BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] CrowdStrike Fiasco
- Subject: [Discuss] CrowdStrike Fiasco
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- Date: Mon, 22 Jul 2024 15:20:07 -0400
- In-reply-to: <ac39bd9e-98dc-4320-aade-2d35025bd612@syntheticblue.com>
- References: <20240722090043.3d5b68ef.Richard.Pieri@gmail.com> <20240722142315.ogmd5qla5hrcr5lz@randomstring.org> <ac39bd9e-98dc-4320-aade-2d35025bd612@syntheticblue.com>
> On 2024-07-22 10:23, Dan Ritter wrote: >> Rich Pieri wrote: >>> While the CrowdStrike (not to be confused with CloudFlare) fiasco >>> Friday affected millions of Windows computers, Linux is not immune to >>> such an event. I'm not familiar with CrowdStrike Falcon, but my >>> employer uses competing PaloAlto Networks' Cortex XDR. It's a similar >>> service with similar capabilities, and there are Linux endpoint >>> packages. These hook themselves into the kernel at a low level via >>> modules so they can do things like isolate individual machines when >>> they exhibit suspicious or malicious behavior. >>> >>> They also could, with the right -- or wrong -- updates, crash or hang >>> the kernel at startup. >>> >>> Recovery under such conditions would be nearly identical to the process >>> that 8.5 million Windows computers are undergoing: boot some form of >>> recovery media, mount the filesystem where the endpoint software or >>> data are installed, delete or replace the relevant files, and reboot. >> >> In fact, CrowdStrike Falcon has a Linux version; it also >> requires a kernel module; and it exhibited a similar -- but >> different crash back in March. > > I wonder if their QA department is hiring.... Dan G Just like when George Kurtz was CTO at McAfee in April 2010 and a very similar issue happened that diabled millions of Windows XP system that also required manual repair. Soon after, McAfee went south and was bought by Intel. A year later George Kurtz started crowdstrike in 2011. Now in 2024, crowdstrike did the same thing. How long do you its going to survive after this? > > _______________________________________________ > Discuss mailing list > Discuss at driftwood.blu.org > https://driftwood.blu.org/mailman/listinfo/discuss >
- References:
- [Discuss] CrowdStrike Fiasco
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] CrowdStrike Fiasco
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] CrowdStrike Fiasco
- From: daniel at syntheticblue.com (Daniel M Gessel)
- [Discuss] CrowdStrike Fiasco
- Prev by Date: [Discuss] CrowdStrike Fiasco
- Next by Date: [Discuss] CrowdStrike Fiasco
- Previous by thread: [Discuss] CrowdStrike Fiasco
- Next by thread: [Discuss] CrowdStrike Fiasco
- Index(es):