Тёмный

CrowdStrike Destroyed The Internet 

ThePrimeTime
Подписаться 606 тыс.
Просмотров 288 тыс.
50% 1

Recorded live on twitch, GET IN
Big thank you to John Hammond!
/ @_johnhammond
/ _johnhammond
My Stream
/ theprimeagen
Best Way To Support Me
Become a backend engineer. Its my favorite site
boot.dev/?prom...
This is also the best way to support me is to support yourself becoming a better backend engineer.
MY MAIN YT CHANNEL: Has well edited engineering videos
/ theprimeagen
Discord
/ discord
Have something for me to read or react to?: / theprimeagenreact
Kinesis Advantage 360: bit.ly/Prime-K...
Get production ready SQLite with Turso: turso.tech/dee...

Опубликовано:

 

14 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 1,4 тыс.   
@_JohnHammond
@_JohnHammond 2 месяца назад
Man it was such a treat to finally join you on a stream -- thanks for having me, and looking forward to more! Will prep some ciphers for DEFCON 😎
@mechanicalfluff
@mechanicalfluff 2 месяца назад
good opportunity for Huntress ads "Hey, Remember this? Wasn't us ;) "
@LzX000
@LzX000 2 месяца назад
@_JohnHammond is the man!
@abdullahsiddique6393
@abdullahsiddique6393 2 месяца назад
Dream team!
@FilipCordas
@FilipCordas 2 месяца назад
@@mechanicalfluff it's the same terrible shit made to get money from corporate budgets that are tax exempt, later the same people that decide to buy the software start to work for the companies that sell this crap isn't a bad system.
@js-gc2hk
@js-gc2hk 2 месяца назад
Hey I'm on the windows 11 dev build and I recently had an update and got the same error blue screen booting up my PC and it won't allow me to get in safe mode or even on my windows password lock screen and I've restarted many times and even did a fresh install of Windows 11 with the automatic repair and did nothing to fix the issue but I kept my files but what it tells me what failed: rcbottom.sys on the blue screen I can get in my bios settings and that's it I need help please 🥺 I don't want a full clean install and lose all my files with pictures this is my home gaming PC and I hope my storage and hope my RTX 4090 won't get bricked from this. Edit I don't even know how crowd strike is affecting my PC I never heard of it till now
@Michael-pw6qk
@Michael-pw6qk 2 месяца назад
"I don't always test code, but when I do, I do it in Production." - CrowdStrike
@b_two
@b_two 2 месяца назад
and on a friday
@nestorguemez4846
@nestorguemez4846 2 месяца назад
My company does deployments on friday too ☠️
@user-kt5hx6hl7m
@user-kt5hx6hl7m 2 месяца назад
I did a deployment today as well. But it was a fix to spaces in a free text search and I tested it in dev, staging and prod. Very minimal and good testing. But a rollout to millions of machines? Why not?
@damnhatesyou
@damnhatesyou 2 месяца назад
@@b_twoif fast food and essential workers can operate on the weekends white collar folks can too.
@Deimos4500
@Deimos4500 2 месяца назад
That happened with a tester team that decided to not test the cases and It was showed on production
@igormoraru9514
@igormoraru9514 2 месяца назад
They found the ultimate protection against malware. No working machine = no malware
@NODGD
@NODGD 2 месяца назад
Can't get hacked if the blue screen of death is in the way
@crispybatman480
@crispybatman480 2 месяца назад
Think of all the data not being leaked!
@hackysmack
@hackysmack 2 месяца назад
@@NODGD You can still get hacked in the half-second before CS hangs you - that's the window CS expects you to use to get the fix.
@robinvlad141
@robinvlad141 2 месяца назад
Can't get Infected nor Hacked. 😂
@the_real_ch3
@the_real_ch3 2 месяца назад
The Skynet solution
@JamesWilsonbillygoatbattle
@JamesWilsonbillygoatbattle 2 месяца назад
"Hey, boss, I removed this useless regression test to save time. It was called 'boot just one single machine"
@abramgalleg
@abramgalleg 2 месяца назад
This is what i was saying all day on repeat. Love when they didn’t test on a SINGULAR machine
@ficolas2
@ficolas2 2 месяца назад
My bet is, the problem happened on the push, or on the build, after the tests. That's why you only build once, and test that. You never build after the fact
@rutgerhoutdijk3547
@rutgerhoutdijk3547 2 месяца назад
Let's rollout a kernel level patch globally on a Friday Yolo 😂
@MatheusOliveira-er4gq
@MatheusOliveira-er4gq 2 месяца назад
😂😂😂
@skunkwerx9674
@skunkwerx9674 2 месяца назад
Let’s also not test it at all before deploying it to all our computers. All these companies just outed themselves as vulnerable to supply chain risk. They could have prevented this by simply testing it in a limited environment first. At some point both parties are culpable.
@mattytee2893
@mattytee2893 2 месяца назад
4:50pm Friday in New Zealand.
@km077
@km077 2 месяца назад
"Yo, Mike, did you test this sht?" "I tested the minor before. This one is basically the same." "full send it?" "FULL FRlCKlNG SEND IT!"
@ckmichael8
@ckmichael8 2 месяца назад
​@@skunkwerx9674No you cannot test it in a limited environment, they just push the kernel patch in the background to ALL devices with no admin or user action. I work in one of the biggest bank of the world and it is like all of a sudden all APAC Windows machines got BSOD and no one can do the work anymore. They actually thought that was some sort of cyber attack.
@martijn3151
@martijn3151 2 месяца назад
Kudos to the one that came up with the name Crowdstrike; spot on!
@kahnfatman
@kahnfatman 2 месяца назад
I thought CrowdStrike is an infamous hacker group like Anon International
@JeremyAndersonBoise
@JeremyAndersonBoise 2 месяца назад
@@kahnfatmanThey are now!
@km077
@km077 2 месяца назад
*foreshadowing*
@stevengill1736
@stevengill1736 2 месяца назад
"striking the crowd since 2004"
@kacperkonieczny7333
@kacperkonieczny7333 2 месяца назад
Worldstrike would be a better name
@4bSix86f61
@4bSix86f61 2 месяца назад
They should win a Guinness World Record for blue screening the whole world 😂
@Yamahog
@Yamahog 2 месяца назад
Add to this a "Carrington -Event style solar flare at the same time..... ", ...... Exit Light , Enter Night .... Take My Hand., .... We're off to Never Never Land .......
@momofomomofo
@momofomomofo 2 месяца назад
CrowdStrike needs kernel space to override syscalls like reading files, mmap, etc. Rootkits and other malware will rewrite syscalls as well. There is no way to intercept calls/access memory for other processes in userspace, and AV is perpetually trying to be "on top", hence the kernel-mode drivers. All AV works like this - once it's hooked in, processes that e.g. read files will be accessing it through a rewritten fopen() syscall that goes through CrowdStrike's driver. "Channel update" means CrowdStrike's updates - they pushed a new DLL to their release channel, machines downloaded and applied it. There was some kind of error where the file that was pushed (to CDN?) was corrupted, and CrowdStrike's "channel updates" don't employ checksums, so machines just downloaded, applied it, and BSOD'ed cause the driver was invalid. Very hard to imagine how their process possibly could have done an immediate rollout of a corrupt file to everybody... Clearly not a great test engineering culture... Why is kernelmode AV needed? If I get RCE on Windows or Linux, I can install background software. It doesn't make a difference if it's Windows or Linux, but there's much more money in mass-targeting Windows machines with e.g. ransomware whereas Linux is usually more specifically targeted with 0day exploits. With AV you have a shot at preventing this without patching the software (CrowdStrike is essentially patching it without relying on the vendor); on Linux you're definitely vulnerable until you patch, but Linux also has a much better patching culture ¯\_(ツ)_/¯ Basically it's not exactly clear whether it's good to have something like this or not, but shitty software is the problem in both cases (rewrite it in Rust lmao)
@RmAndrei93
@RmAndrei93 2 месяца назад
That's the best explanation ive read . Now it make total sense . Thank you
@onecentnickel
@onecentnickel 2 месяца назад
I was curious what the specifics were, that makes sense
@dead-claudia
@dead-claudia 2 месяца назад
worth noting that in kernel space, not even rust can save you from everything. it can make memory easier to wrangle, but it doesn't protect you from other critical faults. a rust panic in kernel space can only sensibly be mapped to an os crash - you REALLY don't want that. and if i'm understanding the issue at play, the os would've crashed either way here, either due to a memory access error or due to a failed bounds check assertion.
