CrowdStrike CEO apologizes for tech outage
reuters.com
reuters.com
Apparently there was no vetting of this company before allowing them to mess with the Windows kernel. Apple has more vetting before they will let even a TODO list app into their app store.
What should Microsoft have done? Require CrowdStrike to have documented processes, and require periodic (like every 6 months) third-party auditing that they have the right processes, and they are complying with their own processes.
SOC 2 requires this, see https://en.wikipedia.org/wiki/System_and_Organization_Contro...
Apple removed support for kernel extensions in Big Sur [3]. Before that, you could sign kernel extensions as long as your Developer ID was permitted, without any requirement to submit the kernel extension to Apple for review [4]. Ironically, the main justification for Apple removing kexts was system stability, because a majority of companies are incapable of writing stable kernel extensions.
Nonetheless, Microsoft is historically more restrictive here than Apple.
[1] https://learn.microsoft.com/en-us/windows-hardware/drivers/k...
[2] https://learn.microsoft.com/en-us/windows-hardware/drivers/i...
[3] https://support.apple.com/en-us/120363
[4] https://developer.apple.com/help/account/reference/supported...
edit: I would like to add, Windows can't just remove kernel modules. It would be a bloodbath. Apple can only get away with it because they're Apple.
Microsoft may have very stringent controls on how kernel code is tested... but then then they allow a company that does not have similarly stringent controls to extend the kernel... what good is the care with which Microsoft tests kernel code?
You can't just blame the third party in this situation. Microsoft gets the blame at the end of the day, see: https://www.washingtonpost.com/technology/2024/07/20/microso...
You also don't need to be using Windows. Linux has kernel modules with no restrictions whatsoever (not even signing!), yet we run manage to run Linux stable in mission critical environments that we rely on every day.
I don't believe in the fear mongering here. Every competent engineer knew that security/antivirus vendors develop absolute trash code since the start of the century, and that extends to their kernel modules. It is no surprise- so why pretend to be surprised? With that said, I believe everyone is trying to pass blame, but at the end of the day, the blame resides solely with the organizations that purchased their product, or, the industry pressures that necessitated it.
I wouldn't blame the victim here. Microsoft endorses CrowdStrike's product so why would they not purchase it?
> or, the industry pressures that necessitated it
Those "industry pressures" are under Microsoft's control.
The guy who used to run Windows division at Microsoft now says: "From now, the only strategy that is not negligence is to move critical infrastructure to mobile devices." [1] Why can't Windows be just as safe as those mobile devices? It is Microsoft's fault that it isn't.
Windows and MacOS are historically much less restrictive than any Mobile OS. I am confident that if Microsoft and Apple attempted to be more restrictive, in the interest of security, it would invite further discussion of anti-competitive behavior and subsequently antitrust. In addition, if those restrictions were damaging to a company worth >75B (CrowdStrike).
I too wish it were different, but the cat is out of the bag.
Company is done like Solarwinds.
“We’re sorry for you, but think of us, we should all be sorry for poor us, too!”
He did ok at first but couldn’t help including themselves in the victims list.
And unless they are sending workers to reboot customers’ machines, they are not really helping as much as they imply.
That's the (further) thing that makes this sleazy beyond any measure: Not only the whole "feel sorry for us too!" thing, but how they are bending these statements to imply they have some part - any part - in any reparations. As mentioned upthread, the burden is being borne by others. Not them.-
"Kurtz’s total compensation was 237 times that of the median compensation of CrowdStrike’s employees and was more than that of five of the CEOs of the group of tech companies known as the Magnificent Seven.
The only more highly compensated CEOs among that group last year were Apple Inc.’s AAPL, +0.06% Tim Cook at $63.2 million and Microsoft Corp.’s MSFT, -0.74% Satya Nadella at $48.5 million.
Jensen Huang, CEO of Nvidia Corp. NVDA, -2.61% — which saw its stock soar 214.9% in the fiscal year through January — received $34.2 million in total compensation last year."
1. In 2010 you were CTO of McAfee when they shipped DAT file version 5958 which caused thousands of computers to crash. In 2024 you’re CEO of CrowdStrike which has caused millions of computers to crash. Why haven’t you learned from your mistake the first time and how many do you aim to crash in 2038?
2. McAfee was forced to sell itself to Intel as a result. Who do you think will buy CrowdStrike once this debacle is over?
3. You left McAfee because you saw a laptop on a plane take 15 minutes to upgrade McAfee’s software. What do you have to say to everyone who was on a plane that was grounded for hours because of the CrowdStrike upgrade?
4. You were paid 46 million USD for the previous year. How much do you think you personally owe in compensation for your latest blunder?
Lets really really hope none (get crashed).-
PS. I can totally see some semi-sentient AI going down, while - by then - we all depend on it for nearly everything, or, many things ...I don't think we can explicitly blame Kurtz for this one though.