5 ms·
This company has post-apocalyptic style photos to make you panic-buy their solution. https://ibb.co/Bc6n527 https://ibb.co/Bc6n527 "62 minutes could bring you
by patates 2y ago
This company has post-apocalyptic style photos to make you panic-buy their solution.
https://ibb.co/Bc6n527 https://ibb.co/Bc6n527
"62 minutes could bring your business down"
I guess they could bring all the businesses down much quicker.
edit: link https://www.crowdstrike.com/en-us/#teaser-79minutes-adversary-1 https://www.crowdstrike.com/en-us/#teaser-79minutes-adversar...
- lamp_book 2y agoBoy, that is some corny branding.
- bob1029 2y agoI agree but I've also personally witnessed how effective this crap is on a certain cohort of IT managers. You can see the 3 or 4 gears grinding together in their head... something like "oh my goodness look at all the things I get for one purchase order!".
- lamp_book 2y agoI could certainly see that! Haha.
- deleted 2y ago[deleted]
- hulitu 2y ago> "62 minutes could bring your business down" > I guess they could bring all the businesses down much quicker. It is because the buyer does not get the message. And, when they get it, it is too late.
- sofixa 2y agoAnd for much longer.
- joenot443 2y agoTheir "Statement" is remarkably aloof for having brought down flights, hospitals, and 911 services. "The issue has been identified, isolated and a fix has been deployed." Maybe I'm misunderstanding what I read elsewhere, but is the machine not BSODing upon boot, prior to a Windows Update service being able to run? The "fix" I see on reddit is roughly: Workaround Steps: 1. Boot Windows into Safe Mode or the Windows Recovery Environment 2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory 3. Locate the file matching “C-00000291*.sys”, and delete it. I'm horrified at the thought of tens of thousands of novice Windows users digging through System32 to delete driver files; can someone set my mind at ease and assure me this will eventually be fixed in an automated fashion? https://www.crowdstrike.com/blog/statement-on-windows-sensor-update/ https://www.crowdstrike.com/blog/statement-on-windows-sensor...
- gulbanana 2y agoIt cannot and will not be fixed in an automated fashion.
- aaronmdjones 2y agoOf course it can be fixed in an automated fashion; it just requires effort. The machines should have netboot enabled so that new validated operating system images can be pushed to them anyway, so you just write a netboot script to mount the filesystem and delete the file, then tell the netboot server that you're done so it doesn't give you the same script again when it reboots. It's like two hours of work with dnsmasq and a minimal Linux ISO. The only problem is that much of the work is not shareable between organisations; network structures differ, architectures may differ, partition layout may differ, the list of assets (and their MAC addresses) will differ. Edit: + individual organisations won't be storing their BitLocker recovery keys in the same manner as each other either. You did back up the recovery keys when you enabled BitLocker, right? Modern cryptsetup(8) supports a BITLK extension for unlocking said volumes with a recovery key. Again, this can be scripted.
- csomar 2y agoIf the affected organizations had such an organized setup, they probably won't need crowdstrike in the first place. The product is made so that companies that don't understand (and won't invest) in security can just check that box by installing the software. Everyone is okay with this.