Siblings miss crucial life-extending treatment because of CrowdStrike outage
kiro7.com
kiro7.com
> Neither the software or any other Crowdstrike offerings are for use in the operation or aircraft navigation, nuclear facilities, communication systems, weapons systems, DIRECT OR INDIRECT LIFE-SUPPORT SYSTEMS, air traffic control, or any application OR INSTALLATION WHERE FAILURE COULD RESULT IN DEATH, SEVERE PHYSICAL INJURY, or property damage. SOFTWARE USER agrees that it is SOFTWARE USER’S RESPONSIBILITY TO ENSURE SAFE USE OF SOFTWARE AND ANY OTHER CROWDSTRIKE OFFERING IN SUCH APPLICATIONS AND INSTALLATIONS.
We don't really think long and hard enough about isolation of systems, and what levels of access they actually need to be able to do their tasks. It's entirely practical to build completely isolated networks. US Government (and most major governments) operate classified networks with air gaps, network diodes and the like. We don't have to make everything actually internet accessible, while still retaining the ability to get data in to such isolated networks.
The degree of reliability that is required is insane, I cannot read the article since I am outside the US, BUT if these are the terms of service and the product was used in any area the was excluded under these terms, the entity that used the product might very well be guilty of gross negligence.
My guess is that it's similar in this case. (Site is down)
“We have a tested backup paper procedure” - Yes, but have you tested being able to access that document when the system is down? Have you tested it when everyone’s workload is 5x normal during a real life incident, given that doing it on paper takes much longer and everyone’s already at the edge of their capacity on a normal day? Have you considered in a real life disaster scenario that something like 20% of the employees might just call out sick?
Of course not, but nobody asks that, so they just tick the “risk mitigated” box and don’t allocate any engineering effort to ensuring the system is robust.
I'm sure there are lesser measures that could work, but I'm exceedingly confident the above will be extremely effective.
> 8. NOTE ON JAVA SUPPORT. THE SOFTWARE PRODUCT CONTAINS SUPPORT FOR PROGRAMS WRITTEN IN JAVA. JAVA TECHNOLOGY IS NOT FAULT TOLERANT AND IS NOT DESIGNED, MANUFACTURED, OR INTENDED FOR USE OR RESALE AS ON-LINE CONTROL EQUIPMENT IN HAZARDOUS ENVIRONMENTS REQUIRING FAIL-SAFE PERFORMANCE, SUCH AS IN THE OPERATION OF NUCLEAR FACILITIES, AIRCRAFT NAVIGATION OR COMMUNICATION SYSTEMS, AIR TRAFFIC CONTROL, DIRECT LIFE SUPPORT MACHINES, OR WEAPONS SYSTEMS, IN WHICH THE FAILURE OF JAVA TECHNOLOGY COULD LEAD DIRECTLY TO DEATH, PERSONAL INJURY, OR SEVERE PHYSICAL OR ENVIRONMENTAL DAMAGE.
Quicktime also has a paragraph about not using them to operate nuclear facilities...
https://www.theregister.com/2008/12/16/windows_for_submarine...
https://en.wikipedia.org/wiki/Microsoft_Java_Virtual_Machine
These lessons need to cut in all directions. If you want to profit off of treating disease you should be held to a much higher standard. Passing the buck off to your AV provider is convenient in the current atmosphere but it's incredibly short sighted.
The consequences of which will be even higher costs for an incredibly marginal improvement in outcomes.
We spend ~$13,500/year/person at the moment, what's another few thousand to that number, for an average gain in a few life-days-per-person?
At some point, you have to accept that medicine is an unlimited money hole, and that it can always do better, and that people are going to die, and that you're going to have to draw the line at some arbitrary cost/benefit limit.
Well US is spending significantly more money than all other highly-developed countries with (on average across population) worse outcomes than many of them to show for it. Also there is a lot of variance inside the country (i.e. the cost of identical treatment might vary wildly depending on health/insurance/etc. provider) making cost/benefit analysis semi meaningless.
also would be interesting if crowdstrike was installed by a reseller who specializes in healthcare / airlines, not the hospital or airline itself
waivers not always enforced, per [1]
> Courts will hold overbroad liability waivers unenforceable on public policy grounds. ... injurers routinely ignore these holdings and persist in requiring would-be plaintiffs to sign such unenforceable waivers anyway
at least one federal case in florida[2] saying advertising a product as safe doesn't defeat the EULA, but it's florida
1. https://wp0.vanderbilt.edu/lawreview/wp-content/uploads/site...
