Live data from Hacker News

New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints

techcommunity.microsoft.com

61–66 of 66 posts

Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints

#61
post #17

Earlier quoted context omitted.

The actual issue was with the signed code reading the data files that the data file update just brought to surface. But I don't think Microsoft verifies customer code, they might not even have access to it.

You are right Microsoft are not checking the 3rd party code itself they are only running a lot of tests on the compiled code. There is a recent video now from a former Microsoft employee where he explains that those drivers that get WHQL certification are ran on test machines in stress conditions for some time, or at least that is how it used to be when he worked there. Since that process is probably quite slow to be…

I guess Microsoft testing lacks fuzzing, then—as does Crowdstrike's.

Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints

#62
post #48

Earlier quoted context omitted.

If you're running CrowdStrike I would think Windows Defender is probably disabled, no?

They could push a windows update that nukes CrowdStrike and re-enables Windows Defender. I'm pretty sure they've done that sort of thing in the past.

That would require the system to actually boot. Which the CrowdStrike bug prevents.

Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints

#63
post #34

Earlier quoted context omitted.

I imagine having an unencrypted disk in 2024 can be most charitably called 'an oversight', so there's little point in attempting to deal with them. (Remember we're talking about boxes with crowdstrike installed...)

Ahh, right. You'd need bitlocker keys. Although I wonder if the central key server could be queried to obtain each host's key? Also makes me wonder about a software configuration management system that operated on disks while the virtual hosts were powered down. With windows it feels like that'd be at least very difficult, but Linux could definitely be managed that way. Like an immutable operating system where change…

And what OS with what security product do you think the central key server runs?

Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints

#64
post #5

Really impressive that they got thru an entire develop, build, approval, and documentation process in just about 2 days. Not that any of those steps are extremely hard for this fix, but I'm always impressed when big corporations can move so fast

I sympathize with the engineers, QA, and everyone involved in getting this out. I have to imagine it was a lot of long hours, and the testing was insane. The last thing I want to do is put this tool out and it somehow messes things up more. But glad it’s out. Hopefully it helps with the remaining machines and with any that are being problematic.

They probably got an exemption to fast track the release because this is a critical issue. I wouldn't expect testing to be so thorough for a release in 2 days. The exemption is more likely.

Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints

#65

Earlier quoted context omitted.

Ahh, right. You'd need bitlocker keys. Although I wonder if the central key server could be queried to obtain each host's key? Also makes me wonder about a software configuration management system that operated on disks while the virtual hosts were powered down. With windows it feels like that'd be at least very difficult, but Linux could definitely be managed that way. Like an immutable operating system where change…

And what OS with what security product do you think the central key server runs?

Well, sure, the central key server will have been affected by this, but that's one VM to remediate/restore and would hopefully be done first. Or at least once people realize the key server is also down.

Re: New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints

#66
post #9
post #7

Earlier quoted context omitted.

They could say "third party kernel modules are installed at your own risk" and provide the usual level of business hours support. CrowdStrike fucked up and Microsoft is helping its customers recover from CrowdStrike's fuckup.

They recommend crowdstrike to customers. Now they are trying to at least skim some good will. Also bad a kernel module that can ruin the OS is partially their fault.

Microsoft does not “recommend CrowdStrike”. Microsoft actually sells its own competitor to CrowdStrike (Defender XDR).
Post reply on HN