It craps the users PC while at it too.
I hope the company burns to the ground and large organizations realize it’s not a really great idea to run a rootkit at every PC ”just because everyone else does it”.
But the implementation (when running on user PC:s) is still half-baked.
My experience is using PC with Crowdstrike for daily software development. In that setting it’s quite terrible.
The server setting sounds a much more reasonable use.
* if not directly to all my thousands of PCs without testing, which is 100% a "me" task and not a "that cloud provider over there" task
Their ability to monitor and intervene against all software on the system also puts them in a position to break all software on the system.
more accurately: s/boss/most informed spy/g
It's likely that there have been multiple discussions about graceful failure at the load stage and decided against for 'security' reasons.
It's perfectly okay to make the protected services unavailable for security reasons, but still a management API should be available, and periodically the device should query whatever source of truth about the "imminent dangers". And as the uncertainty decreases the service can be made available again.
(Sure, then there's the argument against complexity in the kernel ... true, but that simply means that they need to have all this complexity upstream, testing/QA/etc. And apparently what they had was not sufficient.)