CrowdStrike CEO: "defect in a single content update for Windows"
twitter.com
twitter.com
> Too funny: In 2010 McAffe caused a global IT meltdown due to a faulty update. CTO at this time was George Kurtz. Now he is CEO of #crowdstrike > https://www.zdnet.com/article/defective-mcafee-update-causes...
MCAF was a conglomerate of security products driven by sales of their AV suite, which might as well have been developed on a different planet for all that it mattered to the "security people". Same with SYMC.
In their defense, maybe they don't care about the service they claim to provide, and are just looking at it as a money machine black box.
Because on days like today, I do wonder….
People definitely died today. 911 was down for entire states, dozens of hospitals cancelling surgeries, pharmacies not able to serve customers etc
I'm starting to think these vendors are a higher risk and cost than not having them.
Of course it is a security incident. What planet is this guy on??
Gradual rollout? No no, we need the ability to respond to attacks and vulnerabilities fast.
Limiting the service's access and power, like we do for every other service? No no, we need to run as root and access every single user's SSH private keys and browser cookies. How else would we check they're encrypted, in line with your IT policy?
Secure boot? You'll have to bypass it for us so our 'security' kernel module can load, go into the BIOS and install this special key of ours.
Strict code reviews? We consider this bash script run as root to be 'configuration' rather than code.
Installing all software updates? No no, although we need to roll out our changes immediately, we don't support a new LTS Ubuntu release until it's been out for 6 months....
more discussion: https://news.ycombinator.com/item?id=41002195
A lot of IT staff, including myself, woke up to this and are focused on triage and restoration.
Once the noise globally has died down then I’ll expect an apology, among other things.
I’d rather a commitment to a thorough and public accounting of what went wrong. Not just something locked behind the portal login. They owe the world answers about why this wasn’t caught in testing.
https://www.reddit.com/r/crowdstrike/comments/ie8wos/sensors...
...but honestly these types of bugs have been inherent in software since day 1. We have had canary deployment models also for ages - so for this to happen tells us some things about the IT administrators of these companies that were impacted.
I don't think CrowdStrike bears much of the fault here. I recall this similar thing happening with Norton in the early 2000's and many others since then.
https://www.reddit.com/r/crowdstrike/comments/1e6vmkf/bsod_e...
Quote: "Multiple sensor versions apparently. I checked we haven't received a sensor update since the 13th so it must be something else they're updating to cause it. So much for our Sensor Update Policies avoiding things like this..."
Edit to add: Based on the Reddit comment and this thread, https://news.ycombinator.com/item?id=41004103, I would put this on CrowdStrike doing something that was unavoidable by the customer (CrowdStrike could have avoided this). But maybe there are some customer settings that could have prevented this.
I install software -> PC crashes and can't recover itself -> it's the Software's fault. Sure, I could have prevented it, but this doesn't change who's at fault.
Crowdstrike deployed a flawed update resulting in widespread harm. They are responsible for that harm. Companies failing to mitigate that harm through responsible preventive practices are also at fault.
Nothing will change. The people in charge of purchasing and deploying enterprise scale kabuki security software like this aren't interested in accountability or real world efficacy, it's entirely about crafting a narrative sufficient to remain employed. The game isn't security or practicality - box checkers gotta check boxes.