8 ms·
I think you represent the schism in your own post. Retail is hyper focused on the name Microsoft and Windows. But the enterprise and technical people are focuse
by dagaci 2y ago
I think you represent the schism in your own post. Retail is hyper focused on the name Microsoft and Windows. But the enterprise and technical people are focused on rolling back a bad CrowdStrike bad update. They will spend hours and even days focusing on doing that, asking why they were vulnerable to such an update and what they should have done to avert being vulnerable to a bad update.
And for them it will be a bit of a stretch to say Microsoft should have stopped us deploying CrowdStrike. I’m sure Microsoft would love to do just that and sell its own Microsoft Solution.
Now if enterprises decide to run only Linux, BSD, or MacOS would they have been invulnerable to a bad CrowdStrike update: https://www.google.com/search?q=crowdstrike+kernel+panic https://www.google.com/search?q=crowdstrike+kernel+panic
No so your entire premis is fully invalidated by a single google search.
On the other had I do feel Microsoft does have life far too easy in so many enterprises, but the fault here lies as much with the competition.
- gred 2y ago> it will be a bit of a stretch to say Microsoft should have stopped us deploying CrowdStrike I read GP's post to mean that if you take a step back, Windows' history of (in)security is what has led us to an environment where CrowdStrike is used / needed.
- rfoo 2y agoWell, then why would we have Linux and macOS versions of CrowdStrike Falcon Sensor (tm), too?
- oneeyedpigeon 2y agoTo make money? Just because CrowdStrike is available for Linux and Mac doesn't mean that a) people buy and use it in substantial numbers b) people need to buy it. It would be interesting to hear from someone using CrowdStrike in a Linux/Mac environment.
- onewheeltom 2y agoCS installed on my managed Mac. Generally no problems except randomly network stops working. Fixed by waiting.
- vladvasiliu 2y agoWe run Crowdstrike on Linux and Macs so that we can tick some compliance checkbox. Fun fact: they’ve recommended we don’t install the latest kernel updates since they usually lag a bit with support. We’re running Ubuntu LTS, not some bleeding edge arch. It now supports using ebpf so it’s somewhat better.
- ljm 2y agoHad it on my Mac a few years back and my long-lasting memory of it was how it: a) slowed down the performance of my machine to a crawl in a NodeJS project b) had my laptop fans spinning at full blast 24/7, even waking up the laptop overnight to do it It was purely for compliance, but I also got the impression that it was a bloated enterprise solution for the problem.
- berkes 2y agoFor the same reasons there's antivirus software for Mac and Linux. People coming from Microsoft systems just expect it to be required, so there's demand for it (demand != need). And in hybrid environments it may remove a weak link: e.g. a Linux mailserver that serves mail to Windows users best has virus detection for windows viruses.
- klooney 2y agoIt's not just those darn windows admins. Alot of the certifications customers care about- SOC II, ISO whatever, FedRamp, have line items that require it.
- raffraffraff 2y agoI've had to install server antivirus onto my Linux laptop at 4 different companies. Every time it's been a pain in the ass because the the only antivirus solutions I've found for Linux assume that "this must be a file server used by Windows clients". None of them are actually useful, so I've installed them and disabled them. There, box-checking exercise done.
- astura 2y agoIt's not just fake demand, it's required in most instances (example- STIG requirements)
- sam_lowry_ 2y agofake requirements?
- sam_lowry_ 2y agoI spent some time on STIG website out of curiosity. There seem to be down-to-earth practical requirements but only for Windows, cf. https://public.cyber.mil/stigs/gpo/ https://public.cyber.mil/stigs/gpo/ Why does it justify running antiviri on Linux is beyond my understanding. Weak, impotent, speechless IT personnel that can not face off incompetence?
- LtWorf 2y agoSo that work can't progress too fast?
- mbreese 2y agoWindows IT admins who don’t use or understand Linux/Mac. Who also buy at the enterprise level. And who probably have to install (perhaps unnecessary) endpoint protection to satisfy compliance checklists. The amount of Windows centric IT that gets pushed to Linux/Mac is crazy. I’ve been in meeting where using Windows based file storage was discussed at a possibility for an HPC compute cluster (Linux). And they were being serious. This was in theory so that central IT could manage backups.
