This situation is akin to the immune system overreacting and melting the patient in response to a papercut. This sometimes happens, but it's considered a serious medical condition, and I believe the treatment is to nuke someone's immune system entirely with hard radiation, and reinstall a less aggressive copy. Take from that analogy what you want.
Yes they do? And it’s more akin to a shared immune system than a single organism.
In this case, it’s not like viruses move fast relative to the total population of machines, but within the population of machines being targeted they do move fast.
Just one.
To the smart people below:
It’s clear to everyone that 70 minutes is not 1 month. The point is that it’s not a fair comparison: it would simply not have been possible to infect that many computers in 70 minutes: the internet infrastructure just wasn’t there.
It’s like saying “the Spanish flu didn’t do that much damage because there where less people on the planet” - it’s a meaningless absolute comparison, whereas the relative comparison is what matters.
Be better.
Computer security as a whole has improved, whilst the complexity of interconnected systems has exponentially increased.
This has made the barrier to entry for malware higher, and so means we no longer have the same historic examples of large scale worms targeting consumer machines that we used to.
At the same time the financial rewards for finding and exploiting a vulnerability within an organisations complex stack have greatly increased. The rewards are coupled to the time it takes to execute on the vulnerability.
This leads to what we have today: localised, and often specialised attacks against valuable targets that are executed as fast as possible in order to minimise the chance a target has to respond or the vulnerability they are exploiting to be burned.
Of course the “smart people belw” must know this, so it’s unclear why they are pretending to be dumb.
Yup, exactly that.
So what I'm saying it, it's beyond idiotic to combat this with a kernel-level backdoor managed by one entity and deployed across half the Internet. If anyone manages to breach that, they have a way to make their attack much simpler and much less localized (though they're unlikely to be prepared to capitalize on that). A fuckup on the defense side, on the other hand, can kill everything everywhere all at once. Which is what just happened.
It's a "cure" for disease that happens to both boost the potency of the disease, and, once in blue moon, randomly kills the patient for no reason.
The fact is that this does help organisations. Definitely not all of the orgs that buy Crowdstrike, but rapid defence against evolving threats is a valuable thing for companies.
So, individually it’s good for a company. But as a whole, and as currently implemented, it’s not good for everyone.
However that doesn’t matter. Because individually it’s a benefit.
Which is why I'm hoping that this incident will make both security professionals and regulators reconsider the idea of endpoint security as it's currently done, and that there will be some cultural and regulatory pushback. Maybe this will incentivize people to come up with other ideas on how to secure systems and companies, that don't look like a police state on steroids.
The underlying fault in this drama is Microsoft - third party code shouldn’t be able to have the impact it did, regardless of how it is loaded or what it does. Their commitment to supporting legacy interfaces has shot them in the foot here.
If HP pushed a dodgy printer driver (and if those still lived in the kernel) that nuked tens of millions of machines, would you be out here saying “regulators and security professionals need to re-consider printers”?
Microsoft will shit bricks, start to do something to isolate kernel modules, Crowdstrike will be the first shining user of this, and life will go on.
> infected millions of Windows computers worldwide within a few hours of its release
See: https://en.wikipedia.org/wiki/Timeline_of_computer_viruses_a...
And operating systems aren't that bad anymore. You don't have services out of the box opening ports on all the interfaces, no firewalls, accepting connections from everywhere, and using well-known default (or no) credentials.
Even stuff like the recent OpenSSH bug that is remotely exploitable and grants root access wasn't anything close to this kind of disaster because (a) most computers are not running SSH servers on the public internet (b) the exploit is rather difficult to actually execute. Eventually it might not be, but that gives people a bit of breathing space to react.
Most cyberattacks use old, unpatched vulnerabilites against unprotected systems combined with social engineering to get the payload past the network boundary. If you are within a pretty broad window of "up to date" on your OS and antivirus updates, you are pretty safe.
It just needs to infect 200k devices to get to the pot: hundred million dollars of ransomware.
(I expect this to tally up to double-digit billions and thousands of lives lost directly to the outages when the dust settles.)
The organization like MGM and London Drugs?
[SQL] Slammer spread incredibly quickly, even though the vulnerability was patched in the prior year.
> As it began spreading throughout the Internet, it doubled in size every 8.5 seconds. It infected more than 90 percent of vulnerable hosts within 10 minutes.
Worms are not technically viruses, but they can have similar impacts/perform similar tasks on an infected host.
Also keep in mind 8.5 million is likely the count of machines fully impacted and are not counting the machines impacted but were able to be automatically recovered.
Can you cite something? This is HN, not reddit.
> Also keep in mind 8.5 million is likely the count of machines fully impacted and are not counting the machines impacted but were able to be automatically recovered.
Do you have evidence of this? Please bring sources with you.
1. Crowdstrike didn’t test adequately
2. Viruses can move pretty fast once a foothold is gained
There is no real "speed limit" on malware spread.
Their precognitive intelligence suggested that a world wide attack was only moments away. The same precognitive system showed that the virus was so totally incapacitating that the only safe response was to incapacitate the server.
Knowing that the virus was capable of taking down every crowdstrike server, they didn’t waste time trying it on a subset of servers.
When you know you know.
The proper place would be Ring 1, which doesn't exist on Windows.
And being a kernel-level operation, it has the capability to crash the whole system before the actual OS has any chance to intervene.
Hmm, maybe you could have companies pay more to be in the first rollout group? That'd go over well too.