@monad_tcp
@monad_tcp 2 месяца назад
I think the real problem is lack of a solid strategy of machine imaging and relying too much of "pet installations" Ideally you should be able to redeploy your entire infrastructure on clean slate hardware remotely. I was doing that in 2012 on my in premises. I could remote Ina server reboot it, feed it's PXE and the entire OS would reimage to a known image. On top of that I was using virtualization so I could move the VM to another hardware.
@vitalyl1327
@vitalyl1327 2 месяца назад
@@momofomomofo their update process is an utter crap and those who designed.it.are criminally negligent. And Microsoft is equally liable here for not making overlay updates.a default. They don't even have an overlay fs to start with!
@Israel220500
@Israel220500 2 месяца назад
What's funny is that 2 days ago the company I work in (a bank) released a post on it's internal network celebrating the acquisition of the "Falcon" tool to make the work computers more secure. I guess it was a really bad timing
@kacperkonieczny7333
@kacperkonieczny7333 2 месяца назад
"So ironic"
@nisonatic
@nisonatic 2 месяца назад
That Falcon driver took down our whole Falcon company the Falcon day we installed it.
@emanuelgitterle1834
@emanuelgitterle1834 2 месяца назад
I'm also working for a bank. My deepest regrets mate! :(
@arvetemecha
@arvetemecha 2 месяца назад
sorry for your loss
@Israel220500
@Israel220500 2 месяца назад
@@arvetemecha I mean it was not really big deal, just a part of the office PCs and laptops were affected, but the suport team quickly released a note explaining the recovery procedure. We are not crazy enough to try to use Windows for servers or critical parts of the business.
@privacyvalued4134
@privacyvalued4134 2 месяца назад
Just so you know, Prime says "server" but this affects clients too. That is, hundreds of thousands of SCCM deployed laptops and workstations...if not millions. Everywhere. If you are doing remote work and your work issued laptop is running this trash, then it's hosed. But so is your whole organization.
@FilthyHyena
@FilthyHyena 2 месяца назад
You don't have this by default if you have sccm. It is still a paid service. Plenty of companies running AAD were unaffected.
@megaing1322
@megaing1322 2 месяца назад
Yep, I am surprised John didn't push back against this. Having an antivirus on a full on server is one thing that maybe could be criticized, as Prime did, however, antivirus and kernel-level monitoring on enduser devices is quite a bit more reasonable.
@monad_tcp
@monad_tcp 2 месяца назад
​@@megaing1322 Windows Server don't even need Windows Defender. But I know why people would do it. A lot of Windows Server is running desktop software and serving it via RDP. So users are actually using the desktop . Ideally everyone would use Windows Server Core which is reduced and more like a proper server.
@OpinionatedSkink
@OpinionatedSkink 2 месяца назад
@@megaing1322 having antivirus on servers is unfortunately a PCI DSS and ISO27001 requirement, believe it or not. If not running AV, then you'd have to show adequate vulnerability/threat scanning capability via other means.
@CallousCoder
@CallousCoder 2 месяца назад
The businesses hit by this also show their immaturity. They blindly trust pushed updates, without backing up or snapshotting their crap... IDIOTS! They had no manual backup processes in place to keep business going -- albeit slower but going. This dependency on computer systems is eerie. What if power goes down for 48-72 hours? Which also means no diesel trucks could replenish your diesel generators (oh year which as of 2035 are not allowed by the eco-police in the EU either :/)
@MrXperx
@MrXperx 2 месяца назад
My wife works for an insurance company as a software engineer. She and her team has been asked to report to work today (Saturday) to help the IT guys fix the PCs affected. The number of machines affected is too many for just one team to fix.
@CallousCoder
@CallousCoder 2 месяца назад
You as a team were too stupid to completely rely om auto updating the whole company in one go, you go and work on sunday! Will make you feel the error of your ways! NEVER TRUST AN UPDATE! NEVER AUTO UPDATE! At the very least click, okay start update
@mwwhited
@mwwhited 2 месяца назад
I’m a software engineer and my response would be “nope”. CrowdStrike is garbage, I’ve warned it was garbage and haven’t been in IT support or even production support for over a decade (almost 2). The CIO and CSO that thought a garbage startup on the conference circuit can handle IT security can go help… but I’m enjoying my weekend. It’s bad enough CrowdStrike and Threatlocker DoS my C compiler against a “Hello World app”. Those that made the decision to install that trash can fix it themselves.
@gixxerblade
@gixxerblade 2 месяца назад
Praying for her 🙏
@absurdengineering
@absurdengineering 2 месяца назад
That’s why enterprise desktops need IPMI. And that exists. All this can be scripted via IPMI and BMC on the servers. Same goes for Bitlocker. All scriptable.
@JackDespero
@JackDespero 2 месяца назад
3:00 Not knowing Ryanair and being confused about it might be the most American thing I have heard in a while. It is not the Irish Spirit, it is more like Spirit is the American Ryanair. Spirit carries around 20 million passengers per year. Ryanair carries 180 million.
@txbre8758
@txbre8758 2 месяца назад
Yeah as an American, Ryanair was way better than any of our cheap airlines tbh
@Hooverdreng
@Hooverdreng 2 месяца назад
Ryanair are the true trailblazers of treating customers and staff like absolute dirt.
@dastron6939
@dastron6939 2 месяца назад
Lmao I thought the exact same thing! Wild how all of us over here probably know about a decent amount of American airline companies but they don’t know about Ryanair (not even from the countless memes)
@theairaccumulator7144
@theairaccumulator7144 2 месяца назад
@@Hooverdreng they're better than american budget airlines at least
@angusjohnston7172
@angusjohnston7172 2 месяца назад
​@@Hooverdrengif you want to get from airport a to airport b in the cheapest way possible, you choose ryanair
@aisle_of_view
@aisle_of_view 2 месяца назад
I'm loving this. All the times I had to explain to management why we should wait a few days before implementing an update, only to be met with blank stares. lol
@jeroenvermunt3372
@jeroenvermunt3372 2 месяца назад
Finally you have a good example they should be able to agree with. Sadly it will only work for 3-5 years, then they will counter it with "that was so long ago, this shouldn't happen with today's technology"
@JBravo69
@JBravo69 2 месяца назад
Yeah it’s to common. Everyone is nervous when you push an upgrade…
@Umbrellas0
@Umbrellas0 2 месяца назад
I flew American home from a commissioning trip today. Luckily my flight was only delayed an hour, but there was a like 250+ft line from almost the end of the terminal up the customer service desk, and I shit you not, most of the monitors in the terminal were blue screened lol
@brianteague8031
@brianteague8031 2 месяца назад
I feel so bad for the engineer who made this mistake. He's probably going to lose his job even though there were a 100 different failure points from management, procedures, redundancy, and QA testing point of view. I would never want to work for a company like this where one mistake could literally lead to someone dead in a hospital.
@Asto508
@Asto508 2 месяца назад
If they fire some developer over this, then he dodges future bullets. I'm 100% sure this was some manager's fault who thought QA, staging and safe roll out is dragging away from his annual bonus. Fairly sure the engineers at CS already saw something like this coming. Everyone in the business knows how this works.
@dead-claudia
@dead-claudia 2 месяца назад
issues like this in large software companies don't normally result in the dev's individual termination unless their corporate is chronically micromanagey, and i've never gotten that impression of cloudstrike. more likely, the dev's boss will be in serious hot water, if not their boss's boss (or both). also cloudstrike isn't known to be a garbage fire of instability - that's part of what made this so shocking to everyone. many IT people _liked_ the software, and that's an honor few apps and services get to enjoy.
@MereAYT
@MereAYT 2 месяца назад
​@@Asto508This. The developer is too often a scapegoat for bad management and bad processes.
@ayushpurohit8266
@ayushpurohit8266 2 месяца назад
0:32 "Security Expert John Hammond" Something ain't Jurassicing in my park
@petaflop3606
@petaflop3606 2 месяца назад
wdym?
@ayushpurohit8266
@ayushpurohit8266 2 месяца назад
@@petaflop3606 Book Hammond was really lenient on security.
