Live data from Hacker News

Why the CrowdStrike bug hit banks hard

bitsaboutmoney.com

71–80 of 250 posts

Re: Why the CrowdStrike bug hit banks hard

#71
post #59
post #56

Earlier quoted context omitted.

Exactly this. Microsoft did this poorly, so they were forced to allow others to do things poorly too.

I guess I don't think that's the sole reason, as I think the incentives would still be in place even if Microsoft authored security software did not run anything in kernel space.

You mean in terms of third-parties wanting that level of access regardless? I agree, but it would be an easy "no" then.

Re: Why the CrowdStrike bug hit banks hard

#72
post #50
post #37

Earlier quoted context omitted.

With the current model kernel level access is required. Real security products have to be able to operate above userland. Ideally in the future there can be a layer in between userland and kernel for this sort of thing. Maybe we use some of those extra protection rings?

> With the current model kernel level access is required. On Windows.

Note: At least on Linux the main alternatives for this, either eBPF (e.g., pulsar or falcon) or a kernel module, both require this too.

Re: Why the CrowdStrike bug hit banks hard

#73
post #3

I'm still amazed how the blame shifted from Microsoft to CrowdStrike. Yes, CrowdStrike update caused that -- but applications fail all the time. It was Microsoft's oversight to put it on Windows critical path. And banks/airlines etc were hit hard because their _Windows_ didn't boot, not because of an application crash on a perfectly working Windows.

This is the comment I expected, begging to handover your freedoms to run software to a big carry.

If you replace parts in your BMW, and put in some garbage or incompatible parts, it your fault if it doesn’t run.

You expect to sue your mechanic if he messed up, and for him to cover the full cost. For some reason people do not expect CrowdStrike to pay for their stupidity, which is the root of the problem. And the management that installed crowdstrike without due diligence

Re: Why the CrowdStrike bug hit banks hard

#74
post #3

I'm still amazed how the blame shifted from Microsoft to CrowdStrike. Yes, CrowdStrike update caused that -- but applications fail all the time. It was Microsoft's oversight to put it on Windows critical path. And banks/airlines etc were hit hard because their _Windows_ didn't boot, not because of an application crash on a perfectly working Windows.

This is the comment I expected, begging to handover your freedoms to run software to a big carry.

If you replace parts in your BMW, and put in some garbage or incompatible parts, it your fault if it doesn’t run.

You expect to sue your mechanic if he messed up, and for him to cover the full cost. For some reason people do not expect CrowdStrike to pay for their stupidity, which is the root of the problem. And the management that installed crowdstrike without due diligence

Re: Why the CrowdStrike bug hit banks hard

#75
post #41
post #37

Earlier quoted context omitted.

With the current model kernel level access is required. Real security products have to be able to operate above userland. Ideally in the future there can be a layer in between userland and kernel for this sort of thing. Maybe we use some of those extra protection rings?

Couldn't you just ask some OS APIs provided by something in kernelspace for what you need? In fact, isn't this how macOS does things?

Microsoft was on their way to doing this, but was shot down by EU regulators because the APIs weren't available to all third-party vendors.

Re: Why the CrowdStrike bug hit banks hard

#76

The takeaway from this article seems to be: buy crowdstrike shares, because major corps are unable to make any changes, and will continue to pay licensing fees for this "service" for the foreseeable future.

The lawsuits alone are going to be eyewatering. But sure, buy those shares.

Delta airlines is in the headlines saying they had a $500 million impact and have no choice but to sue

Re: Why the CrowdStrike bug hit banks hard

#77
post #58

Maybe the IT departments at the affected orgs take solace in the fact that so many other orgs had issues that the heat is off - but in my opinion this was still a failure of IT itself. There's no reason that update should have been pushed automatically to the entire fleet. If Crowdstrike's software doesn't give you a way to rollout updates on a portion of your network before the entire fleet, it shouldn't be used.

The update bypassed the controls orgs had in place to defer/schedule updates, AFAIK.

I've had trouble nailing down if thats the case from searching around online. And if thats true - thats absolutely on Crowdstrike. And that behavior should disqualify it from being used on critical systems. I imagine this incident will cause a lot of teams to consider just what can happen automatically on their systems.

Re: Why the CrowdStrike bug hit banks hard

#78
post #28

Regulations are a big reason why this happened, sure, but also it hit the companies with great security budgets more. Hospitals, for instance, weren't that widely affected as they barely have any money to buy security tooling. Silver linings and all that, I guess.

> Hospitals Everybody seems to be quick to forget about WannaCry.

Wannacry was not an accident. It was inarguably an intentional attach against general IT infrastructure instead of a borked update.

Re: Why the CrowdStrike bug hit banks hard

#79

Was anyone else surprised how little disruption they personally experienced? I had braced for impact that weekend. But all my flights were perfectly on time, all my banking worked, providers worked, and sites & resources were available. I don’t know if I somehow just have little exposure to Windows in my life or if there’s an untold resiliency story for the global internet in the face of such a massive outage. All I…

IIRC only 5% of Windows machines were affected. So, it is very probable that most people just saw the news but have no real impact on them. Some had minor and maybe memorable impact, like Indian airlines giving handwritten boarding passes.

Re: Why the CrowdStrike bug hit banks hard

#80
post #58

Maybe the IT departments at the affected orgs take solace in the fact that so many other orgs had issues that the heat is off - but in my opinion this was still a failure of IT itself. There's no reason that update should have been pushed automatically to the entire fleet. If Crowdstrike's software doesn't give you a way to rollout updates on a portion of your network before the entire fleet, it shouldn't be used.

Management decides to use Crowdstrike, not IT, and IT has no way to rollout updates in controlled fashion.

So not really a failure of IT, at least not for this reason.

Post reply on HN