Live data from Hacker News

CrowdStrike Update: Windows Bluescreen and Boot Loops

old.reddit.com

541–550 of 1001 posts

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#541
post #538

Crowdstrike did this to our production linux fleet back on April 19th, and I've been dying to rant about it. The short version was: we're a civic tech lab, so we have a bunch of different production websites made at different times on different infrastructure. We run Crowdstrike provided by our enterprise. Crowdstrike pushed an update on a Friday evening that was incompatible with up-to-date Debian stable. So we patc…

This is gold. My friend and me were joking around that they probably did this to macos and linux before, but nobody gave a shit since it's... macos and linux.

(re: people blaming it on windows and macos/linux people being happy they have macos/linux)

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#543
Those EDR software is implemented as a kernel driver.

A third party closed source Windows kernel driver that can't be audited. It gathers massive amount of activities and send back to the central server(which can be sold) as well as execute arbitrary payload from the central server.

It became single point of failure to your whole system.

If an attacker gain control of the sysadmin PC, it's over.

If an attacker gain administrator privilege on EDR-installed system, it run the same privilege with EDR so attacker can hide their activities from EDR. There aren't many EDR products in the world it can be done.

I'd like to call it "full trust security model".

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#544

The details (the particular companies / systems etc) of this global incident don't really matter. When the entire society and economy are being digitized AND that digitisation is controlled and passes through a handful of choke points its an invitation to major disaster. It is risk management 101, never put all your digital eggs in one (or even a few) baskets. The love affair with oligopoly, cornered markets and powe…

Monocultures are known to be points of failure, but people keep going down that path because they optimize for efficiency (heck, most modern economics is premised on the market being efficient).

This problem is pervasive and effects everything from food supply (planting genetically identical seeds rather than diversified "heirloom" crops) to businesses across the board buying and gutting their competitors thus reducing consumer choice.

It's a tough problem akin to a multi-armed bandit: exploit a known strategy or "waste" some effort exploring alternatives in the hopes of better returns. The more efficient you are (exploitation), the higher the likelihood of catastrophic failure in weird edge cases.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#545
Security technology harming security? Shocker. We need less monoculture. Trouble is monoculture pays. Write the software once, deploy it everywhere - free money.

I manage a simple Tier-4 cloud application on Azure, involving both Windows and Linux machines. Crowdstrike, OMI, McAfee and endpoint protection in general has been the biggest thorn in my side.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#546
On a positive note, I'm in morocco and getting money from ATM wasn't working for the whole day I believe because of this outage. I was at the till in a supermarket and people started asking if they can chip in to pay for some food I bought because I didn't have the cash.

Humanity 1 - Technology 0

Edit: Outage of all ATM's in Morocco was yesterday not today. so not sure how the two are related.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#547

Chances if Microsoft or Crowdstrike will be held liable for financial losses caused by this outage?

Prison time for the CEO and board of directors would be nice.

Enough of this limited liability nonsense, there need to be serious, severe, life-changing consequences.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#548

I guess people who continue to use Windows in 2024 arguably deserve this, particularly those utilizing it in a production environment.

what about all the people that use services provided by people that use windows? should there be some sort of pushback here?
Post reply on HN