@masu33
@masu33 2 месяца назад
​@@petaflop3606(Jurassic Park reference.)
@JeremyAndersonBoise
@JeremyAndersonBoise 2 месяца назад
😂 nice one
@saint3106
@saint3106 2 месяца назад
Spared no expen[SYS_FAULT]
@Master120
@Master120 2 месяца назад
CrowdStrike destroyed the best Rootkit ever made*
@orbatos
@orbatos 2 месяца назад
You mean deployed
@douglascoburn
@douglascoburn 2 месяца назад
​@@orbatosUnless Windows is the rootkit 😂
@tao4124
@tao4124 2 месяца назад
😂😂
@BillAnt
@BillAnt 2 месяца назад
It's still in Windows\System32\Drivers\C-000*.SYS heh
@Master120
@Master120 2 месяца назад
@@BillAnt 💀
@heliozone
@heliozone 2 месяца назад
You said the right thing: "Why are you using windows for a serious thing, in first place? "
@vanwaardhuizen
@vanwaardhuizen 2 месяца назад
As someone in the financial services industries, I'm too well aware of this type of software. It's essentially required to run this stuff to pass audit.
@goku445
@goku445 2 месяца назад
parasite industries
@AQDuck
@AQDuck 2 месяца назад
Unfortunately critical infrastructure like hospitals and government running Windows doesn't surprise me one bit. What *did* surprise me with this whole thing is how many billboards, signs, etc. runs Windows... You could EASILY power those with probably even a Raspberry Pi Zero, yet they licensed Windows for that...
@JebtonLT
@JebtonLT 2 месяца назад
It’s a minor miracle billboards, signs, and bigass screen arrays work at all. Ever. Even under best case circumstances. The last time I worked with them I had to translate menus from Chinese to English on my phone just to do the most basic tasks and I still almost flung myself off the roof in protest, I can’t imagine trying to manually patch something like this. What an actual nightmare. Just, pain. Legacy broadcast and media standards truly make all that equipment almost unusable when it’s designed well, maintained well, and working. And I’ve yet to see any one of those three things in person. Honestly, I’m more shocked that any of those systems were secured and updated now that I’m thinking about it.
@realEchoz
@realEchoz 2 месяца назад
i feel like i see public displays showing some silly windows thing all the time. usually a dialog from some useless software showing up on top of the full screen thing they're running or that it updated itself to become unbootable. either way i'd be more surprised when something is done well than when something is done poorly, because the latter is the standard
@Hirokuro_Asura
@Hirokuro_Asura 2 месяца назад
IDK about murica but in some countries there's a state law saying that all the software any company uses (esp affiliated with the state) must have a license purchased (for each machine they have and are using). This includes OS, text and tables editing programs, etc.. If an inspection arrives and finds out there is at least one system without license or with an expired one - the company gets a huge fine to pay. Probably that's why they are using win.
@queasybeetle
@queasybeetle 2 месяца назад
Because nobody likes Linux.
@realEchoz
@realEchoz 2 месяца назад
@@Hirokuro_Asura you can purchase the right to use linux under the general public license. you can also get it for free, but I'm sure someone will take your money if you really need to get rid of it. regardless i don't doubt your claims about corruption existing.
@Basta11
@Basta11 2 месяца назад
First time I heard of Crowdstrike, I was on call on a Saturday night. I happened to be on the computer at the time just checking our systems. Suddenly all of our ETL jobs were failing, databases down. Turns out they installed CrowdStrike and it blocked network communications and shut down a bunch of our containers. Yeah, that was a fun (not) overnight work session. In that case, it was doing what it was suppose to. Just nobody told us they installed it.
@whatever_mate
@whatever_mate 2 месяца назад
When I hear "What is Ryanair?" I know internet has brought nothing together, Americans still live in their own little bubble and literally and figuratively there's still an ocean between us.
@dansanger5340
@dansanger5340 2 месяца назад
I'm American and I immediately knew what Ryanair was, even though I've never flown on them and only been to Europe once. Primagen was one time talking about worthless courses that people are required to take in college, and his first example was geography.
@pnwlady
@pnwlady 2 месяца назад
I knew what Ryan air was. It’s the cheap flights airline in Europe. Not everyone leaves the country enough. 😂
@101Flinx
@101Flinx 2 месяца назад
Back in late 90's/early 2000's a lot of European airlines were using Linux but complained after a few years that it stopped working correctly and abandoned it. Root cause of their problems lie in that they never ran updates on their systems. they somehow thought that they never had to run updates and that their systems would just continue working fine forever.
@SimonBuchanNz
@SimonBuchanNz 2 месяца назад
That's what *I've* always heard about Linux 😄
@gatocochino5594
@gatocochino5594 2 месяца назад
That's because before SystemD updating linux in the massive IT systems corps use was indeed a pain in the ass.
@Tetus7
@Tetus7 2 месяца назад
​@@SimonBuchanNzIt's true if you're completely offline. But if you're connected to the internet, standards are going to change and vulnerabilities are going to be discovered. That requires updates to prevent things from breaking.
@SimonBuchanNz
@SimonBuchanNz 2 месяца назад
@@Tetus7 more just a joke about all the weenies back in the day crowing about all the windows security updates... as if Linux didn't need them too.
@OatmealTheCrazy
@OatmealTheCrazy 2 месяца назад
​@@Tetus7 Not just offline, embedded systems too if exposed to public
@Taedrin
@Taedrin 2 месяца назад
It shut down the airlines... except for Southwest who were spared because they are apparently still on Windows 3.1
@justinrohomon979
@justinrohomon979 2 месяца назад
Rollout for NT 4 server scheduled for 2027
@smanqele
@smanqele 2 месяца назад
no ways ! 🤣
@Lecluyse2000
@Lecluyse2000 2 месяца назад
My mom is the head nurse of a department at a big hospital in my city. She went in at 5 when she usually does at 8. She said today was an absolute nightmare. Like 4-5 usable computers in the whole hospital that were being shared by every department. Nurses writing everything down by hand. She said shes never seen anything like it before.
@alexd7466
@alexd7466 2 месяца назад
wth does a hospital use windows software?? thats your problem there.
@hanswoast7
@hanswoast7 2 месяца назад
@@alexd7466 the usual line or argument is "but everyone uses Word and Excel. We need Microsoft products to stay in touch with everyone so we can collaborate" something something
@Lecluyse2000
@Lecluyse2000 2 месяца назад
@@alexd7466 I mean yeah they don’t have the time to teach 500 people how to use Linux. You gotta keep in mind some of them are 50ish years old and barely know how to operate a computer in the first place.
@DaniZeAlmighty
@DaniZeAlmighty 2 месяца назад
​@@alexd7466hospital staff are usually between 30 to 50 years old, windows is the easiest to operate even for boomers, why shouldnt they use it?
@pattabhinanduri7277
@pattabhinanduri7277 2 месяца назад
My wife is a nurse and has been using Ubuntu for over 10 years . I had to switch to windows recently because some of the systems setup require that she login from windows and there are too many for me to help her. Linux is hard to teach is just not true.
@chanelf.4934
@chanelf.4934 2 месяца назад
CrowdStrike and Kernel Panic on Linux happened like a month or a few months ago. So...this isn't a Windows VS Linux thing. I work at a Cloud Provider and I've seen these security solutions tear up Linux environments too.
@spider853
@spider853 2 месяца назад
Yeah, Prime failed pretty much on Windows part...
@lashlarue7924
@lashlarue7924 2 месяца назад
This is a partly valid point but with Linux you generally don't need to have this sort of anti-malware client in the first place!
@kevinrineer5356
@kevinrineer5356 2 месяца назад
​@JimAllen-PersonaI've also noticed weird spikes on CPU by an unnamed EDR solution. The oddest thing is that they aren't triggered by any obvious system call or daemon. It's non deterministic as far as I know.
@saiphaneeshk.h.5482
@saiphaneeshk.h.5482 2 месяца назад
​@JimAllen-Persona yeah seen the same happen on 2016 iMac model too. Thank fully they replaced it with 2018 edition iMac lol.
@CatFace8885
@CatFace8885 2 месяца назад
So this isn't the first time this happened??? 💀💀💀
@orbatos
@orbatos 2 месяца назад
At this point it's clear they didn't perform integrity checks on the update when sending it on the client end and there is no rollback mechanism for an update failure. The bug causing a null payload is severe, but nothing compared to a total lack of sanity checking, rollout testing and staging.
