cross-posted from: https://awful.systems/post/1965658

Kind of sharing this because the headline is a little sensationalist and makes it sound like MS is hard right (they are, but not like this) and anti-EU.

I mean, they probably are! Especially if it means MS is barred from monopolies and vertical integration.

1 point

This is the best summary I could come up with:


A 2009 agreement insisted on by the European Commission meant that Microsoft could not make security changes that would have blocked the update from cybersecurity firm Crowdstrike that caused an estimated 8.5 million computers to fail, the Big Tech giant said in comments to the Wall Street Journal newspaper.

Thousands of flights were delayed or cancelled, leaving passengers stranded at airports worldwide, the UK’s NHS service was affected and contactless payments failed to work.

Microsoft has Windows Defender, its in-house alternative to CrowdStrike, but because of the 2009 agreement made to avoid a European competition investigation, had allowed multiple security providers to install software at the kernel level.

Microsoft’s main competitor, Apple, in 2020 blocked access to the kernel on its Mac computers, arguing it would improve security and reliability.

Speaking to the Wall Street Journal, a Microsoft spokesman said the company could not make a similar change because of the EU agreement.

Under its new Digital Markets Act, Europe is currently trying to force Apple to give access to its iPhone to allow alternative app stores and web browsers to be used.


The original article contains 348 words, the summary contains 183 words. Saved 47%. I’m a bot and I’m open source!

permalink
report
reply
58 points

Soooo… EU is responsible to write Crowdstrike code with bugs that gets deployed without any QA? Interesting. And EU is directing rules for the rest of the world as well, where the same issue happened as within EU? This is populist bullshit in full swing.

permalink
report
reply
46 points
*

As far as I understand it, the EU is to blame because it forced Microsoft to open up the Windows kernel for software such as Crowdstrike’s. Why the Linux kernel has protection against precisely the flaw that has occurred and the Windows kernel does not, however, remains MS’s secret.

permalink
report
parent
reply
31 points
*

The regulation only states that there must be a level playing field with respect to API access and possibilities in comparison for Microsoft tools and 3rd party tools. The regulation does not state that the APIs have to be inherently insecure and unstable if used in a wrong way, which is what happened. Crowdstrike released a buggy update that crashed their own driver, which is just showing how bad their software as a whole really is.

permalink
report
parent
reply
7 points

Linux has the same issue and was also affected by Crowdstrike earlier this year.

permalink
report
parent
reply
10 points

I know, but someone (KP Singh, I think?) already provided a fix for this. In the end, it’s not about any system being error-free, but about how these errors are dealt with. Crowdstrike screwed up and Microsoft could have fixed this vulnerability after the Linux kernel incident. Maybe. But now pointing the finger at an uninvolved third party is just PR.

permalink
report
parent
reply
2 points

Yet, faulty drivers crapoing your bed without a way for IT remotely being able to access the pc isnkinda your fault, they could have done that with zero EU violations…

permalink
report
reply
1 point
permalink
report
reply
42 points
*

The EU is not responsible for the QA failure of the market. Does Microsoft employ lunatics that do not recognise the reality?

permalink
report
reply
37 points
*
Deleted by creator
permalink
report
parent
reply
9 points

Watching USA lately, I think it’s an special American feature being off-reality.

permalink
report
parent
reply

Europe

!europe@feddit.org

Create post

News and information from Europe 🇪🇺

(Current banner: La Mancha, Spain. Feel free to post submissions for banner images.)

Rules (2024-08-30)

  1. This is an English-language community. Comments should be in English. Posts can link to non-English news sources when providing a full-text translation in the post description. Automated translations are fine, as long as they don’t overly distort the content.
  2. No links to misinformation or commercial advertising. When you post outdated/historic articles, add the year of publication to the post title. Infographics must include a source and a year of creation; if possible, also provide a link to the source.
  3. Be kind to each other, and argue in good faith. Don’t post direct insults nor disrespectful and condescending comments. Don’t troll nor incite hatred. Don’t look for novel argumentation strategies at Wikipedia’s List of fallacies.
  4. No bigotry, sexism, racism, antisemitism, dehumanization of minorities, or glorification of National Socialism.
  5. Be the signal, not the noise: Strive to post insightful comments. Add “/s” when you’re being sarcastic (and don’t use it to break rule no. 3).
  6. If you link to paywalled information, please provide also a link to a freely available archived version. Alternatively, try to find a different source.
  7. Light-hearted content, memes, and posts about your European everyday belong in !yurop@lemm.ee. (They’re cool, you should subscribe there too!)
  8. Don’t evade bans. If we notice ban evasion, that will result in a permanent ban for all the accounts we can associate with you.
  9. No posts linking to speculative reporting about ongoing events with unclear backgrounds. Please wait at least 12 hours. (E.g., do not post breathless reporting on an ongoing terror attack.)

(This list may get expanded when necessary.)

We will use some leeway to decide whether to remove a comment.

If need be, there are also bans: 3 days for lighter offenses, 14 days for bigger offenses, and permanent bans for people who don’t show any willingness to participate productively. If we think the ban reason is obvious, we may not specifically write to you.

If you want to protest a removal or ban, feel free to write privately to the mods: @federalreverse@feddit.org, @poVoq@slrpnk.net, or @anzo@programming.dev.

Community stats

  • 3.8K

    Monthly active users

  • 653

    Posts

  • 4.9K

    Comments