I do understand that main driver behind CrowdStrike installations is compliance checkbox. It still keeps the question, unless we assume pure corruption. But I've heard opinion from security experts, that this software really improves Windows security.
The world running on Windows is a monumental waste of resources and a huge security threat. This will happen over and over again.
The fact that even dummy little terminals that are strictly responsible for showing flight arrivals and departures was impacted by this is hysterical. Why was that not an android or chromeos device with an immutable filesystem, A/B blue green update strategies etc.
Exactly. It seems like we're deploying very capable and complex devices for a simple task which is showing a couple pages of text in a table format.
I have only seen people use them when windows it departments suddenly have to pretend to be cloud savvy, or when enterprisey infosec teams are looking for more vendors to bloat up their budgets. If it’s written in contracts, it’s not the customers demanding av on ephemeral cloud servers, it’s the home team bloating costs so they can cut them later for a raise and applause.
Aaaand whenever it goes that way, antivirals affect performance and stability with random problems, always hurting more than they help
The baseline is NIST guidelines but even that is a huge can of worms. It’s difficult to simply say “yes we’re compliant” especially in large organizations. https://www.cuicktrac.com/nist-compliance/nist-800-171-compl...
A lot of orgs get overwhelmed by this, and so they outsource the effort to a third party.
If that had happened, an attacker very well could have ended the entire internet as we know it. Imagine if that hacker merely used that backdoor to get into Windows Update servers, Google Play servers, or sent out a CrowdStrike update.
We were within weeks of nothing being safe.