So anything connected to the Internet? Shame on these lawyers.
Looks like Crowdstrike outsources their SDET/QA while keeping most software engineers stateside.
I generally don't have an issue with outsourcing, but it's obvious they're trying to save money on QA here. A few 200k SDETs could of probably caught this.
I see this at tons of companies, they see QA as less important...
You're arguing that on shoring QA would reduce the probability of something going wrong. I'm neither going to agree nor disagree.
However, I think the failure here is to mitigate the impact of something going wrong. Their rollout plan was fundamentally flawed - it shouldn't have taken out so many machines at the same time. It should have been rolled out in stages, with only 1 machine at most at any given customer receiving early versions.
It's best to assume a bug will get through 1 day or another, and spend some time mitigating the other axes too.
A higher paid QA might of told management, hey this is a very high risk change. If we're going to roll this out let's limit it to reduce the numbers of people affected.
If you on shore your core development, but outsource all of your QA, I'm forced to assume you value QA less.
I say this because this case a data file was changed. Probably done thousands of times without an issue.
QA would have never said "we need a staged rollout for this". Developers and those who set the process should do it.
But many companies don't view SDETs as equal partners in the developing process.
Anyway the entire world knows they cut corners here.
https://www.crowdstrike.com/blog/falcon-update-for-windows-h...
I wonder how many people didn't get so lucky?
For me, it's mildly annoying, but I've got an emergency supply. The lines of truly desperate people with much more urgent needs than mine were long, and there was a lot of crying and despair in the lobby. I can only imagine the situation in larger cities.
So ultimately it's not bona fide regulation taking away that last few weeks of slack and creating a needless mad rush, but rather the common setup of the "free market" unaccountably setting uniform policy in lock step, while you might get to choose which hold music you listen to.
In my mind, that is because the protection is what they're paid bags of cash to do.
If Crowdstrike was a charity I might find myself agreeable on your description of fair in favor of Crowdstrike.
I mean, just for _basic_ audits, you would hope to have that. If ransomeware can destroy your entire facility, than an angry insider can do much worse.
Error 451
It appears you are attempting to access this website from a country outside of the
United States, therefore access cannot be granted at this time.
Fortunately the archive.today link works.https://web.archive.org/web/20240720155219/https://www.kiro7...
My general practitioner once treated me during a power outage, all I had to do was come back and have my insurance scanned later.
The nation's weird affinity for pen and paper is nothing but Luddism. Once you have experience living in a country with good e-governance you'd roll your eyes at Germany and their love for faxes.
Good e-governance is incredibly difficult, which explains our love for faxes.
E.g. Microsoft faced a lot of scrutiny in the congress hearing in June, some people go as far as saying MS is a danger to the national security of the USA.
If the US, which is the home of these companies and can put pressure in ways the German government cannot, still can‘t force them to deliver secure systems, a fax ( at least an encrypted one) looks pretty attractive.
When the EU parliament still used faxes, the US at least hat to break into the offices and manually install components to the machines to get access.
And yet Estonia, a former impoverished communist country significantly less wealthy than Germany did it, and did it well. But no, Germans always have a laundry list bingo of FUD excuses as to why it can't possibly work. The bingo usually starts with "but m'uh privacy!" even though BAMF, Schufa and every law firm and government agency remotely interested in you can find out everything about you if they want to fine you for something.
2. Estonia is much smaller than Germany, and afaik much more centralised.
Estonia did a lot of things right, but countries like Britain, France and Germany can learn little from Estonia. The results just do not translate.
3. The German system as it is, is designed to make it slow to change. Even if hard right AFD would get the majority of votes in the next election, during one legislative term they could not change the system a lot. To do this, even the absurd long Merkle reign was not long enough.
3. might sound like a disadvantage, and it certainly is for the Germans, BUT if Germany would follow the likes of Hungary, Poland and Turkey, that would destabilise the whole continent.