@tc2241
@tc2241 2 месяца назад
Yup, we can talk all this trash about CrowdStrike, but at the end of the day the client should have a vetting period in stage
@crispybatman480
@crispybatman480 2 месяца назад
​@@tc2241Turns out this was just a massive security audit.
@BlueDude-cf9mk
@BlueDude-cf9mk 2 месяца назад
@@tc2241Yeah but mind you, some companies have been using it for years. Eventually you just trust the “experts” and focus on other important things. Not excusing anyone, just saying, it’s understandable. Crowdstrike takes all the blame because they were the ones promising security and reliability.
@megaing1322
@megaing1322 2 месяца назад
@@tc2241 No? That is misunderstanding what CrowdStrike provides as a feature. CrowdStrike should have had some kind of actual, real-world testing infrastructure to check that the updates get applied correctly. The point is more that shit happens, and CS is no exception. But they appear to have had zero safe guards, or whatever safe guards they had were terrible.
@Ba-gb4br
@Ba-gb4br 2 месяца назад
​@@tc2241No? That's literally what Cloudstrike is paid for? Why would you pay a company for managing your security infrastructure if you need to test their changes every time?
@huubeijndhovenvan7177
@huubeijndhovenvan7177 2 месяца назад
I’m an old unix /linux guy currently working at a windows managed services company. You have no idea how little knowledge, especially basic engineering knowledge, 98% of windows administrators have. Including basic engineers street-wise knowledge. And they are working with an OS which is an order of magnitude bigger and more complex than Linux. They have zero mental image of how stuff works. THIS is why this happens.
@a_blaser
@a_blaser 2 месяца назад
Apple had a similar problem with a content update for their XProtect a few months ago. It falsely identified iOS simulators as containing a virus and would remove them. It only affected developers working in Xcode for about a day. It does show how automatic security updates can create big problems. I unchecked the “auto install security updates” box after that.
@hanswoast7
@hanswoast7 2 месяца назад
I think the best scenario is to have delayed auto-updates to avoid quickfire rubbish. I think being behind like 2 weeks should be fine.
@Aleh_Loup
@Aleh_Loup 2 месяца назад
(FORCED) Pusheed to Prod at Fridaaayyy -- Burned by its sins. In all seriousness, forced remote updates are horrible. And it was pushed to millions of users without proper testing...
@zacharyhodge1761
@zacharyhodge1761 2 месяца назад
This is the poster child for untested changes, and it's unbelievable how much risk companies are assuming by allowing forced pushes from this vendor.
@tc2241
@tc2241 2 месяца назад
It’s insane, push based autodeployments with no vetting period…wtf!?!?
@skunkwerx9674
@skunkwerx9674 2 месяца назад
It’s not really forced at all, every organization that uses crowdstrike has the option to review the updates before using them, everyone that was affected didn’t even test the updates crowdstrike provided. The fact they just went with the force update workflow was a disaster waiting to happen, and here we are. Source: Crowdstrike documentation.
@dead-claudia
@dead-claudia 2 месяца назад
it may have been a security update that worked on the absolute latest version and not any prior version which i've heard of happening many times before
@dead-claudia
@dead-claudia 2 месяца назад
@@skunkwerx9674apparently this came out of an automatic update, not a new program binary
@Marco-Vavassori
@Marco-Vavassori 2 месяца назад
2:58 "who is Ryanair and why does he have his own company; why should I trust Ryan?" I can't stop laughing 😂😂😂
@a4d9
@a4d9 2 месяца назад
Server class hardware has out of band management (HP has ILO, Dell has iDrac) which can be simply described as KVM over the network. The machine does not even need to be switched on. Many client machines in enterprise environments have similar functionality, such as Intel AMT. So no, if configured correctly, no one needs to physically visit each machine.
@logicalspaghetti
@logicalspaghetti 2 месяца назад
31 seconds ago is wild, it's neat to be in here at the same time as the scam bots for the first time in a while.
@youtubepooppismo5284
@youtubepooppismo5284 2 месяца назад
"is wild" like what does that even mean
@testthisfordecficiencies
@testthisfordecficiencies 2 месяца назад
A bot would for sure say this!
@hdbrot
@hdbrot 2 месяца назад
@@youtubepooppismo5284"is wild" means "is crazy".
@youtubepooppismo5284
@youtubepooppismo5284 2 месяца назад
@@hdbrot No shit sherlock
@XueYlva
@XueYlva 2 месяца назад
​@hdbrot this man either isn't chronically online and/or does not know any black people
@andrewtran9870
@andrewtran9870 2 месяца назад
In the US, folks woke up to this, but in Australia, this all happened at 3 pm, peak hours
@zoeherriot
@zoeherriot 2 месяца назад
Yup - same in Japan. All I could think of was the people in the US about to wake up to this. :)
@andrewtran9870
@andrewtran9870 2 месяца назад
@@zoeherriot oh yeah, forgot how similar our time zones are
@harleyspeedthrust4013
@harleyspeedthrust4013 2 месяца назад
list of people who asked: (it's empty)
@zoeherriot
@zoeherriot 2 месяца назад
@@harleyspeedthrust4013 like your head.
@kipoyedcl
@kipoyedcl 2 месяца назад
in Asia, its in the middle of the day, 12nn - 1pm. Many of us came back from lunch with our workstations stuck in the BSOD loop.
@heberdnobre
@heberdnobre 2 месяца назад
Jokes aside, imagine your life or the life of a loved one depending on systems like these (for travel, insurance, or healthcare) and getting stuck without any immediate resolution. Hope no one died because of this.
@NerdyBirdy16
@NerdyBirdy16 2 месяца назад
Imagine missing final moments with your dying loved one bc of this
@quietwulf
@quietwulf 2 месяца назад
Oh wait till the damage law suits start piling up. This could very well wipe out cloud strike
@HickoryDickory86
@HickoryDickory86 2 месяца назад
Sadly, in the UK, one hospital did report a critical incident as a result of a third-party IT system being impacted by this. Who knows how many more will be reported? I get that "shit happens," but this incident needs to be independently investigated. Was this update properly tested before being rolled out, or did they skip best-practice safety measures to save time and/or money? If they skipped safety measures, then they could potentially be liable for involuntary manslaughter.
@Slav4o911
@Slav4o911 2 месяца назад
That's why you don't do every system the same as the other one, even if it's the most secure system in the world, you have to have a back up system made in a completely different way. But I thought the geniuses who secure banks and whatever and get a lot of money knew that... it's seems all are just like parrots, everybody does the same thing as everybody else... and then when one mistakes happens, everybody "burns together".... what a stupid thing to do. Again why everybody was using the same security software?!... and why critical systems were not using Linux?!... By the way I didn't even knew that company existed... until now.... why banks and other organizations use products from some unknown company is beyond me. Friends were asking me if we have problem with our Windows systems at my work... I just told them nah, we don't use Windows in critical systems. I thought that was common especially in banks... but it seems they use Windows with some antivirus/security software.... *which I didn't know exists, until this whole thing happened.* it's unfathomable to me.
@simonbelmont9689
@simonbelmont9689 2 месяца назад
I drank a shot every time you said CLOUD STRIKE as the words CROWD STRIKE were on the screen right in front of you. Now I'm being rushed to ER
@thewhitefalcon8539
@thewhitefalcon8539 2 месяца назад
The ER is closed due to bsod
@brainites
@brainites 2 месяца назад
@@thewhitefalcon8539 🤣
@BlueDude-cf9mk
@BlueDude-cf9mk 2 месяца назад
Crowdstrike: Security so good, it attacks itself.
@mikelannister960
@mikelannister960 2 месяца назад
☠️☠️☠️☠️☠️☠️☠️
@nakoskyranos4080
@nakoskyranos4080 2 месяца назад
The computer has autoamune desiese 😂
@black_platypus
@black_platypus 2 месяца назад
_It hurt itself in its confusion_
@koffiezet
@koffiezet 2 месяца назад
You'd be surprised what an amateur hour the airport, medical and banking world is sometimes, so many "server" applications which are just a GUI running on some desktop machine. If they're lucky they get a dedicated machine, but often it's just running under someone's desk, being also used as a normal client computer.
