Liste des Groupes | Revenir à co vms |
On 7/21/24 4:41 AM, Subcommandante XDelta wrote:So not a driver.The problem here is that Crowdstrike pushed out an evidently brokenIt was not a kernel driver. It was a bad configuration file that
kernel driver that locked whatever system that installed it in a
permanent boot loop. The system would start loading Windows, encounter
a fatal error, and reboot. And reboot. Again and again. It, in
essence, rendered those machines useless.
normally gets updated several times a day:
https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/
The bad file was only in the wild for about an hour and a half. FolksThe impact was pretty huge.
in the US who powered off Thursday evening and didn't get up too early
Friday would've been fine. Of course Europe was well into their work
day, and lot of computers stay on overnight.
The boot loop may or may not be permanent -- lots of systems haveI have already seen speculation that IT security will decrease because
eventually managed to get the corrected file by doing nothing other than
repeated reboots. No, that doesn't always work.
The update was "designed to target newly observed, malicious named pipes
being used by common C2 frameworks in cyberattacks."
Most likely what makes CrowdStrike popular is that they are continuously
updating countermeasures as threats are observed, but that flies in the
face of normal deployment practices where you don't bet the farm on a
single update that affects all systems all at once. For example, in
Microsoft Azure, you can set up redundancy for your PaaS and SaaS
offerings so that if an update breaks all the servers in one data
center, your services are still up and running in another. Most
enterprises will have similar planning for private data centers.
CrowdStrike thought updating the entire world in an instant was a good
idea. While no one wants to sit there vulnerable to a known threat for
any length of time, I suspect that idea will get revisited. If they had
simply staggered the update over a few hours, the catastrophe would have
been much smaller. Customers will likely be asking for more control
over when they get updates, and, for example, wanting to set up
different update channels for servers and PCs.
Les messages affichés proviennent d'usenet.