Fairly sure we don't just push down updates as soon as they are available. Often tested before a roll out. Unless something marked as security critical that needs pushed out asap due to a threat it seems bizarre this wasn't picked up in any testing. Especially when the actual issue is a complete BSOD of the system. Surely that gets picked up on the first batch of testing?
You're assuming it crashes on every single version of windows? I'd be shocked if thats the case. It might just be an older (more "stable") version of windows impacted. I can't imagine airlines and banks being on the latest and greatest version.
One thing that has shocked me is that they weren't on incremental rollouts. When I release new software for an environment that can't be thoroughly tested (i.e. android devices as there are so many different types) I'll do an incremental rollout of 20% per day and refresh the log table like I'm buying tickets for Glastonbury.
An anti virus company will be making 100s of releases a month - current products, previous products and the fact that the anti virus business is very dynamic considering its prey. The number of configurations for Windows software is insane - I have no doubts that this would have been thoroughly tested but you can't have 100% coverage for the millions (billions?!) of configurations for MS platforms - the hardware, the software, the different versions, the different drivers / applications on that machine. Will be really interesting to know what the actually problem was (if we'll ever be told) but bugs like this are constantly released into the wild. It's just this time it caused BSOD.
You're assuming it crashes on every single version of windows? I'd be shocked if thats the case. It might just be an older (more "stable") version of windows impacted. I can't imagine airlines and banks being on the latest and greatest version.
This is impacting Windows 10 and 11 and several different feature release versions (Even older long term service editions use my banks for airlines like you mentioned). The problem is that Crowdstrike sits between the OS layers and intercepts executing code BEFORE the OS get's it. That's part of the appeal of how it works.
This is also why the BSOD is such a major impact, this literally destroys the OS by installing a faulty SYS file. The only way to rectify is to restore in recovery mode and manually remove the SYS file from the devices. Great if you are all in one office, not so great if you are a global country (Like where I work) with users all over the world and no local support team to implement this "Fix". If you are running server in UEFI boot mode (and a lot will be) then you can't get into recovery mode.. so you better hope your backups work.
Bye Bye Crowdstrike. This is a billion dollar mistake.
This is impacting Windows 10 and 11 and several different feature release versions (Even older long term service editions use my banks for airlines like you mentioned). The problem is that Crowdstrike sits between the OS layers and intercepts executing code BEFORE the OS get's it. That's part of the appeal of how it works.
This is also why the BSOD is such a major impact, this literally destroys the OS by installing a faulty SYS file. The only way to rectify is to restore in recovery mode and manually remove the SYS file from the devices. Great if you are all in one office, not so great if you are a global country (Like where I work) with users all over the world and no local support team to implement this "Fix". If you are running server in UEFI boot mode (and a lot will be) then you can't get into recovery mode.. so you better hope your backups work.
Bye Bye Crowdstrike. This is a billion dollar mistake.
The question is who approved it. Lone programmers don't release code in this size IT firm, this is a massive failure that would involve multiple people, from the people who coded it, the testers and the managers who approved the code commits and patch releases
It's seriously damaging to their company that this made it out into the wild. Their clients will be expecting an investigation and explanation as to how this happened and presumbly(!) how it bypassed all their procedural controls.
I know I triggered a few people earlier, but DEI is increasingly a bain to technical companies and is now on a shoogly peg as to whether it's even demonstrably good for companies performance, or indeed the people it's meant to serve.
Privacy notices applicable to prospective candidates for employment with CrowdStrike, including job applicants, are available here.
www.crowdstrike.com
Whether it was the case here or not remains to be seen, but many of us working in the tech sector will have stories about DEI and the weird and wonderful impact it has on rectruitment practises and promotion decisions.
Whether it was the case here or not remains to be seen, but many of us working in the tech sector will have stories about DEI and the weird and wonderful impact it has on rectruitment practises and promotion decisions.
Thats every company now, even trumps secret service agents etc..
there's women about 5ft tall who can't carry the president, they can't body block him etc... all they can do is standard there and look DEI
Hell they would struggle to bathe and change bidens pampers
most people won't get past the head line or ms logo, they are now associated and blamed for a failure they have nothing to do with and the news channels should be taught a lesson for jumping to conclusions.
it's different when they are telling us not to be arm chair experts, don't jump to conclusions , don't listen to the conspiracies that 50% of the time are true anyway.
They should get their facts straight before they rush out a headline.
we went from professional journalism with standards to it being playground gossip
It's seriously damaging to their company that this made it out into the wild. Their clients will be expecting an investigation and explanation as to how this happened and presumbly(!) how it bypassed all their procedural controls.
I know I triggered a few people earlier, but DEI is increasingly a bain to technical companies and is now on a shoogly peg as to whether it's even demonstrably good for companies performance, or indeed the people it's meant to serve.
Privacy notices applicable to prospective candidates for employment with CrowdStrike, including job applicants, are available here.
www.crowdstrike.com
Whether it was the case here or not remains to be seen, but many of us working in the tech sector will have stories about DEI and the weird and wonderful impact it has on rectruitment practises and promotion decisions.
In my recent conversations with recruitment in my company, they've said how it can be difficult when they're told "we need a female here"... and no before anyone asks this was ref: generic tech/admin jobs, not anywhere it might matter.
Thats every company now, even trumps secret service agents etc..
there's women about 5ft tall who can't carry the president, they can't body block him etc... all they can do is standard there and look DEI
Hell they would struggle to bathe and change bidens pampers
In my recent conversations with recruitment in my company, they've said how it can be difficult when they're told "we need a female here"... and no before anyone asks this was ref: generic tech/admin jobs, not anywhere it might matter.
I was once at a place that recruiters almost blocked the recruitment of a physically disabled guy (who passed the competence test with flying colours) on the basis that they already had enough disabled people at the company. My pal was on the technical team and had to point out we don't recruit people because their disabled, but because they are competent.
50% female engineer recruitment was a thing for us for a year or two before that blew up in their face as well.
Given the way this software works and what it does, governments should not be using it. It would not comply with security requirements (not in the UK at least). Of course some will probably just do it anyway without checking..
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.