▲ 586 ▼ CrowdStrike broke Debian and Rocky Linux months ago, but no one noticed (www.neowin.net) submitted 2 years ago by hal_5700X@sh.itjust.works to c/technology@lemmy.world 79 comments fedilink hide all child comments
[–] EncryptKeeper@lemmy.world 16 points 2 years ago (1 child) For antivirus definitions? No, and you wouldn’t want to. permalink fedilink source parent hideshow 2 child comments replies: [–] AlecSadler@sh.itjust.works 6 points 2 years ago (2 children) But it sounds like this added files / drivers or something, not just antivirus rules? permalink fedilink source parent hideshow 4 child comments replies: [–] SeeJayEmm@lemmy.procrastinati.org 26 points 2 years ago (3 children) Turns out it was a content update that caused the driver to crash but the update itself wasn't a driver (as per their latest update.) permalink fedilink source parent hideshow 6 child comments replies: [–] wolfylow@lemmy.world 22 points 2 years ago Found this post that explains what happened in detail: https://lemmy.ohaa.xyz/post/3522666 As an application developer (rather than someone who can/does code operating systems) I was just left open-mouthed … Looks like they’re delivering “code as content” to get around the rigour of getting an updated driver authorised by MS. I realise they can’t wait too long for driver approval for antivirus releases but surely - surely - you have an ironclad QA process if you’re playing with fire like this. permalink fedilink source parent [–] AlecSadler@sh.itjust.works 3 points 2 years ago Oh, wow. permalink fedilink source parent [–] b161@lemmy.blahaj.zone 2 points 2 years ago (2 children) Do you know if the sensor update policy had been set to N-2 would this have avoided the issue? permalink fedilink source parent hideshow 4 child comments replies: [–] starneld@infosec.pub 7 points 2 years ago (1 child) Setting the update policy to N-2 (or any other configuration) would not have avoided the issue. The Falcon sensor itself wasn’t updated, which is what the update policy controls. As it turns out, you cannot control the content channel updates - you simply always get the updates. permalink fedilink source parent hideshow 2 child comments replies: [–] b161@lemmy.blahaj.zone -1 points 2 years ago 💀 Fucking hell CrowdStrike. permalink fedilink source parent [–] quinkin@lemmy.world 2 points 2 years ago No it would not. permalink fedilink source parent [–] mox@lemmy.sdf.org 4 points 2 years ago https://nitter.poast.org/patrickwardle/status/1814343502886477857 permalink fedilink source parent
[–] AlecSadler@sh.itjust.works 6 points 2 years ago (2 children) But it sounds like this added files / drivers or something, not just antivirus rules? permalink fedilink source parent hideshow 4 child comments replies: [–] SeeJayEmm@lemmy.procrastinati.org 26 points 2 years ago (3 children) Turns out it was a content update that caused the driver to crash but the update itself wasn't a driver (as per their latest update.) permalink fedilink source parent hideshow 6 child comments replies: [–] wolfylow@lemmy.world 22 points 2 years ago Found this post that explains what happened in detail: https://lemmy.ohaa.xyz/post/3522666 As an application developer (rather than someone who can/does code operating systems) I was just left open-mouthed … Looks like they’re delivering “code as content” to get around the rigour of getting an updated driver authorised by MS. I realise they can’t wait too long for driver approval for antivirus releases but surely - surely - you have an ironclad QA process if you’re playing with fire like this. permalink fedilink source parent [–] AlecSadler@sh.itjust.works 3 points 2 years ago Oh, wow. permalink fedilink source parent [–] b161@lemmy.blahaj.zone 2 points 2 years ago (2 children) Do you know if the sensor update policy had been set to N-2 would this have avoided the issue? permalink fedilink source parent hideshow 4 child comments replies: [–] starneld@infosec.pub 7 points 2 years ago (1 child) Setting the update policy to N-2 (or any other configuration) would not have avoided the issue. The Falcon sensor itself wasn’t updated, which is what the update policy controls. As it turns out, you cannot control the content channel updates - you simply always get the updates. permalink fedilink source parent hideshow 2 child comments replies: [–] b161@lemmy.blahaj.zone -1 points 2 years ago 💀 Fucking hell CrowdStrike. permalink fedilink source parent [–] quinkin@lemmy.world 2 points 2 years ago No it would not. permalink fedilink source parent [–] mox@lemmy.sdf.org 4 points 2 years ago https://nitter.poast.org/patrickwardle/status/1814343502886477857 permalink fedilink source parent
