Live data from Hacker News

CrowdStrike Update: Windows Bluescreen and Boot Loops

old.reddit.com

301–310 of 1001 posts

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#301
Their stock price will suffer but they can waive license fees for a year or so for every endpoint affected (~$50).

They better pin this on a rogue employee, but even then, force pushing updates shouldn't be in their capability at all! They must guarantee removal of that capability.

Lawsuits should be interesting. They offer(ed?) $1 mil breach insurance to their customers, so if they were to pay only that much per customer this might be compensation north of $10B. But to be honest, wouldn't surprise me if they can pay up without going bankrupt.

The sad situation is, as twitter people were pointing out, IT teams will use this to push back against more agents for a long time to come. But in reality, these agents are very important.

Crowdstrike Falcon alone is probably the single biggest security improvement any company can make and there is hardly any competition. This could have been any security vendor, the impact is so widespread because of how widely used they are, but there is a reason why they are so widely used to begin with.

Oh and just fyi, the mitigation won't leave you unprotected, when you boot normal, the userspace exe's will replace it with a fixed version.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#303

Naive question, if it’s a blue screen of death with a boot loop, how are they going to restore things? Don’t tell me the answer is going to every system manually.

Going to every system manually, then delete a file via command line in Windows' recovery environment.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#306

They all should have used some expensive corporate-and-government-level product that promises protection against exactly that kind of large scale attack on infrastructure.

I assume this is irony, since isn’t Crowdstrike exactly that these days?

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#307
post #104

Maybe one day we will stop giving RCE to so many vendors via auto update.

I am going to stop saying this but people don't realize CS has an official RCE as a feature. As in run remote commands as root/admin on windows or linux/mac through their web.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#308

The details (the particular companies / systems etc) of this global incident don't really matter. When the entire society and economy are being digitized AND that digitisation is controlled and passes through a handful of choke points its an invitation to major disaster. It is risk management 101, never put all your digital eggs in one (or even a few) baskets. The love affair with oligopoly, cornered markets and powe…

Easy to state; non-trivial to implement.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#309
That's what you get for letting a company install a root kit on your servers and desktops ;-)

I mean, don't they do canary updates on CrowdStrike too? Every Windows admin has done this for the last 5+ years, test Windows updates on a small number of systems to see if they are stable. Why not do the same for 3rd party software?

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#310
It's kind of surprising so much infra was using windows servers or windows cloud VMs for these things. I assumed these systems would all be Linux VMS in Azure/AWS/GCP at this point.

on https://azure.status.microsoft/en-gb/status the message is currently:

> We have been made aware of an issue impacting Virtual Machines running Windows Client and Windows Server, running the CrowdStrike Falcon agent, which may encounter a bug check (BSOD) and get stuck in a restarting state.

Post reply on HN