Live data from Hacker News

Why the CrowdStrike bug hit banks hard

bitsaboutmoney.com

131–140 of 250 posts

Re: Why the CrowdStrike bug hit banks hard

#131
post #77

Earlier quoted context omitted.

I've had trouble nailing down if thats the case from searching around online. And if thats true - thats absolutely on Crowdstrike. And that behavior should disqualify it from being used on critical systems. I imagine this incident will cause a lot of teams to consider just what can happen automatically on their systems.

[flagged]

How did 911 services go down then? Whatever system caused that, should be by definition critical, imho.

Re: Why the CrowdStrike bug hit banks hard

#132

Earlier quoted context omitted.

Should endpoint protection require kernel level access? At what point does it stop becoming protection and start becoming a liability? Obligatory who watches/protects the watchmen/protector...

If you don't do it, someone else will. Unless the OS is locked down to the point that even its owner cannot do that. Actually, this is something I like about Operational Technology, you run into a lot of doodads where the elevation process requires turning a physical key, and the device's main functionality is disabled while it is in service mode. Ofc the doodad has to be engineered to operate reliably, perpetually,…

I have said for 20 years now that Microsoft Word should have a check on startup, if the current user is administrator it should put up a message that administrators are not allowed to use a Word Process, login as someone else. This one change would solve a lot of problems.

Even on home machines where no user has a password, having to do something special to get into administrator mode will stop several attacks just because people will slow down and ask.

Re: Why the CrowdStrike bug hit banks hard

#133
post #92

Earlier quoted context omitted.

Management decides to use Crowdstrike, not IT, and IT has no way to rollout updates in controlled fashion. So not really a failure of IT, at least not for this reason.

My comment assumes that the IT department (including its executive) gets to make these sort decisions - why wouldn't they?

In many mature orgs, corporate IT rolls up to the CIO and security will roll up to the CISO

The CISO and security ops will demand to be completely independent from corp IT, for legit reasons, as the security team needs to treat IT as potential insider threat actors with elevated privileges.

They will also demand the ability to push out updates everywhere at any time in response to real-time threats, and per the previous point they will not coordinate or even announce these changes with IT.

There has always been an implicit conflict between security and usability, because of the inherent nature of security deny policies, but they also inherently conflict with conservative change management policies such as IT slow rolling changes through lower environments on fixed schedules and operating with transparency

Re: Why the CrowdStrike bug hit banks hard

#134

Earlier quoted context omitted.

The way I see it, Microsoft sells some antivirus software, and also gets to decide who is allowed or not to compete with their antivirus software, by providing or denying access to the API. Obviously unfair.

I think anti-virus should be part of the core os. This does kill all third party vendors - good riddance to most of them, sorry if there is one that isn't evil (I'm not aware of it)

Once the AV vendors exist, killing them, especially by Microsoft, is clearly anticompetitive.

If you could prevail on a government to decide that, maybe it could work.

One thing I see, is that AV has a component of maintaining a DB of signatures of bad things. This does not seem at all the job of the core os. Would the Debian team maintain such a DB?

Re: Why the CrowdStrike bug hit banks hard

#135
post #90

Earlier quoted context omitted.

In the short term people would probably starve to death.

Probably not. A competent government could install temporary rationing for the most essential goods such as food. It happened through the the whole of the 1917—1920 Russian revolution, with four or five kinds of paper money being circulated around, and the urban population managed through it only if barely. That government was much less competent than the US government is today.

I mean, millions still starved during the revolution, even with the American Relief Administration feeding 10% of the country.

Re: Why the CrowdStrike bug hit banks hard

#136
post #41

Earlier quoted context omitted.

Couldn't you just ask some OS APIs provided by something in kernelspace for what you need? In fact, isn't this how macOS does things?

Microsoft was on their way to doing this, but was shot down by EU regulators because the APIs weren't available to all third-party vendors.

I think it's kind of ridiculous to then blame the regulators for the fact that Microsoft decided not to go ahead with a more competitor-friendly design.

The fact that Microsoft abandoned it as soon as a regulator pointed out how anti-competitive the design of the API was makes you wonder what Microsoft's true intention was. To me that implies the anti-competitive design was its main feature and to Microsoft it would've been pointless to continue without it.

Re: Why the CrowdStrike bug hit banks hard

#137
post #28

Regulations are a big reason why this happened, sure, but also it hit the companies with great security budgets more. Hospitals, for instance, weren't that widely affected as they barely have any money to buy security tooling. Silver linings and all that, I guess.

> Hospitals Everybody seems to be quick to forget about WannaCry.

That really just proves my point.

Re: Why the CrowdStrike bug hit banks hard

#138
post #67
post #41

Earlier quoted context omitted.

Couldn't you just ask some OS APIs provided by something in kernelspace for what you need? In fact, isn't this how macOS does things?

You could, and in fact this is what Microsoft wanted to do. The EU said that they couldn't. And the reason why not is simple. Anything that Microsoft thinks is a good thing to add to the API, they'll add for themselves. When the new API is released, their software is released with it. This gives them a competitive advantage over competitors who have to wait for Microsoft to have the idea that they want, and then scra…

There is another point to consider here. The state of anti-virus solutions before Microsoft released Defender was horrible (probably still is).

It was full of ad infested solutions, which would crash your computer from time to time.

Defender at least was reasonably performant and tended to be stable.

You could say that since they had access to kernel source, they were better informed, but I guess if there was an API, the provided documentation would solve the issue (not necessarily, not everyone bothers to read the docs).

But then you get back on how to enforce equal and open access for everyone (the EU did try to make Microsoft open the Word file format, but turned out it was so complicated and documented in legacy code only, that Micorsoft had trouble giving useful docs)

Anyway, as you said, it's complicated...

Re: Why the CrowdStrike bug hit banks hard

#139
post #92

Earlier quoted context omitted.

Management decides to use Crowdstrike, not IT, and IT has no way to rollout updates in controlled fashion. So not really a failure of IT, at least not for this reason.

My comment assumes that the IT department (including its executive) gets to make these sort decisions - why wouldn't they?

IT doesn't steer the ship in banks (and bank-like orgs). IT gets a mandate from the real decision makers that they have to choose something that does x, y, z - see "Regulations which strongly suggest particular software purchases" in the article for examples of x, y, z.

So sure, IT gets to "decide" - between CrowdStrike, SentinalOne, or Palo Alto (and maybe a couple others). But they don't really have much choice, they can't use an OSS solution, or roll their own, or anything else. They have to pick one of a small number of existing solutions.

Re: Why the CrowdStrike bug hit banks hard

#140

I like the technical stuff here. I'm not so sure about this: > money is core societal infrastructure, like the power grid and transportation systems are. It would be really bad if hackers working for a foreign government could just turn off money. Sure, it would be inconvenient in the short term. But I think the current design is holding us back. I suspect that most of us would have more to gain than to lose if we ma…

In the early 90's Russia, essentially, voided almost all of the Soviet money that remained in monetary system (most of which were bank deposits; they simply vanished with zero compensation), allowing rather small upper limit on the amount of old Soviet roubles one person was allowed to exchange for the new Russian roubles. Believe it or not, that really did not help the low and low-middle classes with their growing f…

Losing access to one currency but not others is quite a different thing, I don't think that would help anybody.

What I think would help is something that evolved in a less stable computing environment. Something which had to be partition tolerant. Such a thing would have to remain more closely coupled with the consent and merits of its participants because it would lack a reliable connection to a far away authority (currently used to uphold the wishes of extraneous parties to the transaction). Something like local-first software, but for money.

Post reply on HN