There is a joke, that claim that the German anthem actually is:“ Stability, stability über alles“
Kind of an unrelated point. Using faxes and paper based burocracy won't save you from crappy politicians implementing crappy policies or a government going crazy.
Why are Germans so obsessed with correlating that crappy burocracy automatically means more political stability as some lame excuse for maintaining the inefficient and crap public burocracy? You can also have political stability with efficient burocracy. The key is political accountability and separation of democratic powers, to maintaining stability, nothing to do with using digital or paper for burocracy.
Germany seems to have not learned very much the first time, though, because it still keeps a hierarchical registry of everyone's religion and home address, and everyone in the bureaucracy has a "just follow orders" mentality.
This is a widespread misunderstanding. The AfD could drastically change the system if it had the sufficient number of seats (or a willing partner). There are very different pathways depending on what your goal is. Merkel was a conservative who had no interest in "changing the system a lot" (quite the opposite). The AfD wants to drastically change things like the immigration system.
It's a bit like how in the US the SCOTUS, thanks to the Trump appointed judges, effectively ruled that the President has a lot more power and is largely above the law (more so than these things already used to be the case before) but the Dems and Biden think the ruling is bad and thus refuse to do anything with that. They could also easily change the tune of the SCOTUS by appointing more judges but refuse to do so to avoid setting a precedent (as if the GOP needed it). "Centrists" often value decorum above succeeding at their stated goals.
There's an episode of Die Anstalt that plays through how the AfD could functionally abolish most of the constitution and democratic system within a single term if you want to know the specifics but it mostly comes down to abusing rules that exist because the system was created under the assumption that everyone would play fair (which is ironic given how things like the 5% hurdle are justified).
> There is a joke, that claim that the German anthem actually is:“ Stability, stability über alles“
I'm not sure where you heard that joke or whether this is a translation of the joke but the German anthem does not actually contain the words "über alles". The German national anthem consists of a single stanza of the Das Lied der Deutschen, the first stanza of which begins with "Deutschland, Deutschland über alles".
BTW it's a common misunderstanding that the "über alles" ("above all") part is why only the final stanza was used by West Germany for its anthem. However that was originally meant as an appeal to German nationhood and unification "above" the monarchs although it was later adapted as an expression of national superiority. The actually problematic part comes later in the first stanza where it names rivers as boundaries - not only did that include East Germany (a separate country) but also parts that were no longer part of either of the two countries.
As for why the second stanza didn't make the cut, I guess it was just a weird one to start a national anthem with as it celebrates German women, fidelity, wine and song and their "old respected fame" which at this point probably felt anachronistic and also wasn't as strong as the third stanza's "unity and justice and freedom" (with "unity" also having a new meaning when East Germany had become a separate country). That said, personally as a German I think it's a terrible anthem, especially given the melody was originally written to celebrate the Kaiser (first of the Holy Roman Empire and later of Austria-Hungary).
Personally I would have preferred the original East German anthem Auferstanden aus Ruinen, at least textually. It's also not great but at least it's better than digging through scraps to adapt an outdated poem set to a monarchist hymn.
This isn't true, IMO. German administrative offices in general don't talk to each other without your permission, with exceptions like the police. This is also the reason why it's e.g. a giant pain to change your name in Germany - everyone has their own independent database. Can you maybe clarify, please?
BAMF has no data of German citizens ("Bundesamt für Migration und Flüchtlinge", Federal Ministry for Migration and Asylum Seekers).
Schufa is a private company which only gets data from other companies, not the government. If you don't allow a company to give your data to the Schufa (which, to be fair, you have to do for many things), they cannot legally get the data (and in this case you could force them to delete it via GDPR).
German administrative authorities don't even have compatible databases. Like, if you go from Munich to Berlin, they have to basically enter your data manually. The software of the local municipalities (Einwohnermeldeämter) have no common API, and up until a few months, there wasn't even a unique ID for every citizen which could be used as a key in databases.
Law firms only can get some data if a court allows it.
If you get e.g. a ticket for speeding, and you didn't drive your car, but your spouse did and you don't tell them who the person in the driver seat on the picture is, there is nothing they can do (except forcing you to, from now on, keep a log book of who drives your car). They can't just call your local municipality and get the ID pictures of your spouse or something.
