I'm still amazed how the blame shifted from Microsoft to CrowdStrike. Yes, CrowdStrike update caused that -- but applications fail all the time. It was Microsoft's oversight to put it on Windows critical path. And banks/airlines etc were hit hard because their _Windows_ didn't boot, not because of an application crash on a perfectly working Windows.
Why the CrowdStrike bug hit banks hard
111–120 of 250 posts
Re: Why the CrowdStrike bug hit banks hard
#112We blame car manufacturers for defects from suppliers, but we don't blame platform manufacturers (Microsoft) for holes in their architecture?
Re: Why the CrowdStrike bug hit banks hard
#113Earlier quoted context omitted.
Note: At least on Linux the main alternatives for this, either eBPF (e.g., pulsar or falcon) or a kernel module, both require this too.
eBPF is at least somewhat sandboxed, no? So it doesn't quite have the access required to accidentally stomp on any portion of kernel memory it wants?
Re: Why the CrowdStrike bug hit banks hard
#114Was anyone else surprised how little disruption they personally experienced? I had braced for impact that weekend. But all my flights were perfectly on time, all my banking worked, providers worked, and sites & resources were available. I don’t know if I somehow just have little exposure to Windows in my life or if there’s an untold resiliency story for the global internet in the face of such a massive outage. All I…
Vanguard.co.uk was down.
But yes, I echo your feelings. When you examine how complex everything is under the hood it's almost unbelievable that anything works.
Re: Why the CrowdStrike bug hit banks hard
#115I'm still amazed how the blame shifted from Microsoft to CrowdStrike. Yes, CrowdStrike update caused that -- but applications fail all the time. It was Microsoft's oversight to put it on Windows critical path. And banks/airlines etc were hit hard because their _Windows_ didn't boot, not because of an application crash on a perfectly working Windows.
Microsoft didn't write the Falcon sensor software nor did they put it in the kernel. In fact, Microsoft has been shouting to the heavens trying to shift the blame from CrowdStrike onto the European Commission, because they want people to irrationally hate antitrust so they can turn Windows into shitty iOS and monopolize the security market (and applications market) for it. Furthermore, Microsoft does actually have so…
One only needs to look at what's happening with Google's privacy sandbox to know the perils of antitrust with regard to introducing new interfaces. Even though Google has offered new interfaces and APIs that they themselves intend to migrate to (and take a ~20% revenue reduction), they've attracted the scrutiny of regulators who claim that this is a way of locking out competitors in the advertising space.
> [0] ancaps fite me
This part is simply inciting a flamewar, and something that you can do without in the spirit of the website guidelines[1].
Re: Why the CrowdStrike bug hit banks hard
#116Fictional statements like this make me reluctant to read further, and ignore source of such "news" in the future.
Re: Why the CrowdStrike bug hit banks hard
#117Earlier quoted context omitted.
The update bypassed the controls orgs had in place to defer/schedule updates, AFAIK.
I've had trouble nailing down if thats the case from searching around online. And if thats true - thats absolutely on Crowdstrike. And that behavior should disqualify it from being used on critical systems. I imagine this incident will cause a lot of teams to consider just what can happen automatically on their systems.
Re: Why the CrowdStrike bug hit banks hard
#118> Another way is if it has recently joined a botnet orchestrated from a geopolitical adversary of the United States after one of your junior programmers decided to install warez because the six figure annual salary was too little to fund their video game habit. Fictional statements like this make me reluctant to read further, and ignore source of such "news" in the future.
also, bragging about your inability to read text seems an odd way to interact.
Re: Why the CrowdStrike bug hit banks hard
#119Earlier quoted context omitted.
Couldn't you just ask some OS APIs provided by something in kernelspace for what you need? In fact, isn't this how macOS does things?
You could, and in fact this is what Microsoft wanted to do. The EU said that they couldn't. And the reason why not is simple. Anything that Microsoft thinks is a good thing to add to the API, they'll add for themselves. When the new API is released, their software is released with it. This gives them a competitive advantage over competitors who have to wait for Microsoft to have the idea that they want, and then scra…
Re: Why the CrowdStrike bug hit banks hard
#120> Another way is if it has recently joined a botnet orchestrated from a geopolitical adversary of the United States after one of your junior programmers decided to install warez because the six figure annual salary was too little to fund their video game habit. Fictional statements like this make me reluctant to read further, and ignore source of such "news" in the future.
what makes you think it was fictional? also, bragging about your inability to read text seems an odd way to interact.