Crowdstrike should considering validating every step of the delivery pipeline before pushing to customers.
I have a similar feeling.
At the very least perhaps have an "A" and a "B" update channel, where "B" is x hours behind A. This way if, in an HA configuration, one side goes down there's time to deal with it while your B-side is still up.
Re: Preliminary Post Incident Review
#105> How Do We Prevent This From Happening Again? > Software Resiliency and Testing > * Improve Rapid Response Content testing by using testing types such as: > * Local developer testing So no one actually tested the changes before deploying?!
And why is it "local developer testing" and not CI/CD. This makes them look like absolute amateurs.
Claw back executive pay, stock, and bonuses imo and you'll see funded QA and CI teams.
Re: Preliminary Post Incident Review
#106Re: Preliminary Post Incident Review
#107Earlier quoted context omitted.
How do we know it hasn't?
If it happened, the industry would have known by now. The group behind it will come out to the public.
Re: Preliminary Post Incident Review
#108There’s only one sentence that matters: "Provide customers with greater control over the delivery of Rapid Response Content updates by allowing granular selection of when and where these updates are deployed." This is where they admit that: 1. They deployed changes to their software directly to customer production machines; 2. They didn’t allow their clients any opportunity to test those changes before they took effe…
Is it really all that surprising? This is basically their business model - its a fancy virus scanner that is supposed to instantly respond to threats.
Re: Preliminary Post Incident Review
#109Earlier quoted context omitted.
* Further testing of the file was skipped because of "trust in the checks performed in the Content Validator" and successful tests of previous versions that's crazy. How costly can it be to test the file fully in a CI job? I fail to see how this wasn't implemented already.
> How costly can it be to test the file fully in a CI job? It didn't need a CI job. It just needed one person to actually boot and run a Windows instance with the Crowdstrike software installed: a smoke test. TFA is mostly an irrelevent discourse on the product architecture, stuffed with proprietary Crowdstrike jargon, with about a couple of paragraphs dedicated to the actual problem; and they don't mention the non-e…
Re: Preliminary Post Incident Review
#1101) Everything went mostly well 2) The things that did not fail went so great 3) Many many machines did not fail 4) macOS and Linux unaffected 5) Small lil bug in the content verifier 6) Please enjoy this $10 gift card 7) Every windows machine on earth bsod'd but many things worked
Source: work in a Windows shop and had a normal day.