288
submitted 1 year ago by sag@lemm.ee to c/showerthoughts@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] Carighan@lemmy.world 137 points 1 year ago

And keep in mind, the falcon sensor exists for Linux. All those big companies largely use it.

Essentially we just got lucky that their buggy patch only affected the windows version of the sensor in a showstopping way. Could have been all major OS.

[-] ludrol@bookwormstory.social 11 points 1 year ago
[-] nevemsenki@lemmy.world 13 points 1 year ago

That's only true if you run falcon-sensor in ebpf and not kmod mode.

[-] lord_ryvan@ttrpg.network 5 points 1 year ago

The issuw didn't affect Linux and macOS systems with Crowdstrike Falcon installed, though, only Windows systems.

On Windows, booting into Safe Mode and removing C:\Windows\System32\Drivers het bestand C-00000291*.sys temporarily solves the BSOD issue, as well.

[-] Brkdncr@lemmy.world 25 points 1 year ago

The point is that it could have. Or maybe some unknown 0-day gets used by someone out to cause chaos instead of collect random.

[-] lord_ryvan@ttrpg.network 8 points 1 year ago

That's true

On one hand I hope people are smart enough to run updates to critical systems on a test environment, first. On the other hand I've learned that that is not at all the case yesterday.

[-] Brkdncr@lemmy.world 11 points 1 year ago

Many security products have no test option. One I’m using has a best practice of a 15 minute delay between test and prod and no automation to suspend besides relying on the vendor to pull the update it within 15 mins if it were to go full crowdstrike.

[-] SeeJayEmm@lemmy.procrastinati.org 10 points 1 year ago

The problem her was that this wasn't a traditional update. It was delivered automatically as a "content" update (like how old av would have definition update). We were given no room to test.

[-] sag@lemm.ee 4 points 1 year ago
this post was submitted on 20 Jul 2024
288 points (100.0% liked)

Showerthoughts

36284 readers
1741 users here now

A "Showerthought" is a simple term used to describe the thoughts that pop into your head while you're doing everyday things like taking a shower, driving, or just daydreaming. The most popular seem to be lighthearted clever little truths, hidden in daily life.

Here are some examples to inspire your own showerthoughts:

Rules

  1. All posts must be showerthoughts
  2. The entire showerthought must be in the title
  3. No politics
    • If your topic is in a grey area, please phrase it to emphasize the fascinating aspects, not the dramatic aspects. You can do this by avoiding overly politicized terms such as "capitalism" and "communism". If you must make comparisons, you can say something is different without saying something is better/worse.
    • A good place for politics is c/politicaldiscussion
  4. Posts must be original/unique
  5. Adhere to Lemmy's Code of Conduct and the TOS

If you made it this far, showerthoughts is accepting new mods. This community is generally tame so its not a lot of work, but having a few more mods would help reports get addressed a little sooner.

Whats it like to be a mod? Reports just show up as messages in your Lemmy inbox, and if a different mod has already addressed the report, the message goes away and you never worry about it.

founded 2 years ago
MODERATORS