CrowdStrike Explains Friday Incident Crashing Millions of Windows Devices (thehackernews.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 24 Jul 2024 11:52
https://sh.itjust.works/post/22696858

#cybersecurity

threaded - newest

kid@sh.itjust.works on 24 Jul 2024 11:53 next collapse

CrowdStrike report of the incident: crowdstrike.com/falcon-content-update-remediation…

PlutoniumAcid@lemmy.world on 24 Jul 2024 18:29 next collapse

Systems in scope include Windows hosts running sensor version 7.11 and above that were online between Friday, July 19, 2024 04:09 UTC and Friday, July 19, 2024 05:27 UTC and received the update.

Definitely incorrect. My machine was powered off by physical switch at that time. It was powered off at 17:00 the day before and powered up at 08:00 CEST / 06:00 UTC and promptly bluescreened.

sugar_in_your_tea@sh.itjust.works on 24 Jul 2024 21:02 collapse

Local developer testing

Hmm, didn’t think of that one…

staggered deployment strategy

Also a novel idea…

It’s like they’re catching up to best practices from 10 years ago, good job team!

mosiacmango@lemm.ee on 25 Jul 2024 05:08 collapse

Listening to literally any sysadmin would have had these practices already in play.

I wonder if any are in the building, of if it’s all devs and “platform engineers.”

kylian0087@lemmy.dbzer0.com on 24 Jul 2024 11:55 next collapse

Wouldn’t any internal testing have cought this issue at CrowdStrike?

Telorand@reddthat.com on 24 Jul 2024 12:39 next collapse

A smoke test, aka turn it on and “see if it catches fire,” would have caught this.

sugar_in_your_tea@sh.itjust.works on 24 Jul 2024 12:55 collapse

And a controlled rollout would’ve limited the damage.

Brkdncr@lemmy.world on 24 Jul 2024 15:54 collapse

Yes. Why would anyone trust Crowdstike after this? They’ve ignored foundational deployment steps.

boydster@sh.itjust.works on 24 Jul 2024 14:17 next collapse

But will you try actually installing the update on a machine or 50 to see if you bork things horrifically?

Crowdstrike: “We are really focused on unit testing right now”

I probably misread it, don’t mind my grumbling, rabble rabble rabble

[deleted] on 24 Jul 2024 21:02 collapse

.