Live data from Hacker News

Why the CrowdStrike bug hit banks hard

bitsaboutmoney.com

141–150 of 250 posts

Re: Why the CrowdStrike bug hit banks hard

#141
post #43
post #3

I'm still amazed how the blame shifted from Microsoft to CrowdStrike. Yes, CrowdStrike update caused that -- but applications fail all the time. It was Microsoft's oversight to put it on Windows critical path. And banks/airlines etc were hit hard because their _Windows_ didn't boot, not because of an application crash on a perfectly working Windows.

This is a valid opinion and I don't know why you were downvoted (well other than the hacker news bubble mindset (or mindless-set). How is Microsoft not to blame, it's their product? We wouldn't blame a Toyota supplier for a failure in a car, but we somehow segment that in the software world?

Toyota chose the supplier, worked with them on the specs and designs, and put it in their OE car delivered to the customer. It has Toyota's name on it, it was bought at a Toyota dealership, is a part of Toyota's warranty.

Crowdstrike is entirely optional software that doesn't come from Microsoft. Microsoft doesn't market it. Microsoft had no hand in making it. Microsoft doesn't sell it. Microsoft had no hand in a user installing Crowdstrike.

Do you not see the obvious differences there?

Re: Why the CrowdStrike bug hit banks hard

#142
post #7

Earlier quoted context omitted.

In the article it states that Microsoft HAD to allow Crowdstrike to run in kernelspace by EU laws, because else MS would have the monopoly on kernel-level security solutions / integrations.

So why didn't MS lock it down in the US if it's an EU-local rule? Their excuse isn't plausible.

You're spilling cheap propaganda. Microsoft likely never had[0] an appropriate userland-level API in place and them blaming the EU should not be repeated by someone calling themselves a journalist.

[0] https://www.youtube.com/watch?v=EGttFWntctU - I need to state here that I do not possess the level of knowledge the author of video presents and therefore am unable to confirm findings included in the video

Re: Why the CrowdStrike bug hit banks hard

#143
While reading this I was struck with an interesting question: What risk does any particular software vendor pose to an industry at large?

For example (making up numbers here): if 75% of all airline computers have croudstrike falcon installed that seems like a very concentrated risk.

I actually wouldn't be surprised if we had this we would see really high concentrations of a small number of vendors in any industry.

Re: Why the CrowdStrike bug hit banks hard

#144
post #92

Earlier quoted context omitted.

My comment assumes that the IT department (including its executive) gets to make these sort decisions - why wouldn't they?

In many mature orgs, corporate IT rolls up to the CIO and security will roll up to the CISO The CISO and security ops will demand to be completely independent from corp IT, for legit reasons, as the security team needs to treat IT as potential insider threat actors with elevated privileges. They will also demand the ability to push out updates everywhere at any time in response to real-time threats, and per the previ…

> The CISO and security ops will demand to be completely independent from corp IT, for legit reasons, as the security team needs to treat IT as potential insider threat actors with elevated privileges.

I always wondered: why should security ops not be a potential insider thread actor? In fact, if they were compromised, it would be even worse.

Do we need two different security ops that monitor each other? :)

Re: Why the CrowdStrike bug hit banks hard

#145

Earlier quoted context omitted.

Microsoft didn't write the Falcon sensor software nor did they put it in the kernel. In fact, Microsoft has been shouting to the heavens trying to shift the blame from CrowdStrike onto the European Commission, because they want people to irrationally hate antitrust so they can turn Windows into shitty iOS and monopolize the security market (and applications market) for it. Furthermore, Microsoft does actually have so…

> because they want people to irrationally hate antitrust One only needs to look at what's happening with Google's privacy sandbox to know the perils of antitrust with regard to introducing new interfaces. Even though Google has offered new interfaces and APIs that they themselves intend to migrate to (and take a ~20% revenue reduction), they've attracted the scrutiny of regulators who claim that this is a way of loc…

It's important to remember that every other browser dropped third-party cookie support years before Chrome did. Google dragged their feet on it until they could come up with a solution that would give Google the same level of tracking, because Google is an advertising company. So the competition authorities are telling Google - and only Google - that they can't drop third-party cookies anymore.

I've never actually heard anyone claim Privacy Sandbox[0] APIs would give third-party ad networks the same level of tracking as Google. But I imagine even if they did, the APIs would probably be a poor fit for competing ad networks, in the same way that, say, the iOS File Provider APIs are a terrible fit for Dropbox[1].

