Live data from Hacker News

CrowdStrike Update: Windows Bluescreen and Boot Loops

old.reddit.com

341–350 of 1001 posts

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#344

I've picked the perfect day to return from vacation. Being greeted by thousands of users being mad at you and people asking for your head on a plate makes me reconsider my career choice. Here's to 12 hours of task force meetings...

Its not just us, form an orderly queue and you'll been seen soon.

Do you really all have these mentally unstable userbases?

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#345

i've seen photos of the bsod from an affected machine, the error code is `PAGE_FAULT_IN_NONPAGED_AREA`. here's some helpful takeaways from this incident: 1) mistakes in kernel-level drivers can and will crash the entire os 2) do not write kernel-level drivers 3) do not write kernel-level drivers 4) do not write kernel-level drivers 5) if you really need a kernel-level driver, do not write it in a memory unsafe langua…

Memory safe language does not prevent crash.

In case of potential UB (and then memory corruption), you get a guaranteed crash.

Wait, crash? :wink:

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#346

i've never heard of crowdstrike ever but it (co-)runs half of the essential IT infrastructure, worldwide? (also, great choice of name i must say)

I only know them because their CEO is a relatively good amateur racing driver lol.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#347

The details (the particular companies / systems etc) of this global incident don't really matter. When the entire society and economy are being digitized AND that digitisation is controlled and passes through a handful of choke points its an invitation to major disaster. It is risk management 101, never put all your digital eggs in one (or even a few) baskets. The love affair with oligopoly, cornered markets and powe…

Now they know the state of each of the affected companies systems. How adept their sysops guys are, a birds eye view of their security practices. Nice move and plausible deniable too :D.

I mean how did this happen at all? Are there no checks in place @ crowdstrike? Like deploying the new update to a selected machines and check whether everything is ok, and then releasing it to the wild incrementally?

Mind boggling.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#348
Vendors of tools like this drive the cybersecurity industry discourse, so 'defense in depth' often practically sorta means 'add more software that does more things'.

But maybe this kind of thing can actually impart the lesson that loading your OS up with always-on, internet-connected agents that include kernel components in order to instrument every little thing any program does on the system is, uh, kinda risky.

But maybe not. I wonder if we'll just see companies flock to alternative vendors of the exact same type of product.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#349
So CrowdStrike is deployed as third party software into the critical path of mission critical systems and then left to update itself. It's easy to blame CrowdStrike but that seems too easy on both the orgs that do this but also the upstream forces that compel them to do it.

My org which does mission critical healthcare just deployed ZScaler on every computer which is now in the critical path of every computer starting up and then in the critical path of every network connection the computer makes. The risk of ZScaler being a central point of failure is not considered. But - the risk of failing the compliance checkbox it satisfies is paramount.

All over the place I'm seeing checkbox compliance being prioritised above actual real risks from how the compliance is implemented. Orgs are doing this because they are more scared of failing an audit than they are of the consequences failure of the underlying systems the audits are supposed to be protecting. So we need to hold regulatory bodies accountable as well - when they frame regulation such that organisations are cornered into this they get to be part of the culpability here too.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#350

The details (the particular companies / systems etc) of this global incident don't really matter. When the entire society and economy are being digitized AND that digitisation is controlled and passes through a handful of choke points its an invitation to major disaster. It is risk management 101, never put all your digital eggs in one (or even a few) baskets. The love affair with oligopoly, cornered markets and powe…

While I agree 100% with what you say in principal, stats show that these occurrences are increasingly rare.
Post reply on HN