▲ 586 ▼ CrowdStrike broke Debian and Rocky Linux months ago, but no one noticed (www.neowin.net) submitted 2 years ago by hal_5700X@sh.itjust.works to c/technology@lemmy.world 79 comments fedilink hide all child comments
[+] finley@lemm.ee 79 points 2 years ago* (last edited 2 years ago) (3 children) [removed by mod] permalink fedilink source parent hideshow 6 child comments replies: [–] rumschlumpel@feddit.org 88 points 2 years ago (2 children) and even Microsoft (x) doubt They had decades to consider Microsoft a liability. Why start doing something about it now? permalink fedilink source parent hideshow 4 child comments replies: [–] catloaf@lemm.ee 21 points 2 years ago (2 children) Because cybersecurity is becoming more of a priority. The US government has really put their attention on it in the last few years. permalink fedilink source parent hideshow 4 child comments replies: [–] Tinidril@midwest.social 32 points 2 years ago* (1 child) I was in IT back in 2001 when the Code Red virus hit. It was a very similar situation where entire enterprises in totally unrelated fields were brought down. So many infected machines were still trying to replicate that corporate networks and Internet backbone routers were getting absolutely crushed. Prior to that, trying to get real funding for securing networks was almost impossible. Suddenly security was the hottest topic in IT and corporations were throwing money at all the snake oil Silicon Valley could produce. That lasted for a couple years, then things started going back to business as usual. Microsoft in particular was making all sorts of promises and boasts about how they made security their top priority, but that never really happened. Security remained something slapped on at the end of product development and was never allowed to interfere with producing products demanded by marketing with inherently insecure designs. permalink fedilink source parent hideshow 2 child comments replies: [–] xyguy@startrek.website 14 points 2 years ago You're absolutely right. Everyone will be very worried and talk about the importance of security in the enterprise and yada yada yada until a cool new AI spreadsheet software comes out and everybody forgets to even check if their firewall is turned on. But with that being said, if you have been looking for a good time to ask for cybersecuity funding at your org, see if you can't lock down 5 years worth of budget while everyone is aware of the risk to their businesses. permalink fedilink source parent [–] Maeve@kbin.earth 3 points 2 years ago Hard to tell, sometimes. permalink fedilink source parent [–] Maeve@kbin.earth 3 points 2 years ago Literally lol'd. Thanks for that! permalink fedilink source parent [–] Brkdncr@lemmy.world 12 points 2 years ago Contracts aren’t set in stone. Not only are those contracts modified before they are accepted by both parties, it’s difficult to limit liability when negligence is involved. CS is at worst going to be defending against those, at best defending against people dumping them ahead of schedule against their contracted term length. permalink fedilink source parent [–] TheBat@lemmy.world -2 points 2 years ago (1 child) Oh so you can fire QA department, get absolutely destructive update to millions of systems across the globe and this gross negligence doesn't matter because of magic words in a contract? I don't think so. permalink fedilink source parent hideshow 2 child comments replies: [+] finley@lemm.ee 4 points 2 years ago* (last edited 2 years ago) (1 child) [removed by mod] permalink fedilink source parent hideshow 2 child comments replies: [–] TheBat@lemmy.world 1 point 2 years ago Then how else is their legal liability is limited? They killed off their QA department to chase profits which resulted in a broken product that crippled hundreds of organizations across the globe. They don't get to just shrug, say oopsie, and point at the contract. permalink fedilink source parent
[–] rumschlumpel@feddit.org 88 points 2 years ago (2 children) and even Microsoft (x) doubt They had decades to consider Microsoft a liability. Why start doing something about it now? permalink fedilink source parent hideshow 4 child comments replies: [–] catloaf@lemm.ee 21 points 2 years ago (2 children) Because cybersecurity is becoming more of a priority. The US government has really put their attention on it in the last few years. permalink fedilink source parent hideshow 4 child comments replies: [–] Tinidril@midwest.social 32 points 2 years ago* (1 child) I was in IT back in 2001 when the Code Red virus hit. It was a very similar situation where entire enterprises in totally unrelated fields were brought down. So many infected machines were still trying to replicate that corporate networks and Internet backbone routers were getting absolutely crushed. Prior to that, trying to get real funding for securing networks was almost impossible. Suddenly security was the hottest topic in IT and corporations were throwing money at all the snake oil Silicon Valley could produce. That lasted for a couple years, then things started going back to business as usual. Microsoft in particular was making all sorts of promises and boasts about how they made security their top priority, but that never really happened. Security remained something slapped on at the end of product development and was never allowed to interfere with producing products demanded by marketing with inherently insecure designs. permalink fedilink source parent hideshow 2 child comments replies: [–] xyguy@startrek.website 14 points 2 years ago You're absolutely right. Everyone will be very worried and talk about the importance of security in the enterprise and yada yada yada until a cool new AI spreadsheet software comes out and everybody forgets to even check if their firewall is turned on. But with that being said, if you have been looking for a good time to ask for cybersecuity funding at your org, see if you can't lock down 5 years worth of budget while everyone is aware of the risk to their businesses. permalink fedilink source parent [–] Maeve@kbin.earth 3 points 2 years ago Hard to tell, sometimes. permalink fedilink source parent [–] Maeve@kbin.earth 3 points 2 years ago Literally lol'd. Thanks for that! permalink fedilink source parent
