Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] CrowdStrike Fiasco



While the CrowdStrike (not to be confused with CloudFlare) fiasco
Friday affected millions of Windows computers, Linux is not immune to
such an event. I'm not familiar with CrowdStrike Falcon, but my
employer uses competing PaloAlto Networks' Cortex XDR. It's a similar
service with similar capabilities, and there are Linux endpoint
packages. These hook themselves into the kernel at a low level via
modules so they can do things like isolate individual machines when
they exhibit suspicious or malicious behavior.

They also could, with the right -- or wrong -- updates, crash or hang
the kernel at startup.

Recovery under such conditions would be nearly identical to the process
that 8.5 million Windows computers are undergoing: boot some form of
recovery media, mount the filesystem where the endpoint software or
data are installed, delete or replace the relevant files, and reboot.

-- 
\m/ (--) \m/



Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org