Cybersecurity firm Crowdstrike pushed an update that caused millions of Windows computers to enter recovery mode, triggering the blue screen of death. Learn …

66 points
*

Are there really a billion systems in the world that run Crowdstrike? That seems implausible. Is it just hyperbole?

permalink
report
reply
44 points

Probably includes a bunch of virtual machines.

permalink
report
parent
reply
21 points

Yeah, our VMs completely died at work. Has to set up temporary stuff on hardware we had laying around today. Was kinda fun, but stressful haha.

permalink
report
parent
reply
9 points

Could you just revert VMs to a snapshot before the update? Or do you not take periodic snapshots? You could probably also mount the VM’s drive on the host and delete the relevant file that way.

permalink
report
parent
reply
27 points

I doubt it’s too much of a stretch, since even here in australia, we’ve had multiple airlines, news stations, banks, supermarkets and many others, including the aluminium extrusion business my father works at, all go down, scale this do hundreds of countries with populations tenfold of ours, it puts it into perspective that there may even be more than a billion machines affected

permalink
report
parent
reply
1 point
Deleted by creator
permalink
report
parent
reply
16 points

Despite how it may seem on Lemmy, most people have not yet actually switched to Linux. This stat is legit.

permalink
report
parent
reply
9 points

I know that Windows is everywhere, I just don’t know the percentage of Windows computers that run Crowdstrike.

permalink
report
parent
reply
10 points

Keep in mind, it’s not just clients, but servers too. A friend of mine works for a decently sized company that has about 1600 (virtual) servers internationally. And yes, all of them were affected.

permalink
report
parent
reply
12 points

Yes

permalink
report
parent
reply
5 points

Sounds pretty plausible to me. An organization doesn’t have to be very big to get into the hundreds or thousands of devices on a network when you account for servers and VM.

A company with 40 employees all accessing and RDS server using a company laptop is looking at 85+ devices already

permalink
report
parent
reply
0 points
*
Deleted by creator
permalink
report
parent
reply
62 points
*

Whoda thunk automatic updates to critical infrastructure was a good idea? Just hope healthcare life support was not affected.

permalink
report
reply
68 points

Many compliance frameworks require security utilities to receive automatic updates. It’s pretty essential for effective endpoint protection considering how fast new threats spread.

The problem is not the automated update, it’s why it wasn’t caught in testing and how the update managed to break the entire OS.

permalink
report
parent
reply
7 points
*

It is pretty easy to imagine separate streams of updates that affect each other negatively.

CrowdStrike does its own 0-day updates, Microsoft does its own 0-day updates. There is probably limited if any testing at that critical intersection.

If Microsoft 100% controlled the release stream, otoh, there’d be a much better chance to have caught it. The responsibility would probably lie with MS in such a case.

(edit: not saying that this is what happened, hence the conditionals)

permalink
report
parent
reply
13 points

I don’t think that is what happened here in this situation though, I think the issue was caused exclusively by a Crowdstrike update but I haven’t read anything official that really breaks this down.

permalink
report
parent
reply
-18 points
*
Removed by mod
permalink
report
parent
reply
11 points

lol, ok

permalink
report
parent
reply
5 points
*

Ok Russian comrade. Security in companies is terrible. You’re right. It’s just a giant grift.

Now, go buy some limited time offer fight fight fight shoes from agent orange.

permalink
report
parent
reply
18 points

Hospital stuff was affected. Most engineers are smart enough to not connect critical equipment to the Internet, though.

permalink
report
parent
reply
20 points

I’m not in the US, but my other medical peers who are mentioned that EPIC (the software most hospitals use to manage patient records) was not affected, but Dragon (the software by Nuance that we doctors use for dictation so we don’t have to type notes) was down. Someone I know complained that they had to “type notes like a medieval peasant.” But I’m glad that the critical infrastructure was up and running. At my former hospital, we used to always maintain physical records simultaneously for all our current inpatients that only the medical team responsible for those specific patients had access to just to be on the safe side.

permalink
report
parent
reply
5 points

That’s actually a very smart idea, keeping physical records of every inpatient. Wonder why the ai companies don’t do transcription of medical notes, instead of trying to add ai features to my washer/ dryer combo. Just seems like a very practical use of the tech

permalink
report
parent
reply
4 points

This is pretty much correct. I work in an Epic shop and we had about 150 servers to remediate and some number of workstations (I’m not sure how many). While Epic make not have been impacted, it is a highly integrated system and when things are failing around it then it can have an impact on care delivery. For example if a provider places a stat lab order in Epic, that lab order gets transmitted to an integration middleware which then routes it to the lab system. If the integration middleware or the lab system are down, then the provider has no idea the stat order went into a black hole.

permalink
report
parent
reply
4 points

I’m an Epic analyst - while Epic was fine, many of our third party integrations shit the bed. Cardiology (where I work) was mostly unaffected aside from Omnicell being down, but the laboratory was massively fucked due to all the integrations they have. Multiple teams were quite busy, I just got to talk to them about it eventually.

permalink
report
parent
reply
1 point

“type notes like a medieval peasant.”

Huh. I thought medieval peasants were usually illiterate? Even less computer literate?

permalink
report
parent
reply
3 points

I work healthcare adjacent and some providers were affected as expected. Hoping as well that those critical systems were not, but that chance is non zero.

permalink
report
parent
reply
22 points

There is no learning, companies just move to different antivirus. The new hotness, the cycle repeats over and over until the new antivirus does this same shit. Look at McAfee in 2010, in fact the CEO of Crowdstrike was the CTO of McAfee then. That easily took down millions of windows XP machines.

permalink
report
reply
3 points

in fact the CEO of Crowdstrike was the CTO of McAfee then

The hero of Linux adoption then. All hail - what’s the name of that guy?

permalink
report
parent
reply
6 points

This isn’t the Windows L you think it is. This can and has happened on Linux. It’s a Crowdstrike/Bad corp IT issue.

permalink
report
parent
reply
2 points

I know, but the whole culture of using such things is Windows-centered.

permalink
report
parent
reply
18 points

permalink
report
reply
14 points

Combing over it’s Wikipedia article, this company already had a series of other issues.

Sucks to anyone who ever relied on them. Oh look at that, they’ve been acquiring other security startups and companies. Perhaps that should also be looked into as well?

permalink
report
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 18K

    Monthly active users

  • 5.8K

    Posts

  • 122K

    Comments