Live data from Hacker News

CrowdStrike Update: Windows Bluescreen and Boot Loops

old.reddit.com

751–760 of 1001 posts

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#751

WTF is CrowdStrike and why is it affecting so many people and companies? I've never heard of it before. And apparently it isn't anything relevant to all Windows users as it didn't affect any computer of any person I personally know.

Very popular corporate endpoint protection (malware detection and spyware) that runs telemetry & monitoring agents installed as kernel-mode drivers on windows. Thus if there is a crash, it crashes the entire kernel (BSOD) . And their drivers load at boot.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#752

This event is predicted in Sydney Dekker’s book “Drift into Failure”, which basically postulates that in order to prevent local failure we setup failure prevention systems that increase the complexity beyond our ability to handle, and introduce systemic failures that are global. It’s a sobering book to read if you ever thought we could make systems fault tolerant.

I haven't read it, but I'd take a leap to presume it's somewhere between the people that say "C is unsafe" and "some other language takes care of all of things".

Basically delegation.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#754
post #432

When you see the size if the impact across the world, the number of people who will die because hospital, emergency and logistics systems are down… You don’t need conventional war any more. State actors can just focus on targeting widely deployed “security systems” that will bring down whole economies and bring as much death and financial damage as a missile, while denying any involvement…

This is, in a way, why Kaspersky was banned in the US... "who scans the scanners?". Kaspersky is not that different from a Cloudstrike EDR product.

   https://news.ycombinator.com/item?id=4092187

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#755
I want to say the problem is that the industry has systematically devalued software testing in favor of continuous delivery and the strategy of hoping that any problems are easy to roll back.

But it's deeper than that: the industry realizes that, once you get to a certain size, no one can hurt you much. Crowdstrike will not pay a lasting penalty for what has just happen, which means executives will shrug and treat this as a random bolt of lightning.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#757
This might be a good time for folks to go back and watch the first episode of James Burke's Connections: The Trigger Effect

https://www.youtube.com/watch?v=NcOb3Dilzjc

Interconnected systems can fail spectacularly in unforeseen ways. Strange that something so obvious is so often dismissed or overlooked.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#758

Due to the scale I think it’s reasonable to state that in all likelihood many people have died because of this. Sure it might be hard to attribute single cases but statistically I would expect to see a general increase in probability. I used to work at MS and didn’t like their 2:1 test to dev ratio or their 0:1 ratio either and wish they spent more work on verification and improved processes instead of relying on tes…

As a tester, I'm frustrated by how little support testing gets in this industry. You can't blame bad testing if it's impossible to get reasonable time and cooperation to do more than a perfunctory job.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#760

Yet their stock tanked only a couple of dollars. They (and their customers) should face some rather unpleasant lawsuits. If you let others own your systems, you should not be allowed to provide critical infrastructure.

I don't think you're going to see as many lawsuits are you think. Most of these contracts probably state that they had to follow reasonable precautions for business continuity and data recovery. Having Crowdstrike in the path seems to have been a reasonable and potentially best practice before today's outage.

I don't think that companies are going to be held liable at all.

Post reply on HN