Some responsibility by design perhaps, but no blame for this event. But more, definitely not. Microsoft has nothing to do with applying the controls within Crowdstrike to prevent bad releases like this. That is all on CrowdstrikeThen I'd hold Apple responsible for creating a system that can be bricked by a random update from a 3rd Party.
I'm not entirely understanding the "Microsoft did nothing wrong!" meme. The global computing system just experienced a huge service outage and you all want to pretend the the system that allowed it to happen can do nothing about it? That if tomorrow another company puts rogue code into a software update this happens all over again?
Microsoft bears more responsibility for this than Crowdstrike, IMO. Just as I'd say Apple bears more responsibility in a similar situation. (and why I detest the EU et al putting their fingers into OS development).
So tomorrow, the world will be asking CrowdStrike how they can make the enterprise computing systems around the world safe from a similar occurrence going forward? No. The questions all go to Microsoft.Some responsibility by design perhaps, but no blame for this event. But more, definitely not. Microsoft has nothing to do with applying the controls within Crowdstrike to prevent bad releases like this. That is all on Crowdstrike
Yet low level access by cybersecurity software always has the possibility of incompatibility with MS patches. They can’t foresee their software acting improperly with operating systems underlying changes. Patches need to be delayed long enough to test for compatibility issues, not patched as soon as they get it for an enterprise environment.No third-party software update should *ever* be able to bring down an entire OS. This is a shockingly fundamental flaw.
What I find insane is the number of backend systems running Windows when something like Linux would be better suited. Not entirely a Mac vs PC thing but a world where companies use Windows instead of working on better solutions.it’s actually insane how much the world relies on Microsoft. some people will take a cheap kick at them (“buy a Mac” “apple for the win”) but Apple stands no chance of ever coming close to Microsoft’s dominance. Entire countries would grind to a halt without them. This is just a taster of what could happen
I know for a fact my work would never switch to Mac. They are using the bare minimum specs to run Windows 10. So yeah we aren’t about to buy Macs for everyone lmao. Also, it would be such a headache. People freak out at the slightest change so switching to a completely different OS sounds like a nightmare. I’m dreading the day when we move to Windows 11 (I actually like W11 and use it as my main OS).
My PC at work was fine today thankfully! Glad it’s the weekend so hopefully no issues on Monday.
But the most important thing is middle management risk. If a manager's department screws up, the manager is blamed. If the outsource company screws up the outsource company is blamed. When in fact the manager probably did not do their due diligence. Outsourcing is all about management risk avoidance.. . . .
"Outsourcing" was and still is a word managers like, because its the easy way to cut costs and it always does in their limited view. Depending on the operation outsourcing can increase costs too but often for different department, and that's why its never mentioned in reports. When television started to automate stuff and outsource some IT stuff later on, it did reduce the amount of employees in the operational department, but quadrupled the amount of IT personnel in other departments. At the time the IT was kind of booming and therefore it wasn't considered bad. But in the long run, costs went up more than they had reduced.
And the worst part of outsourcing... whenever there's a technical issue, the issue isn't resolved immediately. There's long path of communication between services desks/call centers, lengthy meetings of who's reponsible (finger pointing managers), lots of "filtered" messages from/to actual technicians and even stuff getting "lost in translation".
And since time is money, this costs even more money. But since these costs are on different tabs, it isn't visible that much. In fact, it's even considered a good thing... since it is "managed" properly (they think).
this is bad design, third party software shouldn't affect booting.
OS should be designed in such a way that it will be boot in any scenario unless the HDD is corrupt.
i don't think they save money by moving to cloud, they just move money from one budget/org to another.The name itself "CrowdStrike" really fits what's happening now.
Maybe, just maybe this is an eye opener for some companies causing them to rethink their IT choices. Maybe the industry will stop using the bloated Windows OS for everything and wiring it all to the internet.
And maybe, Microsoft will see that it should finally start to focus on good coding instead of rushing everything and bloating software with useless features. Maybe just stop with Windows OS entirely, it's just crap anyway. They should put all the energy into making fast working Office application that DO NOT RELY on cloud servers so much.
Many applications, like all the applications used in airports and transport, can easily run much more reliable on much smaller systems with Linux OS. And if the application needs more... use macOS systems.