But there are areas where it definitely isn't just Luddism, especially in healthcare. See what happened in Finland [1]. Yeah, you can break into a GPs office and steal the physical data quite easily, but that doesn't scale, hacking a centralized service does.
(Sure, there are solutions which would be similarly resistant against hacks as paper - like saving the data on the actual insurance card. But those are not implemented - it has to be a centralized (often SaaS) solution, where hacks can scale nicely)
Sure, they work. At the pace of 1980's business speed. The U.S. is 4x bigger population and 6x gdp than Germany.
Siblings miss crucial life-extending treatment at Seattle Children’s because of CrowdStrike outage
They were one link in what appears to be a pretty fragile dependency graph.
For example, wouldn't it possibly make sense to also blame:
* Regulators / insurers / etc. who require passing the audits that mandate using services like this.
* System designers who failed to implement disaster recovery plans for this scenario.
* Auditors who failed to highlight this risk.
* Device vendors who made medical equipment susceptible to this kind of DoS.
* U.S. FDA / DEA who allowed and/or mandated systems with this kind of vulnerability.
* Voters (in democracies) who ultimately bear responsibility for their government's actions/inactions.
Etc.?
Presumably it was planned in advance, so the patients know the time of their appointment and the doctor knows what was planned, and everything necessary to physically perform the treatment is already prepared at the hospital. What's stopping them from doing it without filling it into a digital system? Why is it impossible to make a paper record and fill it into the computer system later?
If somebody was literally dying, would they stand around the computer like confused characters in a The Sims game who can't find the door, instead of saving the life? And if not, why is this less urgent case different?
I understand they would just postpone whatever can be postponed to save the headache, I don't get the stories about life/health threatening situations.
Note that I am not a doctor and have absolutely no specific knowledge beyond what is in the original article, but I am guessing at potential explanations.
Additionally, the article states that there is some "wiffle [sic] room" around the timing of the infusions. So it may be that the delay is not quite as serious as the title makes it sound.
Again, I understand that restoring a complex net of servers is hard and takes time. But they surely have local hospital IT admins for these absolutely critical computers who are always available on site and can do it individually - it's not like there will be more than a hundred of these at a particular hospital? Hack it a little if you have to, disable the SSO etc - all that can be fixed later.
I think it's always a mistake to outsource control of a mission-critical system, but that is exactly what large tech companies have been encouraging every organization that will listen to them to do for decades now
The culture of organizational IT is broken because a lot of powerful companies found it profitable to break it and leave something inadequate in its place
Again, we had all of this for a forest logging operation - is it too much to expect at a hospital?
Why did we get here? If you're installing kernel-level software you might as well run a kiosk that only runs presigned code and runs off a read-only system image. And a lot of the machines in question DO APPEAR to be kiosk settings (like hospital data entry terminals).
It's easy to sit back and armchair, I'm sure there will be many cybersecurity experts who would figuratively jump at my throat for suggesting that trusting a vendor to run a rootkit on your computers is a bit incompetent. LOL. :D
[0] AppleMobileFileIntegrity, the daemon and kext on iOS that enforces very strict code signing.
Restore from backup or reimaging fresh often means you need a working backup or image server, which at a lot of these places is also a Windows server and is likely also running the same endpoint protection, and is likely also boot looping.
Restore from zero isn't something any IT wants to do, and many of them aren't prepared to do it either.
Like it or not, hospital care revolves around the electronic medical records systems, and while Kaiser Southern California in the 90s was using amber screens and some sort of mainframe, afaik, almost everyone is on EPIC now, which is a windows application with all the baggage that contains. Even before EPIC took over Kaiser, they were running terminal emulators on Windows.
IMHO, it would be better for them to put together a ground up desktop distribution with exactly what they need, but that has user training costs and development costs.
It's preferable, from the corporate perspective, to have everything fail temporarily than to relinquish this level of workforce management.
If this is hard to imagine, just think of a Lyft driver from the perspective of Lyft Inc.
what you're saying is, if the less important service fails, of course the more important one will fail too.
With regard to this case, I don't know any specifics, but I can imagine tools require digital calibration, inventories not tracked outside digital systems, certain meds behind digital access control, and emergency response striained to the point where complicated non emergency procedures would be more risk than benefit.
