Live data from Hacker News

Why the CrowdStrike bug hit banks hard

bitsaboutmoney.com

221–230 of 250 posts

Re: Why the CrowdStrike bug hit banks hard

#221
post #21

Earlier quoted context omitted.

What about the previous crowdstrike bugs that hit Linux systems in a similar fashion? I don't understand how this has anything to do with Windows, Crowdstrike is the one who built the application.

It has everything to do with Windows, because it's Windows who crashed. Applications crash all the time. But in this case people weren't able to even load the Windows to figure what's wrong or what app has crashed. Microsoft allowed a third-party to self-update and didn't put a proper system of review and updates control to the heart of its OS.

The same thing happened before with Linux, crowdstrike made systems unbootable.

So I don't understand why you're focusing on windows here. Linux allows anyone to update too, there's no review or control either.

Just because an OS allows you to break it, does not mean the maker of the OS is liable when you do break it.

Re: Why the CrowdStrike bug hit banks hard

#222
post #3

I'm still amazed how the blame shifted from Microsoft to CrowdStrike. Yes, CrowdStrike update caused that -- but applications fail all the time. It was Microsoft's oversight to put it on Windows critical path. And banks/airlines etc were hit hard because their _Windows_ didn't boot, not because of an application crash on a perfectly working Windows.

I’ve used this analogy before. If I sell you a bike and you remove the breaks you can’t sue me when you crash. Any OS which allows users to do what they generally want to do, also allows users to fubar their own systems.

Let me exaggerate a bit to show how bad that analogy is:

Let's say I've developed an laptop that bricks whenever you open a website with incorrectly formatted HTML.

Not sure how to adapt your bike analogy to this... Let's say you made a bike that's intended to be ridden outdoors, but breaks down whenever user sits on indoors. Yea, no one is supposed to ride it indoors. Not sure it's the best analogy though.

UPDATE: let's say the bike breaks down completely whenever it's ridden in the rain.

Re: Why the CrowdStrike bug hit banks hard

#223
post #3

I'm still amazed how the blame shifted from Microsoft to CrowdStrike. Yes, CrowdStrike update caused that -- but applications fail all the time. It was Microsoft's oversight to put it on Windows critical path. And banks/airlines etc were hit hard because their _Windows_ didn't boot, not because of an application crash on a perfectly working Windows.

This is the comment I expected, begging to handover your freedoms to run software to a big carry. If you replace parts in your BMW, and put in some garbage or incompatible parts, it your fault if it doesn’t run. You expect to sue your mechanic if he messed up, and for him to cover the full cost. For some reason people do not expect CrowdStrike to pay for their stupidity, which is the root of the problem. And the mana…

Bit it wasn't some garbage parts in a car, it was an app. And apps fail all the time, OS is expected to handle that. Same as car is expected to handle rain for example.

Re: Why the CrowdStrike bug hit banks hard

#224
post #98
post #72

Earlier quoted context omitted.

Note: At least on Linux the main alternatives for this, either eBPF (e.g., pulsar or falcon) or a kernel module, both require this too.

eBPF is at least somewhat sandboxed, no? So it doesn't quite have the access required to accidentally stomp on any portion of kernel memory it wants?

The version of the CrowdStrike sensor that caused kernel panics on RHEL/Rocky was using eBPF. It living in eBPF doesn't mean it can't cause system instability.

And as mentioned elsewhere, an eBPF module behaving badly but in valid ways can still make your system pretty unusable.

Re: Why the CrowdStrike bug hit banks hard

#225

Earlier quoted context omitted.

This is the comment I expected, begging to handover your freedoms to run software to a big carry. If you replace parts in your BMW, and put in some garbage or incompatible parts, it your fault if it doesn’t run. You expect to sue your mechanic if he messed up, and for him to cover the full cost. For some reason people do not expect CrowdStrike to pay for their stupidity, which is the root of the problem. And the mana…

Bit it wasn't some garbage parts in a car, it was an app. And apps fail all the time, OS is expected to handle that. Same as car is expected to handle rain for example.

Buggy third-party kernel modules cause kernel panics all the time in Linux. You can easily write a kernel module to make a Linux system explode.

Re: Why the CrowdStrike bug hit banks hard

#226

Earlier quoted context omitted.

But then again ransomware would happen like you said if they skipped it? And ransomware sounds even worse.

The difference is that if windows does the skipping then you probably don't find out until its too late, if the application does the skipping there is the opportunity to set up alerting so you can fix whatever went wrong.

Do you mean that the skip would be manually approved after telemetry is sent and folks on-call paged? Then that sounds like it could be viable and a good idea yes.

But always a chance that the skipping mechanism could break as well. And there must be some form of networking available to able to send that and ask for approval.

Re: Why the CrowdStrike bug hit banks hard

#227

I like the technical stuff here. I'm not so sure about this: > money is core societal infrastructure, like the power grid and transportation systems are. It would be really bad if hackers working for a foreign government could just turn off money. Sure, it would be inconvenient in the short term. But I think the current design is holding us back. I suspect that most of us would have more to gain than to lose if we ma…

The uber-wealthy don't have most of their assets in currency. Its in stocks, houses, cars, boats, etc. Delete the dollars, it'll hurt them a bit, but in the end they still have a house(es).

But now all those people who were using currency to trade for housing now suddenly need to find a new way to trade for shelter.

Who got hurt worse here?

Re: Why the CrowdStrike bug hit banks hard

#228

Earlier quoted context omitted.

Once the AV vendors exist, killing them, especially by Microsoft, is clearly anticompetitive. If you could prevail on a government to decide that, maybe it could work. One thing I see, is that AV has a component of maintaining a DB of signatures of bad things. This does not seem at all the job of the core os. Would the Debian team maintain such a DB?

It happens all the time that the big companies take something in house and kill a market. The car radio market is all but dead now that manufactures ship decent radios.

Also Apple is notorious for killing software businesses by creating their own built in version.

Re: Why the CrowdStrike bug hit banks hard

#229
post #209

Earlier quoted context omitted.

I'm not making an analogy with the microwave (your saying food is software and the microwave is hardware) I'm literally talking about the software that runs on a microwave.

I'm aware of the point you're trying to make with the microwave. I'm making another analogy; one you're not getting. And either way, yes, I think you should be able to change the software on the microwave. It is your microwave . Do whatever you want with it. Why should Samsung or GE have the right to say what you can or cannot do with the things you own? If we want to talk microwaves, Microsoft is the microwave manuf…

Why? because it would have avoided 5 Billion in damages. I think that's reason enough for me.

Re: Why the CrowdStrike bug hit banks hard

#230
post #209

Earlier quoted context omitted.

I'm not making an analogy with the microwave (your saying food is software and the microwave is hardware) I'm literally talking about the software that runs on a microwave.

I'm aware of the point you're trying to make with the microwave. I'm making another analogy; one you're not getting. And either way, yes, I think you should be able to change the software on the microwave. It is your microwave . Do whatever you want with it. Why should Samsung or GE have the right to say what you can or cannot do with the things you own? If we want to talk microwaves, Microsoft is the microwave manuf…

Ok got it. Crowdstrike is malware. If you install malware you're just a dumb user. got it.
Post reply on HN