Earlier quoted context omitted.
Even computer security itself is a metaphor (at least in its inception). I often wonder what if instead of using terms like access, key, illegal operation, firewall, etc. we'd instead chosen metaphors from a different domain, for example plumbing. I'm sure a plumbing metaphor could also be found for every computer security concern. Would be so quick to romanticize as well as militarize a field dealing with "leaks," "…
“Fatbergs” expresses some things delivered by some teams very eloquently for me!
Preliminary Post Incident Review
161–170 of 227 posts
Re: Preliminary Post Incident Review
#162Cowards. Why don't you just stand up and admit that you didn't bother testing everything you send to production? Everything else is smoke and the smell of sulfur.
The "What Happened on July 19, 2024?" section combined with the "Rapid Response Content Deployment" make it very clear to anyone reading that that is the case. Similarly, the discussion of the sensor release process in "Sensor Content" and lack of discussion of a release process in the "Rapid Response Content" section solidify the idea that they didn't consider validated rapid response content causing bad behavior as a thing to worry about.
Re: Preliminary Post Incident Review
#163It compiled, so they shipped it to everyone all at once without ever running it themselves.
They fell short of "works on my machine".
Re: Preliminary Post Incident Review
#164Earlier quoted context omitted.
They mentioned they do dogfooding. Wonder why it did not work for this update.
You just got tricked by this dishonest article. The whole section that mentions dogfooding is only about actual updates to the kernel driver. This was not a kernel driver update, the entire section is irrelevant. This was a "content file", and the first time it was interpreted by the kernel driver was when it was pushed to customer production systems worldwide. There was no testing of any sort.
Re: Preliminary Post Incident Review
#165Re: Preliminary Post Incident Review
#166Earlier quoted context omitted.
Fun post, but I'll state the obvious because I think many people do believe that every Windows machine BSOD'd. It was only ones with Crowdstrike software. Which is apparently very common but isn't actually pre-installed by Microsoft in Windows, or anything like that. Source: work in a Windows shop and had a normal day.
True, and definitely worth a mention. This is only Microsoft's fault insofar as it was possible at all to crash this way, this broadly, with so little recourse via remote tooling.
Re: Preliminary Post Incident Review
#167Earlier quoted context omitted.
You just got tricked by this dishonest article. The whole section that mentions dogfooding is only about actual updates to the kernel driver. This was not a kernel driver update, the entire section is irrelevant. This was a "content file", and the first time it was interpreted by the kernel driver was when it was pushed to customer production systems worldwide. There was no testing of any sort.
All these people claiming they didn’t have canaries. They actually did but people are in denial that they are the canary for crowdstrike lol
Re: Preliminary Post Incident Review
#168Earlier quoted context omitted.
If it happened, the industry would have known by now. The group behind it will come out to the public.
This would be the kind of vulnerability that would be worth millions of dollars and used for targeted attacks and/or by state actors. It could take years to uncover (like Pegasus, which took 5 years to be discovered) or never be uncovered at all.
Re: Preliminary Post Incident Review
#169Earlier quoted context omitted.
>Now that this Global Outage happened, it will change the landscape a bit. I seriously doubt that. Questions like "why should we use CrowdStrike" will be met with "suppose they've learned their lesson".
I'm referring to the landscape how current Cybersecurity vendors deliver "detection definition" (for lack of better phrase) to their customers. If you don't send them fast to your customer and your customer gets compromised, your reputation gets hit. If you send them fast, this BSOD happened. It's more like damn if you do, damn if you don't.
> If you send them fast, this BSOD happened.
> It's more like damn if you do, damn if you don't.
What about notifications? If someone has an update policy that disable auto-updates to a critical piece of infrastructure, you can still let him know that there's a critical update is available. Now, he can do follow his own checklist in order to ensure everything goes well.