Live data from Hacker News

CrowdStrike Update: Windows Bluescreen and Boot Loops

old.reddit.com

951–960 of 1001 posts

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#951
This event raises the question: What is the liability of Crowdstrike given its erroneous update caused the meltdown, and the impact certainly had negative personal or business outcomes globally.

See for example 6000 flights cancelled or the many statements posted here regarding it negatively impacting healthcare and other businesses.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#952

This event is predicted in Sydney Dekker’s book “Drift into Failure”, which basically postulates that in order to prevent local failure we setup failure prevention systems that increase the complexity beyond our ability to handle, and introduce systemic failures that are global. It’s a sobering book to read if you ever thought we could make systems fault tolerant.

As an architect of secure, real-time systems, the hardest lesson I had to learn is there's no such thing as a secure, real-time system in the absolute sense. Don't tell my boss.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#953

Took down our entire emergency department as we were treating a heart attack. 911 down for our state too. Nowhere for people to be diverted to because the other nearby hospitals are down. Hard to imagine how many millions of not billions of dollars this one bad update caused.

> Hard to imagine how many millions of not billions of dollars this one bad update caused.

And even worse, possibly quite a few deaths as well.

I hope (although I will not be holding my breath), that this is the wake-up call we need to realise that we cannot have so much of our critical infrastructure rely on the bloated OS of company known for its buggy, privacy-intruding, crapware riddled software.

I'm old enough to remember the infamous blue-screen-of-death Windows 98 presentation. Bugs exist but that was hardly a glowing endorsement of high-quality software.. This was long ago, yet it is nigh on impossible to believe that the internal company culture has drastically improved since then, with regular high-profile screw-ups reminding us of what is hiding under the thin veneer of corporate of respectability.

Our emergency systems don't need windows, our telephone systems don't need windows, our flight management systems don't need windows, our shop equipment systems don't need windows, our HVAC systems don't need windows, and the list goes on, and on, and on.

Specialized, high-quality OSes with low attack surfaces are what we need to run our systems. Not a generic OS stuffed with legacy code from a time when those applications were not even envisaged.

Keep-it-simple-stupid -KISS-is what we need to go back to, our lives literally depend on it.

With the mutli-billion dollars screw-up that happened yesterday, and an as-of-yet unknown number of deaths, it's impossible to argue that the funds are unavailable to develop such systems. Plurality is what we need, built on top of strong standards for compatibility and interoperability.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#955

At one point overnight airlines were calling for an "international ground stop for all flights globally". Planes in the air were unable to get clearance to land or divert. I don't believe such a thing has ever happened before except in the immediate aftermath of 9/11.

the same time new showed up here, on wechat tiktok clone (moments i think, in English) was showing animations of the usa air traffic maps and how the tech blackout affected it. from those images i that it was huge.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#956

Remember, there's someone out there right now, without irony, suggesting that AI can fix this. There's someone else scratching their head, wondering why AI hasn't fixed this yet. And there's someone doing a three-week bootcamp in AI, convinced that AI will fix this. I’m not sure which is worse

when even jsDevOpsv can see the king is naked....

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#957
post #80

We are a major CS client, with 50k windows-based endpoints or so. All down. There exists a workaround but CS does not make it clear whether this means running without protection or not. (The workaround does get the windows boxes unstuck from the boot loop, but they do appear offline in the CS host management console - which of course may have many reasons).

stop the pandering. you know very well crowdstrike doesn't offer good protection to begin with!

everyone pay for legal protection. after it happens you can show you did everything, which means nothing (well now this show even worse than nothing), by showing you paid them.

if they tell you to disable everything, what does it change? they're still your blame shield. which is the reason you have cs.

... the only real feature anybody care is inventory control.

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#958

I've picked the perfect day to return from vacation. Being greeted by thousands of users being mad at you and people asking for your head on a plate makes me reconsider my career choice. Here's to 12 hours of task force meetings...

well, you did agree to go in business with crowdstrike, and base your company IT on windows, so...

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#959
post #951

This event raises the question: What is the liability of Crowdstrike given its erroneous update caused the meltdown, and the impact certainly had negative personal or business outcomes globally. See for example 6000 flights cancelled or the many statements posted here regarding it negatively impacting healthcare and other businesses.

we are bound to see the YouTube ads equivalent of late night spot ads for lawyers with accelerated audio "have you lost someone to the 2024, 2025 or 2029 crowdstrike global hospital outages? if so you may be entitled to compensation. DM law5237 on X to find more"

Re: CrowdStrike Update: Windows Bluescreen and Boot Loops

#960

Can someone explain to me why such systems need anti-virus in the first place? Windows has pretty good facilities for locking down the system so that ordinary users, even those with local admin rights, cannot run or install unauthorised code so if nothing can get in why would the system need checking for viruses? So why do most companies not lock down their machines?

easier to show a paid bill than to show true due diligence to your insurance when you're hit with ransomware.

that's the whole CS business model.

Post reply on HN