Sujet : Re: Computing is Complex (was: Re: A meditation on the Antithesis of the VMS Ethos)
De : ldo (at) *nospam* nz.invalid (Lawrence D'Oliveiro)
Groupes : comp.os.vmsDate : 29. Jul 2024, 22:36:37
Autres entêtes
Organisation : A noiseless patient Spider
Message-ID : <v89215$ld7e$1@dont-email.me>
References : 1 2
User-Agent : Pan/0.159 (Vovchansk; )
On Mon, 29 Jul 2024 12:58:51 -0400, Stephen Hoffman wrote:
... with occasionally-intractable results. Such as trying to stuff a
modern and robust password hash into an eight-byte field.
The Unix tradition of text-based config files (in this case, /etc/shadow)
wins again.
As for the referenced mess, CrowdStrike was basically testing in
production, and seemingly lacked any sort of continuous integration ...
They advertise it as a positive point, that they can respond to new
security threats faster than other companies--certainly faster than
Microsoft.
And yes, they do it by cutting corners on testing. I’ve seen many other
comments raising the hoary old “never implement new system changes on a
Friday” meme ... but what happens if the malware writers release a zero-
day on a Friday?