@jvaudio
@jvaudio 2 месяца назад
Longtime security professional here and I must say that I am shocked by the lack of awareness around how all of this stuff works. It should be noted that enterprises run EDR/XDR agents such as Crowdstrike on Linux, Mac, and Windows machines. To be able to detect modern, sophisticated malware, you need low-level/kernel access to the machines. Enterprises manage a ton of machines and to protect our environment from endpoints (servers/laptops/etc.), we need to monitor them as users are traditionally the riskiest thing in an environment.
@FilthyHyena
@FilthyHyena 2 месяца назад
It is obscenely sad that I had to scroll down this far to find this. Well past morons somehow watching this only to decide that this is somehow the fault of SCCM. Much less all the misinformation and just general weird opinions being pushed around by people that are supposedly tech savvy in RU-vid videos like this. I mean Jesus. This dude does not apparently understand why AAD servers exist in 2024 when Linux still runs as jank as it does and is in no way friendly to learn for general users?
@laughingalien
@laughingalien 2 месяца назад
What you said makes sense. What doesn't make sense is how this F#%K UP happened. Do companies test in production now?
@MarkusSeidl
@MarkusSeidl 2 месяца назад
@@laughingalienYes
@SharatS
@SharatS 2 месяца назад
​@@laughingalien Always have, always will.
@tagaretiro
@tagaretiro 2 месяца назад
@@laughingalien No. AV companies have infrastuctures in place to test product updates before pushing them into real-world. I''m guessing it is either a QA engineer fucking up when checking the testing results or an issue with their CDN serving a corrupt file.
@giogio182
@giogio182 2 месяца назад
"Isn't EU all about privacy and security?" Privacy? Yes. Security? Not really. Expecially not enforced to a foreign country entity. That's more of a USA thing. 😅
@JeremyAndersonBoise
@JeremyAndersonBoise 2 месяца назад
So, to me, it appears that CrowdStrike seemingly did not test this on any actual machines before deploying it globally, think about the negligence of that move.
@jnawk83
@jnawk83 2 месяца назад
​@@ricardodelacrvz1400it's a Microsoft problem only insofar as much as Microsoft's products are so garbage that this kind of 3rd party crap is necessary, and they are responsible only so far as they have made this kind of thing a race to the bottom.
@BrandonBusby-u2b
@BrandonBusby-u2b 2 месяца назад
​@@ricardodelacrvz1400Why would Microsoft test another company's software? Writing drivers in Kernel space so any driver issue crashes the system. That's not a Microsoft problem.
@RmAndrei93
@RmAndrei93 2 месяца назад
Microsoft don't test their own products. Why test another companies ?
@Vpaq
@Vpaq 2 месяца назад
​@@ricardodelacrvz1400Dude it's not an update that was pushed by Microsoft, it's not their responsibility to test everything and anything a user can install on top of the OS. Do you think car companies like Nissan test every aftermarket part that could be installed? This was a problem of CrowdStrike not testing the update before pushing it and the consumer not testing it on an isolated environment that mirrors their production one to ensure it plays nice with all the other software they may be running. If anything, Windows did exactly what it should've and crashed immediately.
@BrandonBusby-u2b
@BrandonBusby-u2b 2 месяца назад
@@RmAndrei93 "Microsoft doesn't teat their own products." That's quite a nuanced view you have there. Yes, no test ever done at Microsoft. I'm sure that's true... not.
@pedrogorilla483
@pedrogorilla483 2 месяца назад
I’m surprised how much infra uses Windows.
@JustkickinitG
@JustkickinitG 2 месяца назад
That was my immediate thought as well. Holy hell. You would think that infrastructure like transportation would have their own OS's with a ton of redundancy.
@taz9609
@taz9609 2 месяца назад
shocking really!
@Fiercesoulking
@Fiercesoulking 2 месяца назад
Near all cooperation and governments use windows because of Office & Teams + mentioned group policies(which also ended up that a lot of industrie hardware has .Net APIs) . Linux is only on the webserver side big. This also the reason windows is so big its as much feature complete as possible
@paca3107
@paca3107 2 месяца назад
​ @Fiercesoulking you're right. Many products from MS are very useful for business, when similar programss are not that good or untrusted for managment. It's sad but there is no many good alternatives.
@paca3107
@paca3107 2 месяца назад
second reason is that windows in the peak had around 90% of market share, so many industry specific programs was written for windows and they still in use.
@ALZlper
@ALZlper 2 месяца назад
The hospital staff didn't know which medication my dad was scheduled to receive today.. This is absolutely embarrassing for the hospital in my opinion. They should've never setup their infrastructure like that.
@MrBestard
@MrBestard 2 месяца назад
My dad went the doctor today, the computer system was showing incorrect insurance information.
@BN-qo5zc
@BN-qo5zc 2 месяца назад
Cuts mean no funding for paper backups or fallback systems.
@Wahinies
@Wahinies 2 месяца назад
With security like this who needs ransomware
@dead-claudia
@dead-claudia 2 месяца назад
@@Wahiniesi mean crowdstrike all but zero-day'd itself. the bug in question was one of the classic vulnerability culprits.
@rbgtk
@rbgtk 2 месяца назад
How should those hospitals have set up their infrastructure if you don't mind me asking?
@blahblahboii
@blahblahboii 2 месяца назад
My team was in the middle of a production go live when our systems started getting struck down one by one. thankfully, my own machine would only bsod intermittently and not on boot-up. When googling the issue, I found that this wasnt even the first time crowdstrike has caused these issues (my company adopted crowdstrike late last year). There were forum posts from july 2023, and march 2023 of the exact same issue.
@user-wf7uf2jp8x
@user-wf7uf2jp8x 2 месяца назад
Effected my department. I had to go around recovering my coworkers' conputers.
@Yamahog
@Yamahog 2 месяца назад
Ditto, I got about 10 going here this morning before I.T. showed up and took over.
@dockdrumming
@dockdrumming 2 месяца назад
I had too as well. What a headache.
@qwantom1
@qwantom1 2 месяца назад
5,000 isn’t that bad. My company has 7,000 workstations that will need to be manually recovered in addition to a few thousand servers. Gotta feel bad for the IT guys
@Yamahog
@Yamahog 2 месяца назад
So my Company's ISP uses Fiber, With Linux based servers, and yet all 40,000 + workstations on my Company's Intranet use W-10 ..... How stupid is that ???.... Anywho ...I managed to get about 10+ PCs active in critical areas, before IT showed up and took over at my site this morning. Kudos to that ISP, which is the same ISP that I have at home ..... And I've been using Linux since ~2003.... So needless to say, I was unaware of the " Take-Down by Crowd Strike" until I read Google news this morning.
@OldManShoutsAtClouds
@OldManShoutsAtClouds 2 месяца назад
✅️Confidentially ✅️Integrity ❌️Availability
@RmAndrei93
@RmAndrei93 2 месяца назад
It's 100 % confidential is it's 100% reliabiably useless
@coolm98
@coolm98 2 месяца назад
CIA
@ChadSkeeters
@ChadSkeeters 2 месяца назад
Exactly!
@shamashel
@shamashel 2 месяца назад
Considering they didn’t use checksums to verify the update files, I think we’ve only got the C here
@krs4129
@krs4129 2 месяца назад
It did not turn off any Internet, it turned off machines that use Internet. There were no internet outages.
@goku445
@goku445 2 месяца назад
Mine was perfectly fine...
@keyboard_g
@keyboard_g 2 месяца назад
This happened to some Debian servers in April, just the blast radius wasn’t big enough to make news
@vilian9185
@vilian9185 2 месяца назад
because crowdstrike is not required to make linux secure, now on windows....
@evilj
@evilj 2 месяца назад
@@vilian9185 my company used to run crowdstrike on all machines, Linux as well. SecOps policy :)
@georgerogers1166
@georgerogers1166 2 месяца назад
@@vilian9185 GLibC binary incompatability is enough.
@jrlx86
@jrlx86 2 месяца назад
​@@vilian9185Falcon is still available for Linux, so some people must be installing it
@RockChalk263
@RockChalk263 2 месяца назад
@@vilian9185 you don't need crowstrike on Windows either.