And we were managing forests and waterways, not hospitals and human lives.
I'm happy nothing significant was hit over here in Poland; reading the main HN thread on the outage feels like reading war reports.
That's literally what we did to restart our forest logging machinery. Are human lives less critical than that?
Ad medicine - hence my question, I'd really like to know what's the blocker. So far it seems the blocker is bad IT management, regulation and liability, not impossibility to perform the treatment.
Again, from what I've seen, infusions are not just "throw it in an IV bag and wait".
Failed hardware is different, but hospitals likely have very few computers just 'lying around'. Especially the highly regulated machines, such as those which are attached to MRIs and the like.
CFR 21 Part 11 was the bane of my existence. Software that can be installed and configured in a matter of minutes? That's a six month project, at least. Sure, backups are great, but then you've got a significant process to get it back up and running.
These aren't early-2000 logging operations.
I see you'll never be convinced, but this is how modern operations work. Being a hospital (or other industry with heavy government regulations) make operations that much worse.
Hospitals also have limited resources in terms of IT staff. It's not a Azure army of operations staff that can rush out to every endpoint and click buttons.
When I was in helpdesk eons ago, I was "responsible" for roughly 300 - 400 endpoints, plus a handful of servers. As were all of the other helldesk techs. If something like this happened, there's simply not enough hands to go around as fast as everyone would like.
And due to CFR 21 Part 11, what you ask would be a non-starter.
Fail safe is the only acceptable failure mode for any critical system. Crowdstrike failed here, but they're not the only thing that can go wrong with computers. Where is the redundancy?
Also, air-gapping helps only so much when network dies and hospitals can't exchange patient information or send images from MRIs and X-rays to radiologists.
My dentist literally took a photo of my x-ray with his phone and sent it to to my orthodontist via Whatsapp and everything went quick and smooth, much faster than the official channels. Solutions to get a job done quickly and efficiently in case of emergency always exist, they're just not "by the book".
Hippa doesn't apply in Europe but GDPR, and I don't see how that would be in violation since my information was exchanged only between the two parties with my consent, on an encrypted channel.
They would only get into trouble if that info would leak in an identifiable way to unauthorized third parties and would cause damages (here there's no punitive damages like in the US). And people here tend to guard their WhatsApp chats pretty well since it's what everyone uses and it also contains their private chats so in a sense it can even be more secure than the official medical channels which are just more burocratic but offer no actual guarantee of more data security.
Say WhatsApp is found to have a security hole that has been leaking data to 3rd parties. What may be the fate of dentists / doctors that decided to use it an "encrypted channel" for medical records? Are doctors / dentists not fat targets for lawsuits? What might the guidance be from their lawsuit insurance policy?
If all of your computers go down your throughput is going to go down because other kinds of organization are going to be slower to do ad hoc… so you triage.
Bureaucracy certainly stops smart people from doing the right thing, but more often, it stops stupid people from doing the wrong thing. Hack away at bureaucracy at your peril.
The people writing hospital policies or regulations aren't thinking about individual patient outcomes unless some notable news story came out recently, and even then it's maybe the third or fourth priority on a list a hundred items long.
It’s not filling in new data that’s the problem - every person involved in treatment needs to be able to access the patient’s medical records to check for contraindications. Allergies and drug interactions are a quick way to kill someone when injecting drugs directly into their veins even if they’re already in a hospital.
At a major hospital there’s too many patients coming through and the data changes too frequently to keep paper backups.
They've been going every two weeks for the last five years. I doubt they wouldn't know what to do ...
Another comment in this thread quotes Crowdstrike's ToS which states that their software should not be used on critical systems.
I blame the hospital for its inability to operate with pen and paper in the event of a computer crash or a power outage.
It's all on a network for a reason. If it's on a network, it has to comply with all regulations that govern the service.
I'm sure if MS decides to remove the ability for third parties to write code that runs in kernel mode in the name of security/reliability/whatever, this site would immediately turn on a dime and say that Microsoft is evil for removing user control over their machines.
Hopefully folks learn from this.
But honestly windows admins don’t understand the systems they’re maintaining.. so this was inevitable.