Earlier quoted context omitted.
The actual issue was with the signed code reading the data files that the data file update just brought to surface. But I don't think Microsoft verifies customer code, they might not even have access to it.
You are right Microsoft are not checking the 3rd party code itself they are only running a lot of tests on the compiled code. There is a recent video now from a former Microsoft employee where he explains that those drivers that get WHQL certification are ran on test machines in stress conditions for some time, or at least that is how it used to be when he worked there. Since that process is probably quite slow to be…
New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints
61–66 of 66 posts
Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints
#62Earlier quoted context omitted.
If you're running CrowdStrike I would think Windows Defender is probably disabled, no?
They could push a windows update that nukes CrowdStrike and re-enables Windows Defender. I'm pretty sure they've done that sort of thing in the past.
Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints
#63Earlier quoted context omitted.
I imagine having an unencrypted disk in 2024 can be most charitably called 'an oversight', so there's little point in attempting to deal with them. (Remember we're talking about boxes with crowdstrike installed...)
Ahh, right. You'd need bitlocker keys. Although I wonder if the central key server could be queried to obtain each host's key? Also makes me wonder about a software configuration management system that operated on disks while the virtual hosts were powered down. With windows it feels like that'd be at least very difficult, but Linux could definitely be managed that way. Like an immutable operating system where change…
Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints
#64Really impressive that they got thru an entire develop, build, approval, and documentation process in just about 2 days. Not that any of those steps are extremely hard for this fix, but I'm always impressed when big corporations can move so fast
I sympathize with the engineers, QA, and everyone involved in getting this out. I have to imagine it was a lot of long hours, and the testing was insane. The last thing I want to do is put this tool out and it somehow messes things up more. But glad it’s out. Hopefully it helps with the remaining machines and with any that are being problematic.
Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints
#65Earlier quoted context omitted.
Ahh, right. You'd need bitlocker keys. Although I wonder if the central key server could be queried to obtain each host's key? Also makes me wonder about a software configuration management system that operated on disks while the virtual hosts were powered down. With windows it feels like that'd be at least very difficult, but Linux could definitely be managed that way. Like an immutable operating system where change…
And what OS with what security product do you think the central key server runs?
Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints
#66Earlier quoted context omitted.
They could say "third party kernel modules are installed at your own risk" and provide the usual level of business hours support. CrowdStrike fucked up and Microsoft is helping its customers recover from CrowdStrike's fuckup.
They recommend crowdstrike to customers. Now they are trying to at least skim some good will. Also bad a kernel module that can ruin the OS is partially their fault.