@balogdavid2006
@balogdavid2006 2 месяца назад
A lot of companies run crowdstrike or generally cybersecurity suits on linux/unix too, this is not a windows problem. And generally enterprise runs on windows because of active directory and office. Also .net and c# is quite common for monolith applications
@HirschyKiss
@HirschyKiss 2 месяца назад
This turned my normally pretty dead Friday morning into a hellscape. My organization has Falcon on all endpoints, and many of our customers are on Windows, and we had a LOT of tickets come in. As for servers, unfortunately there are a good bit of windows only application servers, it does suck
@RavingKats
@RavingKats 2 месяца назад
Yup, I work in fintech and even the working PC's were struggling to load apps and software systems, half the time nothing worked. It was a long day.
@kevharv
@kevharv 2 месяца назад
Prime doesn’t have an IT ops background. To him servers are ephemeral but that’s not how traditional IT systems work.
@nooblangpoo
@nooblangpoo 2 месяца назад
>thank the day off >I'm an IT Tech MORE LIKE ENJOY THE HELL ON.
@JeremyAndersonBoise
@JeremyAndersonBoise 2 месяца назад
Thank you for your service
@dead-claudia
@dead-claudia 2 месяца назад
🫡
@a_lethe_ion
@a_lethe_ion 2 месяца назад
I actually love that "anti cheat" is like a point on the scale of how intrusive something is
@firemyst9064
@firemyst9064 2 месяца назад
In grocery: my beverage company had an issue in sales, some system went down. Another beverage company, their warehouse picker system for beer went down. A grocery store(singular to my knowledge) clicklist system went down, no online shopping allowed. Starbucks mobile ordering went down (nation wide I heard).
@MuammarQadaffi
@MuammarQadaffi 2 месяца назад
Why does a BILLBOARD need to be linked up to a computer with windows installed? What a waste.
@Stabby666
@Stabby666 2 месяца назад
It's pretty standard. Reason is that there are drivers for weird resolutions, industry standard "digital signage" software for Windows, and it mostly "just works" with zero effort. Not sure why they'd install a virus scanner like this on one though - generally they don't have internet access (or only access a specific server once per day to download media). That said, many of the latest "slab" type screens you see in malls etc use Raspberry Pi compute modules internally.
@kevinrineer5356
@kevinrineer5356 2 месяца назад
​@@Stabby666 they'd have crowdstrike to be in compliance for cyber security insurance. If it connects to the internet at any time for any amount of time, it has to have an EDR solution for most cyber insurance AFAIK.
@tom_marsden
@tom_marsden 2 месяца назад
Y2K finally came but it was 24 years late
@boyardeanes
@boyardeanes 2 месяца назад
my phone started ringing at 12:49 am - "we are down, have BSD on many machines, can't reach the server screens", fun way to wake up. Long night,
@CallousCoder
@CallousCoder 2 месяца назад
If you had BSD on your screen you would've been fine :D Think about an OS that's called BSD ;)
@adirnoyman2231
@adirnoyman2231 2 месяца назад
Two questions: 1) Why didn’t they see this bug in testings???? 2) Why didn’t they push this update incrementally to a smaller amount of customers?
@CTimmerman
@CTimmerman 2 месяца назад
Skilled people are expensive and less inclined to kiss ass.
@takeuchi5760
@takeuchi5760 2 месяца назад
1) Because the testing was insufficient. 2) Because that insufficient testing was believed to be sufficient by them.
@Asto508
@Asto508 2 месяца назад
@@takeuchi5760I'd rather think cost reduction by management. CS has become big enough that some cowboy managers entered the company and wanted to increase their share.
@dead-claudia
@dead-claudia 2 месяца назад
@@takeuchi5760every. single. time.
@Slav4o911
@Slav4o911 2 месяца назад
Because nowadays you get in higher position by kissing your boss ass... that's why this happens and it would get even worse in the future. Non thinking "yes men" get better salaries and are placed in higher positions.
@dehydr8d275
@dehydr8d275 2 месяца назад
The short pause to slander United Airlines was cathartic. I’ve been saying the same thing for the last few years and I finally feel heard
@piotrc966
@piotrc966 2 месяца назад
EDR is for Linux and MacOS too. Not only Windows. EDR for linux server is the first cell to detect a security breach - as long as it works 🤣.
@Jabberwockybird
@Jabberwockybird 2 месяца назад
How can you not make a million Jurassic Park jokes?
@Alico_Reborn
@Alico_Reborn 2 месяца назад
On updating old systems to new ones: 6 years ago, when I was working at Walmart, we had someone updating our Self Check-Out machines with newer software. They updated the computers from XP to Vista. Yikes! And people wonder why our security is such a big issue.
@memoryleakerz
@memoryleakerz 2 месяца назад
* Ryan and John push a global kernal update * "Wait Ryan, are you seeing what I'm seeing?" "Shit."
@UnfiItered
@UnfiItered 2 месяца назад
This would've never happened if they did a internal test before they push out a update.
@nicholaslueck5385
@nicholaslueck5385 2 месяца назад
Helpful insight
@jonnyvelocity
@jonnyvelocity 2 месяца назад
I'm amazed they don't do that.
@billharris3707
@billharris3707 2 месяца назад
I'm in IT. Our servers came back up pretty quickly. The bigger issue was the endpoint client. We couldn't just write a PowerShell script and push it for a fix because none of then endpoint had internet access. We had to access the Recovery option, get into CMD, remove the bad update file and reboot manually; on. every. single. machine. (sometimes guiding our user over the phone). The reason for the shut down, from what I can tell, was not the severs being down, but the endpoints.
@guilhermehx7159
@guilhermehx7159 2 месяца назад
My personal laptop was affected. Like three days ago it started tô get slow. Then even slower. And Then yesterday the blue screen showed up forcing a reinitialization
@Yamahog
@Yamahog 2 месяца назад
Hey Bill. I hear ya. I had to brute force make about 10+ workstations disable the csagent.sys update in some rather critical departments here. Fortunately our ISP, Fibre - based, was unaffected and once I got my PC going, ( all of maybe 2 minutes of finagling without a sweat), I went after some others, all done via GUI and some brute force resets, no CLI, ( CMD in your case), needed. What I did see though, is the update affected PC's differently, which was odd. If the PC was inactive during the update, ( User logged in with screen locked but still on the intranet, as in my case..) , a GUI reset took about 2 minutes to force the use of the older csagent.sys file,(?), and log on, as the update had failed, but it gave the same BSD diagnostic. But,... If the PC was active and the forced reboot was attended by staff logging out to allow the update, then the reset was almost impossible without the intervention of IT to go Root and do a reinstall of CrowdStrike , or possibly re-map the drive of the PC. Nuff said on this , ... lol
@guilhermehx7159
@guilhermehx7159 2 месяца назад
@@Yamahog is it possible tô fix mine?
@jamesarthurkimbell
@jamesarthurkimbell 2 месяца назад
Mr. Hammond, I think we're back in business
@thereal_nsxdavid
@thereal_nsxdavid 2 месяца назад
Also best impression of Seth Rogen in Cybersecurity
@amisco333
@amisco333 2 месяца назад
Right?🤣🤣
@ParanoidxProd
@ParanoidxProd 2 месяца назад
My cousin works there and said he was on call but it wasn’t his team. Wild shit
@zacharyhodge1761
@zacharyhodge1761 2 месяца назад
R.I.P. your cousin's Employee Stock Investment Program.
@dead-claudia
@dead-claudia 2 месяца назад
reminds me of the time while i was on call at aws where cloudwatch's log ingest kicked the bucket for hours in us-east-1. fortunately we weren't impacted much beyond just flying mostly blind, and the justifiably spooked backend teams in my department also survived. but the execution plane for one of the other departments almost went down with cloudwatch bc their logs weren't rotating (bc the uploads kept failing) and their disks were filling up so fast it was threatening to down some of their hosts in mere minutes. (they ended up manually deleting logs regularly across these many thousands of hosts, just to keep availability.)
@samcalder6946
@samcalder6946 2 месяца назад
This is possibly the best named company in history. This is exactly the same result if the entire crowd goes on strike.
@TheOrijinalPajeet
@TheOrijinalPajeet 2 месяца назад
Ryanair is the largest airline on earth. Known for wanting to sell stand up "seats" in the aircraft, basically they tie you down to a vertical pipe.
@MatheusOliveira-er4gq
@MatheusOliveira-er4gq 2 месяца назад
The cheapest
@petrsebik
@petrsebik 2 месяца назад
Aint no way they would allow these stand seats, because the aircraft has to evacuated under 90 seconds or they wont be certified to be commercially used. And if you have higher seat density with these stand seats you will to not pass the evacuation limits.
