top 50 comments

sorted by: hot top controversial new old
[–] 164 points 2 years ago (2 children)

To avoid such issues in the future, CrowdStrike should prioritize rigorous testing across all supported configurations.

Bold of them to assume there's a future after a gazillion off incoming lawsuits.

  • source
  • hideshow 4 child comments
  • [+] 79 points 2 years ago* (last edited 2 years ago) (5 children)
  • [–] 88 points 2 years ago (2 children)

    and even Microsoft

    (x) doubt

    They had decades to consider Microsoft a liability. Why start doing something about it now?

  • source
  • parent
  • hideshow 3 child comments
  • [–] 21 points 2 years ago (2 children)

    Because cybersecurity is becoming more of a priority. The US government has really put their attention on it in the last few years.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 32 points 2 years ago* (1 child)

    I was in IT back in 2001 when the Code Red virus hit. It was a very similar situation where entire enterprises in totally unrelated fields were brought down. So many infected machines were still trying to replicate that corporate networks and Internet backbone routers were getting absolutely crushed.

    Prior to that, trying to get real funding for securing networks was almost impossible. Suddenly security was the hottest topic in IT and corporations were throwing money at all the snake oil Silicon Valley could produce.

    That lasted for a couple years, then things started going back to business as usual. Microsoft in particular was making all sorts of promises and boasts about how they made security their top priority, but that never really happened. Security remained something slapped on at the end of product development and was never allowed to interfere with producing products demanded by marketing with inherently insecure designs.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 14 points 2 years ago

    You're absolutely right. Everyone will be very worried and talk about the importance of security in the enterprise and yada yada yada until a cool new AI spreadsheet software comes out and everybody forgets to even check if their firewall is turned on.

    But with that being said, if you have been looking for a good time to ask for cybersecuity funding at your org, see if you can't lock down 5 years worth of budget while everyone is aware of the risk to their businesses.

  • source
  • parent
  • load more comments (1 reply)
  • [–] 12 points 2 years ago

    Contracts aren’t set in stone. Not only are those contracts modified before they are accepted by both parties, it’s difficult to limit liability when negligence is involved. CS is at worst going to be defending against those, at best defending against people dumping them ahead of schedule against their contracted term length.

  • source
  • parent
  • load more comments (3 replies)
  • [–] 35 points 2 years ago (3 children)

    They mean after Crowdstrike gets sold, the new company promises a more rigorous QA, and quietly rebrands it.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 82 points 2 years ago (3 children)

    Additionally, organizations should approach CrowdStrike updates with caution

    We would if we were able to control their "deployable content".

  • source
  • hideshow 6 child comments
  • [–] 46 points 2 years ago*

    I read on another thread that an admin was emulating a testing environment by blocking CrowdStrike IPs on their firewall for the whole network before each update, with the exception of a couple machines. It's stupid that he has to do this but hey, his network was unaffected

  • source
  • parent
  • [–] 8 points 2 years ago (1 child)

    Serious question, can you not? There isn't an option to...like...set a review system first?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 16 points 2 years ago (1 child)

    For antivirus definitions? No, and you wouldn’t want to.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 2 years ago (2 children)

    But it sounds like this added files / drivers or something, not just antivirus rules?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 26 points 2 years ago (6 children)

    Turns out it was a content update that caused the driver to crash but the update itself wasn't a driver (as per their latest update.)

  • source
  • parent
  • hideshow 8 child comments
  • [–] 22 points 2 years ago

    Found this post that explains what happened in detail: https://lemmy.ohaa.xyz/post/3522666

    As an application developer (rather than someone who can/does code operating systems) I was just left open-mouthed …

    Looks like they’re delivering “code as content” to get around the rigour of getting an updated driver authorised by MS. I realise they can’t wait too long for driver approval for antivirus releases but surely - surely - you have an ironclad QA process if you’re playing with fire like this.

  • source
  • parent
  • load more comments (4 replies)
  • [–] 79 points 2 years ago (10 children)

    But I've read so many posts on here about how Linux is flawless!

  • source
  • hideshow 12 child comments
  • [–] 24 points 2 years ago (2 children)

    Are you shocked that bad software can crash multiple operating systems or something?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 61 points 2 years ago (7 children)

    Nah, but there were some Linux evangelists claiming this couldn't possibly happen to Linux and it only happened to Windows because Windows is bad. And it was your own fault for getting this BSOD if you're still running Windows.

    And sure, Windows bad and all, but this one wasn't really Microsofts fault.

  • source
  • parent
  • hideshow 8 child comments
  • load more comments (6 replies)
  • [–] 7 points 2 years ago

    I'm not shocked at all, but there seems to be a very sizable number of people on Lemmy who think if people just used Linux there'd never be another problem or exploit again, which is ridiculous. Mac users used to feel the same way until the market share started to grow and all of the sudden you're seeing news of serious exploits.

  • source
  • parent
  • load more comments (8 replies)
    [–] 44 points 2 years ago (4 children)

    Companies don't really use Debian or Rocky in widescale production because they have no support.

    Now red hat or ubuntu is a different matter.

    Honestly though this does point out that this is a pattern of behavior on crowdstrikes part. This should have been the canary in the coalmine.

  • source
  • hideshow 8 child comments
  • [–] 8 points 2 years ago

    We use Alma, which is basically Rocky. Before that, CentOS. Lots of people don't need or want the expensive support contracts.

    OSS support though donations and commits is the way to go unless you get value out of those contracts (we would not).

  • source
  • parent
  • [–] 6 points 2 years ago*

    I don’t know about that. In the HPC space we use a lot of EL distros. Mainly Centos & now Rocky. Most of the nodes run the os in ram too. Though almost all those kind of systems have no internet connection and don’t use things like crowdstrike. I’ve worked for a few places where the only part of the company that used windows was the office staff eg accounting, hr, etc. everything else is/was using an EL distro or upstream of one eg Fedora. Those type of places usually don’t mess things like crowdstrike for a lot of different reasons eg the kind of data they’re processing and security requirements on that data.

  • source
  • parent
  • [–] 11 points 2 years ago (5 children)

    In April, a CrowdStrike update caused all Debian Linux servers in a civic tech lab to crash simultaneously and refuse to boot.

    And then, you boot their servers from a Linux Live USB, run TimeShift to restore the last system snapshot, refuse the latest patch from Cloudstrike and they all lived happily ever after.

  • source
  • hideshow 9 child comments
  • load more comments (1 reply)
    [–] 6 points 2 years ago (1 child)

    Because Linux sysadmins know to test a fucking update before applying to the whole company

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 5 points 2 years ago

    Microsoft already has a very bad reputation, so they will be blamed for every issue on their OS.

    Vista suffered from bad 3rd party drivers, then people proceeded to just dunk on M$ due to their already bad name. Despite Edge is nowadays just a different flavor of Chromium, people are still making "haha IE slow" memes, even those that still claim Google being the "savior of the internet".

  • source
  • load more comments
    view more: next ›