"Outsourcing" was and still is a word managers like, because its the easy way to cut costs and it always does in their limited view. Depending on the operation outsourcing can increase costs too but often for different department, and that's why its never mentioned in reports. When television started to automate stuff and outsource some IT stuff later on, it did reduce the amount of employees in the operational department, but quadrupled the amount of IT personnel in other departments. At the time the IT was kind of booming and therefore it wasn't considered bad. But in the long run, costs went up more than they had reduced.
And the worst part of outsourcing... whenever there's a technical issue, the issue isn't resolved immediately. There's long path of communication between services desks/call centers, lengthy meetings of who's reponsible (finger pointing managers), lots of "filtered" messages from/to actual technicians and even stuff getting "lost in translation".
And since time is money, this costs even more money. But since these costs are on different tabs, it isn't visible that much. In fact, it's even considered a good thing... since it is "managed" properly (they think).
Part of the reason is that Windows shares a lot of its code base with previous generations of Windows. As a Forbes article said:this is bad design, third party software shouldn't affect booting.
OS should be designed in such a way that it will be boot in any scenario unless the HDD is corrupt.
The next version of Windows is expected to ship later this year as the Windows 11 2024 Update (also known as version 24H2.) This is, of course, a continuation of Windows 11, but this release is special as it's based on a new version of the Windows platform underneath, codenamed Germanium.
Windows allowed Crowdstrike to take control of Windows booting process.This has nothing to do with Windows/PC. It's a 3rd party app, running on Windows, whose job is to act as a security tool...the tool updated silently (as it does often) with a bad update by its own developers, rebooted, and crashed Windows. It's clear the developers at Crowdstrike did absolutely zero testing before pushing the update.
A similar tool could have been installed on non-Windows machines and had the same effect.
I've been running both Mac and Windows at home for 30+ years and neither systems have any 3rd party security tools and hence neither OSes have ever crashed (knock on wood) because of of a 3rd party security update. This tool appears to be aimed at corporate environments where the company really needs extra paranoid protection against all kinds of attacks that us home users normally will never see.
I'm sure all the "just get a Mac and you'll NEVER have to worry about ANY security problems FOREVER" comments have never considered there's a reason why Macs have never prevailed in the corporate world a)in employee user base and b)as the core infrastructure of businesses. I'm not knocking on Macs, but there are plenty of reasons why.
I mean it’s literally an antivirus app. You don’t need one for the Mac. But you certainly do for windows. Just sayingNot sure why people are crapping on Microsoft here. The issue is crowdstrike.
Then be ready to always leave attack vectors. Every decision is a compromise. Leaving the backdoor open to vulnerabilities is worse in my opinion, and would have a higher likelyhood as a risk than what happened today to customers from Crowdstrike.No third-party software update should *ever* be able to bring down an entire OS. This is a shockingly fundamental flaw.
I'm surprised no one has blamed Tim Cook for this.
Then an attacker needs to get in the supply chain. Which is possible and has happened before with application level software. But if corporate endpoint devices are that open that anyone can install software. Well they deserve what they’ve got coming, and are in the EU subjected to a fine or worse.Fully agree. Not sure how CrowdStrike integrates with Windows but I find it absolutely insane it could do something like this. Tells me that an attacker could exploit this for a massive-scale DoS attack.
Microsoft would say to switch to Microsoft Defender for endpoint combined with purview for DLP, and sell you more Azure servicesSo tomorrow, the world will be asking CrowdStrike how they can make the enterprise computing systems around the world safe from a similar occurrence going forward? No. The questions all go to Microsoft.
I don't think that security is a good reason for taking risks (or by-passing a process).Ok once again this wasn’t a windows update it was a security definition update. So when the next zero day comes out how long should a company stay vulnerable to said zero day before they patch? If they run patches in dev once a week then patch prod the following week and get compromised in that timeframe what will you say then?
I don't believe Apple grants third parties access to the kernel in the way MS did here. Worse here, was MS admitted that they do not review and/or certify the updates. That, to me, is a massive failure on Microsoft's front.Not sure why people are crapping on Microsoft here. The issue is crowdstrike. They have Linux and Mac versions of Falcon sensor too. They just happened to screw up the windows version today and push it to production past everyone’s security controls.
This could be Apple or Linux tomorrow.
So tomorrow, the world will be asking CrowdStrike how they can make the enterprise computing systems around the world safe from a similar occurrence going forward? No. The questions all go to Microsoft.