@Yamahog
@Yamahog 2 месяца назад
LOL
@araarathisyomama787
@araarathisyomama787 2 месяца назад
@@petrsebik Maybe they wanted to do that on smaller aircrafts that can be evacuated faster
@petrsebik
@petrsebik 2 месяца назад
@@araarathisyomama787 maybe. But not by ryanair, as ryanair's fleet is by 95% boeing 737 with around 190 passangers capacity. And the other 5% is 28 leased airbuses A320 with same capacity.
@andrewmusholt9327
@andrewmusholt9327 2 месяца назад
For my company, it was a 100% manual/in-person fix. Walking around the office for an entire day, booting into safe mode, and deleting the file.
@goku445
@goku445 2 месяца назад
Could have been automated through booting on LAN on a Linux system...
@tozrimondher4250
@tozrimondher4250 2 месяца назад
CrowdStrike really made the dream of wannabe hackers come true
@JeremyReedGeezus
@JeremyReedGeezus 2 месяца назад
Ryan air is the airline "owned" by the US military. From what i jave heard, they are used to transport US troops over seas.
@NotAFanMan88
@NotAFanMan88 2 месяца назад
I feel left out, my IT infrastructure didn't get taken out today, all our stuff (including some windows boxes) are on-prem and don't have it installed. I still had to work.
@RavingKats
@RavingKats 2 месяца назад
Mostly, crowdstrike is enterprise cloud security for fortune 500 companies. Everyone's freaking about PC level, and I get it's a lot of machines, but if your enterprise servers are busted who cares if machines turn on, you legit can't access anything required to do your job at least not consistently, even if some servers are ok the load is too much. What's really crappy about machine level at enterprise with these types of securities is that there's master admin sso keys that are typically necessary to even be able to boot into recovery to apply fixes. Hopefully orgs with hundreds of employees per site have those all organized by workstation (hahaha everyone knows that's unlikely!)
@realEchoz
@realEchoz 2 месяца назад
thank god i was left out and hopefully won't have to touch a windows machine for the rest of my life. you know, except for when i check in on a flight or some other thing where they decided an angle grinder was a good screw driver
@TheNerd
@TheNerd 2 месяца назад
01:00 The answer is that probably 95% of all business and B2B related software (in offices) runs on Windows and Windows only even on the Server side. Try to teach your average office worker who struggles to tell if the PC is turned on or not (when the screen is black because its turned off) to install some random Linux Software with 7 dependencies that you need to install via shell (Good luck with that one) or in other words: "Why no one cares about Linux in offices and no one ever will". And no: Ubuntu is not a good example of "easy to use" by MacOS or Windows standards that are already considered to be "hard to use" by average people. Average people dont't even know the difference between "user" and "password" when they get prompted to login. Any more questions?
@Kc-nn8mn
@Kc-nn8mn 2 месяца назад
IT management: we need to restrict employee's permissions for security. Employee: please approve I'll need some permissions to do my work. Security team: wtf you need that permissions. Crowdstrike: I need your super admin to install patch on your keneral. IT management and security team: go for it. Thanks so much. Given: that CS CEO was McAfee CTO who created a big disaster crashed tens of thousands of computers. That guy is much more reliable than your loyal employee.:)
@Jkaninteangemittnamn
@Jkaninteangemittnamn 2 месяца назад
Ryanair is the other cheapest flight travel provider but in EU , They might fly from airports nobody else makes money from and shure dont expect much in term of service but its cheap for students
@2kadrenojunkie
@2kadrenojunkie 2 месяца назад
"i'll never use linux, it doesn't have antivirus!" meanwhile, antivirus:
@austinrichardson1255
@austinrichardson1255 2 месяца назад
My employer was unaffected because we don't use CrowdStrike. I also wouldn't have been affected because I use Linux. GG EZ
@AmonAsgaroth
@AmonAsgaroth 2 месяца назад
Literally happened to linux back in April. Crowdstrike has a linux version and it also caused a kernel panic. The only difference is that not a lot of public infra runs on linux so it didn't make the "normie" news.
@Ubben1999
@Ubben1999 2 месяца назад
⁠@@AmonAsgaroth”not a lot of public infra runs on Linux” - the vast majority of the Internet runs on Linux distros. I would imagine almost none of them uses Crowdstrike, however, hence no public outcry.
@tc2241
@tc2241 2 месяца назад
Better is to have a stage env and not allow automated push deployments to prod
@jnawk83
@jnawk83 2 месяца назад
​@@tc2241this
@FilthyHyena
@FilthyHyena 2 месяца назад
​@@Ubben1999and yet the vast majority of companies use AAD or AD or azure hybrid.
@greennin
@greennin 2 месяца назад
Crowdstrike is the perfect name for the company that did this
@Slav4o911
@Slav4o911 2 месяца назад
The more funny thing is I hear about this company for the first time... even though I know a lot about antivirus companies.
@greennin
@greennin 2 месяца назад
@@Slav4o911 Me too, not afraid to admit it. And I bet there are quite a few tech companies with a really wide read that we haven't heard
@alst4817
@alst4817 2 месяца назад
MacAfee come back! We have cocaine here too!
@JohnnySmith-to7jw
@JohnnySmith-to7jw 2 месяца назад
this happened: Bullying and 'politics' in the Psycho companies... and this is the result... when 'soft skills' are more appreciated than 'technical skills.' NOTE: 'soft skills' = Bullying and 'politics' ;)
@samcalder6946
@samcalder6946 2 месяца назад
Somebody's getting fired for releasing this to Production on a Friday.
@AQDuck
@AQDuck 2 месяца назад
And sadly it's going to be the nervous Jr guy who were pressured into "just push to prod" on his first day.
@hanswoast7
@hanswoast7 2 месяца назад
Most companies and governments in the EU are lobbied into oblivion to use Microsoft, antivirus and such. There is somehow a strong urge to be dependent on US big tech. Open source efforts are usually belittled and soon de-funded. It is quite frustrating.
@Slav4o911
@Slav4o911 2 месяца назад
Of course they are, there was a regulation in my country to use only licensed software, by companies... i.e. Windows... this stupidity stayed for a few years until the regulation was changed. I think some US politician just came to my country and then that "regulation" was invented. Later the regulation was changed, but for a few years that nonsense regulation was enforced.
@SimonBuchanNz
@SimonBuchanNz 2 месяца назад
Dunno why everyone's complaining about Microsoft and Windows here. Crowdstrike isn't their product, and it has Linux and Mac versions, it's just they happened to not get hit by this one. It's not like there isn't plenty of *good* reasons to point and laugh at Microsoft security and reliability: they recently took like half a year to squash all the print spooler vulnerabilities, for example.
@alulim4968
@alulim4968 2 месяца назад
You missing the point even while you have it in front of you: Windows is SO SHIT that it is the only OS who got affected by this thing. Maybe if Windows would'n be such a shit, Crowdstrike wouldn't kill their systems.
@ratchy1231
@ratchy1231 2 месяца назад
​@@alulim4968 CrowdStrike had a very similar problem causing kernel panics on Linux systems just this april. This does not say anything about Windows.
@realEchoz
@realEchoz 2 месяца назад
imo it's just a good excuse to keep laughing at microsoft, bonus points for the fact that forced updates is something they have been pushing very hard for (not that this was a forced update anyway). also in a lot of these cases windows was just used for things it should never even have been considered for (public displays, etc.)
@rushyscoper1651
@rushyscoper1651 2 месяца назад
@@alulim4968 when u make kernel level software we no longer talking about pure OS, u missing with the OS if it fail its on u. not microsoft fault, honestly not even the kernel level software fault cause these shit are t be expected, the idea that this sort of solution where used in very important areas that should never have kernel panic is very stupid.
@rushyscoper1651
@rushyscoper1651 2 месяца назад
@@ratchy1231 the difference is there many linux flavor that most likely only few of them got effected u also might less likely to see linux ppl running shit like that cause its stupid idea to give remote access to kernel level other then game related stuff.
