Live data from Hacker News

CrowdStrike Update: Windows Bluescreen and Boot Loops

old.reddit.com

151–160 of 1001 posts

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#153

If it's true that a bad patch was the reason for this I assume someone, or multiple people, will have a really bad day today. Makes me wonder what kind of testing they have in place for patches like this, normally I wouldn't expect something to go out immediately to all clients but rather a gradual rollout. But who knows, Microsoft keeps their master keys on a USB stick while selling cloud HSM so maybe Crowdstrike ju…

Doesn't matter what testing exists. More scale. More complexity. More Bugs.

Its like building a gigantic factory farm. And then realizing that environment itself is the birthing chamber and breeding ground of superbugs with the capacity to wipe out everything.

I used to work at a global response center for big tech once upon a time. We would get hundreds of issues, we couldn't replicate cause we literally have to set up our own govt or airline or bank or telco to test certain things.

So I used to joke with the corporate robots to just hurry up and take over govts, airlines, banks and telcos already, cause thats the only path to better control.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#155
CyberStrike offers a temporary solution for crashed systems Cyberstike has given users a potential way to fix their systems.

Boot Windows into Safe Mode or the Windows Recovery Environment (you can do that by holding down the F8 key before the Windows logo flashes on screen) Navigate to the C:WindowsSystem32driversCrowdstrike directory Locate the file matching “C-00000291.sys” file, right click and rename it to “C-00000291.renamed” Boot the host normally.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#156
post #80

We are a major CS client, with 50k windows-based endpoints or so. All down. There exists a workaround but CS does not make it clear whether this means running without protection or not. (The workaround does get the windows boxes unstuck from the boot loop, but they do appear offline in the CS host management console - which of course may have many reasons).

Does CS actually offer any real protection? I always thought it was just feel-good software, that Windows had caught up to separating permissions since after XP or so. Either one is lying/scamming, but which one?

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#158
The only surprising thing is that this doesn't happen every month. Nobody understands their runtime environment. Most IT org's long ago "surrendered" control and understanding of it, and now even the "management" of it (I use the term loosely) is outsourced.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#159
post #148

Absolutely shameful display of how the cure can be worse than the disease. It's nonsense snake oil and security theater such as this that throws the cyber"security" industry into disrepute. One may as well have just installed McAfee Anti Virus.

This has been the story of the antivirus "industry" all along. They simultaneously seem to employ actual bona-fide security researchers while also making sure none of their software products are ever touched by people you could even refer to as "developers". I can't even imagine the noise at Microsoft from all the crash reports solely caused by antivirus software written by utter clowns injecting into other programs and, as here, into the kernel.

Previous: https://infosec.exchange/@wdormann/112530285189478825

Previous: https://thehackernews.com/2022/05/chinese-hackers-caught-exp...

Previous: https://www.ftc.gov/news-events/news/press-releases/2024/02/...

Previous: https://www.fortiguard.com/psirt/FG-IR-24-015

...

Post reply on HN