[–] catloaf@lemm.ee 21 points 2 years ago (2 children) Because cybersecurity is becoming more of a priority. The US government has really put their attention on it in the last few years. permalink fedilink source parent hideshow 4 child comments replies: [–] Tinidril@midwest.social 32 points 2 years ago* (1 child) I was in IT back in 2001 when the Code Red virus hit. It was a very similar situation where entire enterprises in totally unrelated fields were brought down. So many infected machines were still trying to replicate that corporate networks and Internet backbone routers were getting absolutely crushed. Prior to that, trying to get real funding for securing networks was almost impossible. Suddenly security was the hottest topic in IT and corporations were throwing money at all the snake oil Silicon Valley could produce. That lasted for a couple years, then things started going back to business as usual. Microsoft in particular was making all sorts of promises and boasts about how they made security their top priority, but that never really happened. Security remained something slapped on at the end of product development and was never allowed to interfere with producing products demanded by marketing with inherently insecure designs. permalink fedilink source parent hideshow 2 child comments replies: [–] xyguy@startrek.website 14 points 2 years ago You're absolutely right. Everyone will be very worried and talk about the importance of security in the enterprise and yada yada yada until a cool new AI spreadsheet software comes out and everybody forgets to even check if their firewall is turned on. But with that being said, if you have been looking for a good time to ask for cybersecuity funding at your org, see if you can't lock down 5 years worth of budget while everyone is aware of the risk to their businesses. permalink fedilink source parent [–] Maeve@kbin.earth 3 points 2 years ago Hard to tell, sometimes. permalink fedilink source parent
[–] Tinidril@midwest.social 32 points 2 years ago* (1 child) I was in IT back in 2001 when the Code Red virus hit. It was a very similar situation where entire enterprises in totally unrelated fields were brought down. So many infected machines were still trying to replicate that corporate networks and Internet backbone routers were getting absolutely crushed. Prior to that, trying to get real funding for securing networks was almost impossible. Suddenly security was the hottest topic in IT and corporations were throwing money at all the snake oil Silicon Valley could produce. That lasted for a couple years, then things started going back to business as usual. Microsoft in particular was making all sorts of promises and boasts about how they made security their top priority, but that never really happened. Security remained something slapped on at the end of product development and was never allowed to interfere with producing products demanded by marketing with inherently insecure designs. permalink fedilink source parent hideshow 2 child comments replies: [–] xyguy@startrek.website 14 points 2 years ago You're absolutely right. Everyone will be very worried and talk about the importance of security in the enterprise and yada yada yada until a cool new AI spreadsheet software comes out and everybody forgets to even check if their firewall is turned on. But with that being said, if you have been looking for a good time to ask for cybersecuity funding at your org, see if you can't lock down 5 years worth of budget while everyone is aware of the risk to their businesses. permalink fedilink source parent
[–] xyguy@startrek.website 14 points 2 years ago You're absolutely right. Everyone will be very worried and talk about the importance of security in the enterprise and yada yada yada until a cool new AI spreadsheet software comes out and everybody forgets to even check if their firewall is turned on. But with that being said, if you have been looking for a good time to ask for cybersecuity funding at your org, see if you can't lock down 5 years worth of budget while everyone is aware of the risk to their businesses. permalink fedilink source parent
[–] Maeve@kbin.earth 3 points 2 years ago Literally lol'd. Thanks for that! permalink fedilink source parent
[–] Brkdncr@lemmy.world 12 points 2 years ago Contracts aren’t set in stone. Not only are those contracts modified before they are accepted by both parties, it’s difficult to limit liability when negligence is involved. CS is at worst going to be defending against those, at best defending against people dumping them ahead of schedule against their contracted term length. permalink fedilink source parent
[–] TheBat@lemmy.world -2 points 2 years ago (1 child) Oh so you can fire QA department, get absolutely destructive update to millions of systems across the globe and this gross negligence doesn't matter because of magic words in a contract? I don't think so. permalink fedilink source parent hideshow 2 child comments replies: [+] finley@lemm.ee 4 points 2 years ago* (last edited 2 years ago) (1 child) [removed by mod] permalink fedilink source parent hideshow 2 child comments replies: [–] TheBat@lemmy.world 1 point 2 years ago Then how else is their legal liability is limited? They killed off their QA department to chase profits which resulted in a broken product that crippled hundreds of organizations across the globe. They don't get to just shrug, say oopsie, and point at the contract. permalink fedilink source parent
[+] finley@lemm.ee 4 points 2 years ago* (last edited 2 years ago) (1 child) [removed by mod] permalink fedilink source parent hideshow 2 child comments replies: [–] TheBat@lemmy.world 1 point 2 years ago Then how else is their legal liability is limited? They killed off their QA department to chase profits which resulted in a broken product that crippled hundreds of organizations across the globe. They don't get to just shrug, say oopsie, and point at the contract. permalink fedilink source parent
[–] TheBat@lemmy.world 1 point 2 years ago Then how else is their legal liability is limited? They killed off their QA department to chase profits which resulted in a broken product that crippled hundreds of organizations across the globe. They don't get to just shrug, say oopsie, and point at the contract. permalink fedilink source parent