@nicky5185
@nicky5185 2 месяца назад
Software engineer here. Answering your question about "why does anybody want Windows". I have experience working in both public and private sector. The rule of the thumb is as follows. Public sector will always use Windows and Windows based software. Private sector will always use Linux and open source software. Windows is part of the stablishment, and for the life of me, I can't see this in any other way than "on purpose"
@jorper2526
@jorper2526 2 месяца назад
15 years of IT in Private Sector.. Oil and Gas, Energy, Healthcare, Banking. I think you're in a Software Engineer bubble. Windows was on every laptop and workstation. Servers is where you start having some Linux, AIX.. Highly dependent on the environment, or system usage. Sometimes the core business systems were on Windows, sometimes they were Linux or AIX. But every endpoint, all authentication (Active Directory) was 100% Windows.
@nicky5185
@nicky5185 2 месяца назад
@@jorper2526 this is where we differ. I wouldn't class banking, oil and gass, healthcare or energy as _private_. They may look _private_ on the surface, but it is just that. Can you run your own private LTD company doin the same business as healthcare? Or banking? Would you be able to finance your own drilling prospects and get your explotation rights in the same way a family business run (e.g.) their arts and crafts shop and online commerce website? Can a private farm be bailed out with everyody's tax dollar when they go belly up due to gross missmanagement?
@daphenomenalz4100
@daphenomenalz4100 2 месяца назад
How did it pass through QA checks, do they really have bad deployment setup, like they are the best in the business, how can that slip
@aisle_of_view
@aisle_of_view 2 месяца назад
Non tech CEO tells management "Cut costs. Do we REALLY need QA? Get rid of them"
@jjones503
@jjones503 2 месяца назад
"We haven't had a mistake in years, fire the qa team, we don't need them"
@SM-cs3nt
@SM-cs3nt 2 месяца назад
@@aisle_of_viewTo be honest you don’t need QA if you have a proper staging environment that mirrors the Live environment and if you have an adequate deployment process. Agile Teams that deploy and test their features themselves work far quicker and more efficiently without QA - the idea is to fail quickly and deploy quickly in small increments. Obviously you still need safeguards such as a proper deployment process - but that isn’t an argument against agile development.
@Slav4o911
@Slav4o911 2 месяца назад
Beancounters want to save 1 cent, that's how these things happen.
@YoungGrizzly
@YoungGrizzly 2 месяца назад
I work on a team that runs the email system for a state and its sub agencies. This state is usually up our butts about having a test environment and running all system patches through that environment before applying it into production. So seeing crowd strike make this mistake is wild to me. Like how could it not be caught then go on to affect so many systems. THEN you have the IT personnel who turn on auto updates (I’m guessing) and just let stuff run. I know I’m speaking from hindsight here but this makes me appreciate the CAB process that I’ve always thought was a hindrance.
@erykfromm
@erykfromm 2 месяца назад
CrowndStrike - the company that helped to jail Julian Assange. DNC-Mails anyone?
@crispybatman480
@crispybatman480 2 месяца назад
Oh shit
@markusdiersbock4573
@markusdiersbock4573 2 месяца назад
Really, the World-Wide Fail wasn't caused by the bad update. The FAIL was in rolling out the update to EVERYONE at once -- a blitz. Had they done a Canary deployment and slow-roll, the problems would have tiny
@johnlovell8299
@johnlovell8299 2 месяца назад
Thinking about this differntly; what did they just install on millions of machines?
@jjones503
@jjones503 2 месяца назад
"Click yes to continue"
@enisenzzah9400
@enisenzzah9400 2 месяца назад
Imagine if you had 5,000 servers that you needed to manually fix, and you decided to outsource this work, and then you got malware again. 😂
@Slav4o911
@Slav4o911 2 месяца назад
🤣🤣🤣
@pauljoseph3081
@pauljoseph3081 2 месяца назад
The hassle was global. The company must be held responsible.
@Volvith
@Volvith 2 месяца назад
I called in sick on Friday, at like 6:30 in the morning. Went back to sleep. Woke up 5 hours later: "Oh wow, IT is globally on fire, the Internet is imploding, Windows is dying..." Went back to sleep. If there is a God, homie's got my back lol.
@NoodleFlame
@NoodleFlame 2 месяца назад
Our GP practice in the UK wasn't able to access medical records or see any patients today because of it
@CallousCoder
@CallousCoder 2 месяца назад
Unforgivable from their side. When I worked in healthcare software, we had a special chapter in our manual for working when system was down. A whole manual backup process. Most would print patient details once a month and a weekly print out of ongoing treatments and medication for each patient id. Im worst case you could ask a patient's details fill out a photocopied empty patient card filled that in and leave it on the "to be processed desk drawer". And they would work like that when we came to upgrade their hardware or a power outage happened. So these companies are to blame just as much.
@Lampe2020
@Lampe2020 2 месяца назад
If you're creating and/or maintaining code that is mission-critical for so many people, ALWAYS test EVERY SINGLE update BEFORE it gets to any customer on a few machines that you yourself control. So that if you make a grave mistake (like e.g. causing a boot loop), you can catch it before any costomer gets it.
@scottyd980
@scottyd980 2 месяца назад
Sky-Net went Online.
@DrKaoliN
@DrKaoliN 2 месяца назад
1:02 IMHO it is companies, not people / employees, who choose to use Windows because of the features provided by Active Directory. Also, a lot of creative software does not natively deploy to Linux. Not to mention the driver headache that non technical people don't want to hear about. BSD doesn't seem to be exactly made for desktops. And justifying the pricey mac to the financial department doesn't seem to work. Hey, great to see John Hammond here!
@nickwinn
@nickwinn 2 месяца назад
This is 50% on Crowdstrike and 50% on the customer. Falcon admins can set update policies and allow small groups to get the latest N version while keeping the majority on N-1.
@skunkwerx9674
@skunkwerx9674 2 месяца назад
@@nickwinn yes, exactly! Thank you! This could have been prevented so easily by testing in a limited environment first, at some point both parties are culpable. Especially to yolo allow forced updates from a third party on a Friday with zero quarantined testing. Falcon gives org admins direct control to prevent this, problem is none of their internal teams that use falcon are smart enough to be proactive around what happens when a bad roll out happens. I guess contingency isn’t a word in their companies Rolodex. Talk about outting your company as vulnerable to supply chain risk. Yikes.
@Yamahog
@Yamahog 2 месяца назад
@@skunkwerx9674 Agreed, However, Large Corporate entities like Health Authorities IT departments need to VM these updates before rolling the updates to their critical areas. It only requires one Virtual Machine to test the sanity of an update before a corporate roll-out. Stay Safe
@skunkwerx9674
@skunkwerx9674 2 месяца назад
@@Yamahog yep, totally agree as well.
@CallousCoder
@CallousCoder 2 месяца назад
Thank you! I have been preaching too, that this showed how inept those companies are that obviously rely blindly on computers, energy and possible even the internet to be up and running, without having any manual backup processes in place. Doctors offices that couldn't treat people, is insane! I worked in healthcare systems and we even had a chapter how to operate your practice in case of a system outage (which also covers power outages and hardware problems). Same with air carriers. Sure I can imagine that if SITA was down that you would not print a passenger manifest for every flight proactively (although perhaps we should). But the could've printed the passenger manifest of a flight an manually issued boarding cards -- like they did in the early 80s even. As a passenger you just would've have to content with the place available but that's better than being stuck on an airport in a line. And ironically I also worked on airports systems and energy production systems (and the latter aren't doing great in most countries who adopt the new climate agenda -- because the grid itself can't cope with the new demand and upscaling that infrastructure has in many places not caught up with the demand). It's insane we just blindly rely on systems and system updates these days....
Далее
No One Hires Jr Devs So I Made A Game
39:31
Просмотров 37 тыс.
My Burnout Experience
15:20
Просмотров 168 тыс.
The CrowdStrike Problem Isn’t A Simple Fix…
13:04
Просмотров 177 тыс.
They got away with this??
1:21:04
Просмотров 1,6 млн
Tarpit Ideas: The Sequel
13:50
Просмотров 65 тыс.
The Rabbit Is A Scam
56:17
Просмотров 246 тыс.
Linus Torvalds: Speaks on Hype and the Future of AI
9:02
CrowdStrike IT Outage Explained by a Windows Developer
13:40
The Brutal Truth Behind Tech Layoffs | Prime Reacts
1:20:34
Why Facebook Doesn't Use Git
31:01
Просмотров 274 тыс.
Microsoft Is KILLING Windows | ft. Steve @GamersNexus
19:19