Live data from Hacker News

Why the CrowdStrike bug hit banks hard

bitsaboutmoney.com

181–190 of 250 posts

Re: Why the CrowdStrike bug hit banks hard

#181
post #91

Did it really hit banks hard? Core banking systems don't run windows, they run on mainframes typically on IBM z/OS. I know it hit the financial firms hard and knocked out their trading systems but I don't know of any major bank losing their core bank system due to crowdstrike. Australia got hit hard because they modernized their bank systems and now most are cloud based. I am not aware of any major bank running their…

> they modernized their bank systems

You mean they made them more vulnerable?

Re: Why the CrowdStrike bug hit banks hard

#182
> This created a minor emergency for me, because it was an other-than-minor emergency for some contractors I was working with.

> Many contractors are small businesses. Many small businesses are very thinly capitalized. Many employees of small businesses are extremely dependent on receiving compensation exactly on payday and not after it. And so, while many people in Chicago were basically unaffected on that Friday because their money kept working (on mobile apps, via Venmo/Cash App, via credit cards, etc), cash-dependent people got an enormous wrench thrown into their plans.

I never really thought about not having to worry about cashflow problems as a privilege before, but it makes sense, considering having access to the banking system to begin with is a privilege. I remember my bank's website and app were offline, but card processing was unaffected - you could still swipe your cards at retailers. For me, the disruption was a minor annoyance since I couldn't check my balance, but I imagine many people were probably panicking about making rent and buying groceries while everything was playing out.

Re: Why the CrowdStrike bug hit banks hard

#183

Was anyone else surprised how little disruption they personally experienced? I had braced for impact that weekend. But all my flights were perfectly on time, all my banking worked, providers worked, and sites & resources were available. I don’t know if I somehow just have little exposure to Windows in my life or if there’s an untold resiliency story for the global internet in the face of such a massive outage. All I…

I wish that were the case for me! My in-laws had their flight out of JFK delayed by 2-3 days, as did my daughter who was supposed to fly as an unaccompanied minor.

Re: Why the CrowdStrike bug hit banks hard

#184

Earlier quoted context omitted.

Should endpoint protection require kernel level access? At what point does it stop becoming protection and start becoming a liability? Obligatory who watches/protects the watchmen/protector...

Yes, it needs kernel access given the userspace api's available in windows. Period. not a single person who knows how the tool works and the threats it protects against has said other wise. userpace can't disable or tamper kernel space but an admin/root process in userspace can.

FWIW I asked if it should require access, not what the current status quo is/what limitations exist within the OS.

Re: Why the CrowdStrike bug hit banks hard

#185

Just as a general comment on this whole affair: This would be the third incident I'm familiar with of a file of entirely zeroes breaking something big. Folks, as much as we wish it weren't true, null comes up all the damn time, and if you don't have tests trying to force-feed null into your system in novel and exciting ways, production will demonstrate them for you. Never assume 'zero' (for whatever form zero takes i…

As long as the botchers get away with impunity, they won't “waste” resources on higher standards.

Re: Why the CrowdStrike bug hit banks hard

#186

Earlier quoted context omitted.

You're living in a different reality. I can't fathom how anybody could legitimately make that claim. Even if you're defining "critical system" as "critical to humans" and not "critical to the business", then sure, you can say "Airlines aren't critical" and for most passengers, yeah, you're probably right. Most industries aren't critical, so businesses being ground to a halt doesn't matter for the consumers. But 911 s…

One interesting thing I saw is, per a snippet that claimed to be part of Crowd Strike's ToS, it shouldn't have been installed on any of those machines where human life depended upon it (along with no nuclear facilities and a few other exceptions). Is there going to be any fallout from people installing it on systems the software wasn't designed for? Did Crowd Strike perhaps know it was being installed on these system…

if a user does something the manufacturer told them specifically not to do, I have a hard time blaming the manufacturer for it. Within an approved use? absolutely, blame the manufacturer.

but if you shoot yourself in the foot, don't blame the bowyer just because they sold the bow to you.

Re: Why the CrowdStrike bug hit banks hard

#187

The article specifically mentions US banks and as I personally didn't see any disruption over here - is there (anec)data on how popular CrowdStrike is in the US vs the EU?

Might be question what type of disruption it is. Transfers and web bank is likely to work. Branches offices and ATMs might have issues. So if you try to do anything in person or negotiate anything with workers in bank there could be issues.

Re: Why the CrowdStrike bug hit banks hard

#188
post #20

Earlier quoted context omitted.

The application (Crowdstrike) was part of Windows' booting process. Windows cannot simply "skip" failed drivers. Say Crowdstrike driver failed as a one time thing, Windows skipped it instead of retrying which led to the endpoint being vulnerable and a ransomware happens. We'd be saying the opposite now. This is a high-impact ability Windows offers to applications - and applications should take responsibility and trea…

But then again ransomware would happen like you said if they skipped it? And ransomware sounds even worse.

The difference is that if windows does the skipping then you probably don't find out until its too late, if the application does the skipping there is the opportunity to set up alerting so you can fix whatever went wrong.

Re: Why the CrowdStrike bug hit banks hard

#189

The takeaway from this article seems to be: buy crowdstrike shares, because major corps are unable to make any changes, and will continue to pay licensing fees for this "service" for the foreseeable future.

The lawsuits alone are going to be eyewatering. But sure, buy those shares.

I admire your optimism.

Re: Why the CrowdStrike bug hit banks hard

#190
post #14

> For historical reasons, that area where almost everything executes is called “userspace.” It's an old term at this point, but I don't think the reasons for it being called "userspace" have changed or become outdated since then, so I wouldn't call them historic per se.

I used to like Patrick's posts but lately they are way to long and full of irrelevant minutia. Decide who you're writing for, and write to that audience.

Some of his audience likes the irrelevant minutia.
Post reply on HN