Live data from Hacker News

Why the CrowdStrike bug hit banks hard

bitsaboutmoney.com

231–240 of 250 posts

Re: Why the CrowdStrike bug hit banks hard

#231

Earlier quoted context omitted.

I’ve used this analogy before. If I sell you a bike and you remove the breaks you can’t sue me when you crash. Any OS which allows users to do what they generally want to do, also allows users to fubar their own systems.

Let me exaggerate a bit to show how bad that analogy is: Let's say I've developed an laptop that bricks whenever you open a website with incorrectly formatted HTML. Not sure how to adapt your bike analogy to this... Let's say you made a bike that's intended to be ridden outdoors, but breaks down whenever user sits on indoors. Yea, no one is supposed to ride it indoors. Not sure it's the best analogy though. UPDATE: l…

No one's forcing you to install kernel level software.

If I install some kernel level anti cheats and they stop Windows from booting, I need to blame the game developers. Not Microsoft.

Your free to install pretty much whatever you want on Windows.

Re: Why the CrowdStrike bug hit banks hard

#232

Earlier quoted context omitted.

[flagged]

You're living in a different reality. I can't fathom how anybody could legitimately make that claim. Even if you're defining "critical system" as "critical to humans" and not "critical to the business", then sure, you can say "Airlines aren't critical" and for most passengers, yeah, you're probably right. Most industries aren't critical, so businesses being ground to a halt doesn't matter for the consumers. But 911 s…

The 911 system itself is critical sure. I never said it wasn't. When the computer systems supporting 911 went down due to crowdstrike, those functions were replaced with available backups, that were planned for situations like this, e.g. using analog phones and taking notes by hand (just like they used to do it).

If the system survives (albeit with diminished capacity) loss of a component, then that component is not critical for the system. That's basically the definition of "critical".

Source: https://www.usatoday.com/story/news/nation/2024/07/19/crowds...

Re: Why the CrowdStrike bug hit banks hard

#233
post #221

Earlier quoted context omitted.

It has everything to do with Windows, because it's Windows who crashed. Applications crash all the time. But in this case people weren't able to even load the Windows to figure what's wrong or what app has crashed. Microsoft allowed a third-party to self-update and didn't put a proper system of review and updates control to the heart of its OS.

The same thing happened before with Linux, crowdstrike made systems unbootable. So I don't understand why you're focusing on windows here. Linux allows anyone to update too, there's no review or control either. Just because an OS allows you to break it, does not mean the maker of the OS is liable when you do break it.

Same with Linux yes, I never said Linux is any better in this question than Windows. At least it's free, and no warranties is given. But if RedHat had failed the same way, I think ReHat Inc would bear the blame just as well.

PS: I believe BSD-based systems would be more resilient because of microkernel architecture.

Re: Why the CrowdStrike bug hit banks hard

#234
post #14

> For historical reasons, that area where almost everything executes is called “userspace.” It's an old term at this point, but I don't think the reasons for it being called "userspace" have changed or become outdated since then, so I wouldn't call them historic per se.

I used to like Patrick's posts but lately they are way to long and full of irrelevant minutia. Decide who you're writing for, and write to that audience.

> Decide who you're writing for, and write to that audience.

He has, and he does.

Re: Why the CrowdStrike bug hit banks hard

#235
post #14

> For historical reasons, that area where almost everything executes is called “userspace.” It's an old term at this point, but I don't think the reasons for it being called "userspace" have changed or become outdated since then, so I wouldn't call them historic per se.

I used to like Patrick's posts but lately they are way to long and full of irrelevant minutia. Decide who you're writing for, and write to that audience.

Congrats, you've been screenshotted and tweeted by him!

"In which an HN commenter offers me writing advice but fails to understand the implication of second sentence"

https://x.com/patio11/status/1818757982706139297

Re: Why the CrowdStrike bug hit banks hard

#236
post #67
post #41

Earlier quoted context omitted.

Couldn't you just ask some OS APIs provided by something in kernelspace for what you need? In fact, isn't this how macOS does things?

You could, and in fact this is what Microsoft wanted to do. The EU said that they couldn't. And the reason why not is simple. Anything that Microsoft thinks is a good thing to add to the API, they'll add for themselves. When the new API is released, their software is released with it. This gives them a competitive advantage over competitors who have to wait for Microsoft to have the idea that they want, and then scra…

[deleted]

Re: Why the CrowdStrike bug hit banks hard

#237
post #72
post #50

Earlier quoted context omitted.

> With the current model kernel level access is required. On Windows.

Note: At least on Linux the main alternatives for this, either eBPF (e.g., pulsar or falcon) or a kernel module, both require this too.

macOS does not require this however.

Re: Why the CrowdStrike bug hit banks hard

#238

Earlier quoted context omitted.

One interesting thing I saw is, per a snippet that claimed to be part of Crowd Strike's ToS, it shouldn't have been installed on any of those machines where human life depended upon it (along with no nuclear facilities and a few other exceptions). Is there going to be any fallout from people installing it on systems the software wasn't designed for? Did Crowd Strike perhaps know it was being installed on these system…

if a user does something the manufacturer told them specifically not to do, I have a hard time blaming the manufacturer for it. Within an approved use? absolutely, blame the manufacturer. but if you shoot yourself in the foot, don't blame the bowyer just because they sold the bow to you.

Supposedly, CrowdStrike sales would pressure companies to have the software installed on every system in their network.

Re: Why the CrowdStrike bug hit banks hard

#239

Earlier quoted context omitted.

Once the AV vendors exist, killing them, especially by Microsoft, is clearly anticompetitive. If you could prevail on a government to decide that, maybe it could work. One thing I see, is that AV has a component of maintaining a DB of signatures of bad things. This does not seem at all the job of the core os. Would the Debian team maintain such a DB?

It happens all the time that the big companies take something in house and kill a market. The car radio market is all but dead now that manufactures ship decent radios.

Bad things happen all the time. US school shoothings are a regular occurence.

Re: Why the CrowdStrike bug hit banks hard

#240
post #230

Earlier quoted context omitted.

I'm aware of the point you're trying to make with the microwave. I'm making another analogy; one you're not getting. And either way, yes, I think you should be able to change the software on the microwave. It is your microwave . Do whatever you want with it. Why should Samsung or GE have the right to say what you can or cannot do with the things you own? If we want to talk microwaves, Microsoft is the microwave manuf…

Ok got it. Crowdstrike is malware. If you install malware you're just a dumb user. got it.

Finally you're getting it. Making real progress here.

Microsoft didn't make CrowdStrike. They didn't make the update. They didn't enforce it. They didn't sell it.

Post reply on HN