There are three different ways you can introduce a new standard or interface:

- You can go to or form a standards body with all the relevant market players and agree on a technical specification for that interface. This is preferred, and it's how the Web is usually done.

- You can take a competitor's interface people are already using and adopt that. This is how you get de-facto standards, and while they might have loads of technical problems[2], none of them give you an unfair market advantage.

- You can make your own interface and force competitors to adopt that. You get all the technical problems of a de-facto standard, but those are all problems your competition has to deal with, not you.

The difference is a matter of market advantage. Out of all the major browser vendors, only Google has dominance in online marketing. Microsoft and Apple would like to have a piece of that pie, but they all dropped third-party cookies without tying it to their own competing standards that they wanted to force other people to use.

[0] Hell of an Orwellian name

[1] For example, if you use Dropbox as your file storage, you can't pick folders. At all. On an operating system built by the company whose engineers are obsessed with bundles (directories that look and act like files instead of folders).

[2] laughs in SWF

Re: Why the CrowdStrike bug hit banks hard

#146
post #77

Earlier quoted context omitted.

The update bypassed the controls orgs had in place to defer/schedule updates, AFAIK.

I've had trouble nailing down if thats the case from searching around online. And if thats true - thats absolutely on Crowdstrike. And that behavior should disqualify it from being used on critical systems. I imagine this incident will cause a lot of teams to consider just what can happen automatically on their systems.

It’s definitely the case. See Crowdstrike’s preliminary post incident review here: https://www.crowdstrike.com/falcon-content-update-remediatio...

The nature of “content updates” vs a full product update. Though you may be right, perhaps they provide controls for those updates, I’ve never used their software. But doesn’t sound like it.

Re: Why the CrowdStrike bug hit banks hard

#147

I like the technical stuff here. I'm not so sure about this: > money is core societal infrastructure, like the power grid and transportation systems are. It would be really bad if hackers working for a foreign government could just turn off money. Sure, it would be inconvenient in the short term. But I think the current design is holding us back. I suspect that most of us would have more to gain than to lose if we ma…

I agree there needs to be more competition, but that doesn't mean you need to get rid of the old way. It is better when two approaches run in parallel, to compensate the other's shortcomings.

Re: Why the CrowdStrike bug hit banks hard

#148
post #104
post #92

Earlier quoted context omitted.

My comment assumes that the IT department (including its executive) gets to make these sort decisions - why wouldn't they?

Major purchases tend to be pushed up the ladder. It’s not uncommon for a CEO or non technical director etc to decide what IT systems to use.

In my experience the decisions on any non trivial IT system rollout are made by entirely unqualified, non technical execs who are usually swayed by marketing such as clownstrikes Super Bowl advertisement.

Technical people will make a recommendation, knowing it’s going to be ignored and that the decisions already been made.

Re: Why the CrowdStrike bug hit banks hard

#149
post #77

Earlier quoted context omitted.

I've had trouble nailing down if thats the case from searching around online. And if thats true - thats absolutely on Crowdstrike. And that behavior should disqualify it from being used on critical systems. I imagine this incident will cause a lot of teams to consider just what can happen automatically on their systems.

[flagged]

You're living in a different reality. I can't fathom how anybody could legitimately make that claim.

Even if you're defining "critical system" as "critical to humans" and not "critical to the business", then sure, you can say "Airlines aren't critical" and for most passengers, yeah, you're probably right. Most industries aren't critical, so businesses being ground to a halt doesn't matter for the consumers.

But 911 systems were affected, and those are certainly critical to humans. If 911 doesn't work, ambulances and fire trucks can't be dispatched, and people die.

EDIT: Computers attached to hospital beds, including trauma surgery rooms, were affected. I'm really curious what you think defines a critical system.

Re: Why the CrowdStrike bug hit banks hard

#150
post #14

> For historical reasons, that area where almost everything executes is called “userspace.” It's an old term at this point, but I don't think the reasons for it being called "userspace" have changed or become outdated since then, so I wouldn't call them historic per se.

Why is it called "userspace" when all it runs is some Docker containers hosting a web frontend's server, and no human being ever telnets into it? Where's the "user" in that story?

Where is the "user" when the machine is a Windows box stuffed behind a façade wall that displays airport directions, notifications, and ads on rotate?

Post reply on HN