• Starting today August 7th, 2024, in order to post in the Married Couples, Courting Couples, or Singles forums, you will not be allowed to post if you have your Marital status designated as private. Announcements will be made in the respective forums as well but please note that if yours is currently listed as Private, you will need to submit a ticket in the Support Area to have yours changed.

Crowdstrike Bug Shuts Down… Basically Everything

ThatRobGuy

Part of the IT crowd
Site Supporter
Sep 4, 2005
28,318
17,072
Here
✟1,473,167.00
Country
United States
Gender
Male
Faith
Atheist
Marital Status
Single
Politics
US-Others
But it actually worked as programmed, didn't it?
Is this that meme of the guy pointing to his head and saying

"you can't get a virus,


if your computer won't boot up"


I'm sure someone probably has already made that one today...they had to have lol
 
  • Like
Reactions: wing2000
Upvote 0

iluvatar5150

Well-Known Member
Site Supporter
Aug 3, 2012
29,607
29,330
Baltimore
✟770,814.00
Country
United States
Faith
Christian
Marital Status
Married
Politics
US-Democrat
Is this that meme of the guy pointing to his head and saying

"you can't get a virus,


if your computer won't boot up"


I'm sure someone probably has already made that one today...they had to have lol
yeah, I saw something to that effect on reddit this morning
 
Upvote 0

ThatRobGuy

Part of the IT crowd
Site Supporter
Sep 4, 2005
28,318
17,072
Here
✟1,473,167.00
Country
United States
Gender
Male
Faith
Atheist
Marital Status
Single
Politics
US-Others
Anyway, as of 3:45 EST, our internal operations are back up and good to go, as are all of our clients except for 2 (their recovery has the extra wrinkle of them using BitLocker)
 
Upvote 0

RDKirk

Alien, Pilgrim, and Sojourner
Site Supporter
Mar 3, 2013
42,207
22,783
US
✟1,738,001.00
Faith
Christian
Marital Status
Married
Anyway, as of 3:45 EST, our internal operations are back up and good to go, as are all of our clients except for 2 (their recovery has the extra wrinkle of them using BitLocker)
Boooo on Bitlocker. It has its place, but not on my system. Bitlocker bricked one of my laptops...actually locked up the BIOS.
 
Upvote 0

RocksInMyHead

God is innocent; Noah built on a floodplain!
May 12, 2011
9,203
9,958
PA
✟434,229.00
Country
United States
Faith
Catholic
Marital Status
Single
Politics
US-Democrat
I don't either but I didn't realize how big Crowdstrike is, isn't it a fairly new company?
They've been around since 2012, so not particularly new.
 
Upvote 0

ThatRobGuy

Part of the IT crowd
Site Supporter
Sep 4, 2005
28,318
17,072
Here
✟1,473,167.00
Country
United States
Gender
Male
Faith
Atheist
Marital Status
Single
Politics
US-Others
I don't either but I didn't realize how big Crowdstrike is, isn't it a fairly new company?
They've been around for over a decade at this point...but yes, their global footprint is pretty massive (as we all witnessed yesterday, by hospital systems, airlines, and banking institutions all over the world getting negatively impacted)
 
  • Informative
Reactions: Laodicean60
Upvote 0

pgp_protector

Noted strange person
Dec 17, 2003
51,891
17,793
57
Earth For Now
Visit site
✟459,298.00
Gender
Male
Faith
Christian
Marital Status
Widowed
Politics
US-Others
Thankfully our company doesn't use CrowdStrike :)
But there were at least 3 failures on this
1) The Developer with the bad patch (happens to all of us)
2) The Reviewer who approved the Merge Request into master (They are doing software reviews before releasing right? )
3) QA who released the patch.
 
Upvote 0

RDKirk

Alien, Pilgrim, and Sojourner
Site Supporter
Mar 3, 2013
42,207
22,783
US
✟1,738,001.00
Faith
Christian
Marital Status
Married
Thankfully our company doesn't use CrowdStrike :)
But there were at least 3 failures on this
1) The Developer with the bad patch (happens to all of us)
2) The Reviewer who approved the Merge Request into master (They are doing software reviews before releasing right? )
3) QA who released the patch.
I don't think any of those were the problem, as I understand it. The software did precisely what it was designed to do: It discovered a vulnerability or change in Microsoft's kernel, was unable to fix it, so it shut the system down as designed.

The problem was that it was Microsoft's own change to their kernel that the software didn't know about.

Back when I owned a farm of 60 test servers and 50 production for a Fortune 50 company, it was my job on "Microsoft Tuesday" to run the Microsoft updates on my test servers (they ran various different production applications) to make sure the Microsoft update didn't break any of the company applications or server functions. The company policy was that every Microsoft update would be applied by that next Tuesday, so my response could never be "don't run the update," my response had be, "Hey, devs, these are the applications this update will break...I hope you've got plenty of Mountain Dew!"

Well, that applied to me, too, because whatever patches the devs developed, I still needed to test them in my test farm against the Microsoft update and then apply in "prod" before that next Tuesday.
 
Upvote 0

Belk

Senior Member
Site Supporter
Dec 21, 2005
30,715
15,179
Seattle
✟1,178,408.00
Gender
Male
Faith
Agnostic
Marital Status
Married
I don't think any of those were the problem, as I understand it. The software did precisely what it was designed to do: It discovered a vulnerability or change in Microsoft's kernel, was unable to fix it, so it shut the system down as designed.

The problem was that it was Microsoft's own change to their kernel that the software didn't know about.

Back when I owned a farm of 60 test servers and 50 production for a Fortune 50 company, it was my job on "Microsoft Tuesday" to run the Microsoft updates on my test servers (they ran various different production applications) to make sure the Microsoft update didn't break any of the company applications or server functions. The company policy was that every Microsoft update would be applied by that next Tuesday, so my response could never be "don't run the update," my response had be, "Hey, devs, these are the applications this update will break...I hope you've got plenty of Mountain Dew!"

Well, that applied to me, too, because whatever patches the devs developed, I still needed to test them in my test farm against the Microsoft update and then apply in "prod" before that next Tuesday.
We appreciate you guys being the guinea pigs. We started delaying our QA for a week after patch Tuesday to see if everyone else ran into issues.
 
Upvote 0

RDKirk

Alien, Pilgrim, and Sojourner
Site Supporter
Mar 3, 2013
42,207
22,783
US
✟1,738,001.00
Faith
Christian
Marital Status
Married
Here is an easily understood (and probably 99% correct) overview of what happened.

So, it looks like Cloudstrike Falcon got adminstrative permission from Microsoft to operate within the sacrosanct Microsoft kernel, but then gave itself permission to breach Microsoft's protection of the kernel to do a lot more in the kernel than Microsoft intended anything should do. I think that makes Cloudstrike Falcon a Trojan Horse by perfect definition.

 
Upvote 0