[–] SeeJayEmm@lemmy.procrastinati.org 26 points 2 years ago (3 children) Turns out it was a content update that caused the driver to crash but the update itself wasn't a driver (as per their latest update.) permalink fedilink source parent hideshow 6 child comments replies: [–] wolfylow@lemmy.world 22 points 2 years ago Found this post that explains what happened in detail: https://lemmy.ohaa.xyz/post/3522666 As an application developer (rather than someone who can/does code operating systems) I was just left open-mouthed … Looks like they’re delivering “code as content” to get around the rigour of getting an updated driver authorised by MS. I realise they can’t wait too long for driver approval for antivirus releases but surely - surely - you have an ironclad QA process if you’re playing with fire like this. permalink fedilink source parent [–] AlecSadler@sh.itjust.works 3 points 2 years ago Oh, wow. permalink fedilink source parent [–] b161@lemmy.blahaj.zone 2 points 2 years ago (2 children) Do you know if the sensor update policy had been set to N-2 would this have avoided the issue? permalink fedilink source parent hideshow 4 child comments replies: [–] starneld@infosec.pub 7 points 2 years ago (1 child) Setting the update policy to N-2 (or any other configuration) would not have avoided the issue. The Falcon sensor itself wasn’t updated, which is what the update policy controls. As it turns out, you cannot control the content channel updates - you simply always get the updates. permalink fedilink source parent hideshow 2 child comments replies: [–] b161@lemmy.blahaj.zone -1 points 2 years ago 💀 Fucking hell CrowdStrike. permalink fedilink source parent [–] quinkin@lemmy.world 2 points 2 years ago No it would not. permalink fedilink source parent
[–] wolfylow@lemmy.world 22 points 2 years ago Found this post that explains what happened in detail: https://lemmy.ohaa.xyz/post/3522666 As an application developer (rather than someone who can/does code operating systems) I was just left open-mouthed … Looks like they’re delivering “code as content” to get around the rigour of getting an updated driver authorised by MS. I realise they can’t wait too long for driver approval for antivirus releases but surely - surely - you have an ironclad QA process if you’re playing with fire like this. permalink fedilink source parent
[–] b161@lemmy.blahaj.zone 2 points 2 years ago (2 children) Do you know if the sensor update policy had been set to N-2 would this have avoided the issue? permalink fedilink source parent hideshow 4 child comments replies: [–] starneld@infosec.pub 7 points 2 years ago (1 child) Setting the update policy to N-2 (or any other configuration) would not have avoided the issue. The Falcon sensor itself wasn’t updated, which is what the update policy controls. As it turns out, you cannot control the content channel updates - you simply always get the updates. permalink fedilink source parent hideshow 2 child comments replies: [–] b161@lemmy.blahaj.zone -1 points 2 years ago 💀 Fucking hell CrowdStrike. permalink fedilink source parent [–] quinkin@lemmy.world 2 points 2 years ago No it would not. permalink fedilink source parent
[–] starneld@infosec.pub 7 points 2 years ago (1 child) Setting the update policy to N-2 (or any other configuration) would not have avoided the issue. The Falcon sensor itself wasn’t updated, which is what the update policy controls. As it turns out, you cannot control the content channel updates - you simply always get the updates. permalink fedilink source parent hideshow 2 child comments replies: [–] b161@lemmy.blahaj.zone -1 points 2 years ago 💀 Fucking hell CrowdStrike. permalink fedilink source parent
[–] b161@lemmy.blahaj.zone -1 points 2 years ago 💀 Fucking hell CrowdStrike. permalink fedilink source parent
[–] mox@lemmy.sdf.org 4 points 2 years ago https://nitter.poast.org/patrickwardle/status/1814343502886477857 permalink fedilink source parent