6 ms·
Wouldn't want to be the guy who pushed this particular commit. It's ironic that the company that is supposed to prevent this sort of thing causes the biggest wo
by neverminder 2y ago
Wouldn't want to be the guy who pushed this particular commit. It's ironic that the company that is supposed to prevent this sort of thing causes the biggest worldwide outage ever. Crowdstrike is finished. Let's hope this will result in at least a small increase in desktop Linux market share.
- ciabattabread 2y agoCrowdstrike is finished? Ha! SolarWinds got the US government hacked by the Russians and they still exist.
- janice1999 2y agoInterestingly SolarWinds is headquartered in Austin and CrowdStrike recently moved there too.
- Bognar 2y agoWhy is that interesting?
- lucifargundam 2y agoImplying a geographic coincidence
- bhouston 2y agoThe SolarWinds stock has never recovered from its high before the hack. And it is on a downward trend.
- yuvadam 2y agoJust a small reminder that's it's never "the guy" and always "the process", or lack thereof.
- neverminder 2y agoYeah, but heads will have to roll for this one, the world will be calling for blood, so who better if not "the guy"?
- alserio 2y agothe management that enabled the process. And follow the chain to the top, they are paid very well to own the risks
- averageRoyalty 2y agoMore importantly, the companies that enabled auto update from a vendor to production rather than having a validation process. This sort of issue can happen with any vendor, penalising the vendor won't help with the next time this happens.
- gquere 2y agoWas there a way to not enable these channel updates? If so, would you still check all the mandatory security measures when being audited?
- averageRoyalty 2y agoThe way is to not install third party software with kernel level access that you can't stop pulling remote updates. How does that pass a security audit in the first place?
- josephg 2y agoIt’s both. If you’re an engineer and you push out shitty code that takes down 911 systems and ambulances, you f’ed up. Push back against processes that cause harm, or have the potential to cause harm. You are ultimately responsible for your actions. No one else. The excuse of “I was just following orders” has been dead and buried since WW2. Yeah, ideally management should know better. But management aren’t usually engineers. Even when they are, they don’t deal with the code on a day to day basis. They usually know much less about the actual processes and risks than the engineers on the ground.
- BrentOzar 2y ago> Crowdstrike is finished Unlikely, just as Solarwinds wasn't finished when they distributed malware that got government agencies hacked. You underestimate the slow turning radius of giant company purchasing departments.
- bhouston 2y agoAs I posted elsewhere, the SolarWinds stock has never recovered from its high before the hack. And it is on a downward trend.
- taneliv 2y agoEnterprise Linuxes also employ Crowdstrike or similar "security" products as mandatory part of their IT deployments. Often (always?) this is due to companies wanting certification for their secure processes, in order to sell to government or large corporations that require them.
- neverminder 2y agoCrowdstrike in their official statement said "Linux and MacOS not affected". Are there any reports stating otherwise?
- dathinab 2y agonot affected because the bug is in the windows specific code, not because it works so much different on linux
- tbgilson 2y agoYes indeed. That's kind of how Chernobyl happened.
- martopix 2y ago> Crowdstrike is finished Boeing is still there... we'll see
- galdosdi 2y agoWhy the fuck didn't MSFT just do blue/green canarying? No update should be rolled out to a billion devices at once until it's baked in a million devices for a bit, and that only after baking in 10,000 devices for a bit.
- BenjiWiebe 2y agoCrowdStrike is not MSFT. This also affected Linux installations with CrowdStrike installed, from what I've read.
- galdosdi 2y agoThanks, sorry, I commented before getting my facts in order. Comment still stands as applied to CrowdStrike.
- strunz 2y agoSource? I have not seen any thing about that and CS themselves say it's Windows only.
- toast0 2y agoCrowdstrike broke the update for Windows only this time. Although look around, they did a bad update on Linux earlier this year (although that only broke some of the Linux installs).
- hulitu 2y ago> Crowdstrike is finished. We thought about Microsoft the same way, some 15 years ago. /s