- rietta 2y agoI can answer this. For the same reason I have run ClamAV on Linux development workstations. Because without it, we cannot attest that we have satisfied all requirements of the contract from the client's security organization. Also if you are a small business and are required to have cybersecurity liability insurance, the underwriter will require such sensors to be in place or you will get no policy.
- usefulcat 2y agoIf said underwriters don't typically cover things like the current CrowdStrike problem, that seems like a pretty big case of misaligned incentives.
- deleted 2y ago[deleted]
- skywhopper 2y agoThe policies are written by folks who have no understanding of different operating environments. The requirement "All servers and workstations must have EDR software installed" leads to top-level execs doing a deal with Crowdstrike because they "support" Linux, Mac, and Windows. So then every host must have their malware installed to check the box. Doesn't matter if it's useful or not.
- rietta 2y agoIndeed and insurance too. For our business, our professional errors and omissions coverage for years had the ability to cover cyber issues. No more. That requires cybersecurity insurance and the underwriters will not entertain underwriting a policy unless EDR is in place. They don't care if you are running OpenBSD and are an expert in cybersecurity who testifies in court cases or none of that. EDR from our list or no insurance.
- renewedrebecca 2y agoBecause of Security Theater.
- Aaronstotle 2y agoBecause it will look very bad if you answer, "No, our company has no Anti-virus because we are a macOS shop" on a security questionnaire
- p_l 2y agoFor macOS? Because without it you don't have certain monitoring and compliance capabilities that are standard built-ins in windows, plus for windows/linux/mac the monitoring capabilities are all useful and help detect unwanted operation.
- thaumasiotes 2y ago> I read GP's post to mean that if you take a step back, Windows' history of (in)security is what has led us to an environment where CrowdStrike is used / needed. Windows does have a history of insecurity, but it is no different from any other software in this regard. The environment would be the same in the absence of Windows. Attacks are developed for Windows because attacks against Windows are more valuable -- they have a large number of potential targets -- not because they're easier to develop.
- AgentME 2y agoMacOS has been phasing out support for third-party kernel extensions and CrowdStrike doesn't use a kernel extension there according to some other posts.
- ehutch79 2y agoAlso, it does actually work on MacOS despite this. We’ve had it catch someone getting malware.
- nijave 2y agoWhether you like macOS or not, they definitely are innovating in this space. They (afaik) are the only OS with more granular data access for permissions as well (no unfettered filesystem access by default, for instance) It's also a shame CrowdStrike doesn't take kernel reliability seriously
- fsflover 2y agoQubes OS has a better model, security by compartmentalization: everything runs in separate VMs with hardware virtualization.
- nijave 2y agoAndroid and iOS have compartmentalization as well but it's not hardware level (at least as far as I know).
- throwaway48476 2y agoQubes is great but no desktop GPU supports virtualization.
- klodolph 2y agoI could be happy if the GPU was only used for compositing. If I were doing ML work, maybe I do that work in an ephemeral cloud environment. I know this doesn’t cover everyone’s use case, but it doesn’t have to.
- graemep 2y agoThe issue with Crowdstrike on Linux did not cause widespread failures, so its clear that the majority of enterprises that do run their servers on Linux were not affected. They were invulnerable because they do not need Crowdstrike or similar. Linux (or BSD) servers do not usually require third party kernel modules. Linux desktops might have the odd video driver or similar.
- Vilian 2y agoThe difference is that i van easily rollback a linux system, a complete update too, nota on windows
- miah_ 2y agoCrowdstrike on Linux is only useful for appeasing corporate auditors, and making Crowdstrike money.
- lizknope 2y agoIn the case of a bad Linux kernel update I would just reboot and pick the previous kernel from the boot menu. By default most Linux distributions keep the last 3. I'm not an IPMI remote management expert but it may be possible to script this. All my machines at home run Linux except for my work laptop. It is stuck in this infinite blue screen reboot loop. Because we use Bitlocker I can't even get it into safe mode or whatever to delete the bad file. I think IT will have to manually go around to literally 8,000 work laptops and fix them individually.
- t_spins 2y agoYou would "just pick the previous kernel from the boot menu". That's funny, cause in this case you could "just delete the file causing the issue." Anything can sound easy and simple if you state it that way. How do you access the boot menu for a server running in the cloud, which you normally just SSH into (RDP in Windows' case)? About your last paragraph: we have just started sending out the bitlocker keys to everyone so it can be done by them too. Surely not best practice, but it beats everyone having to line up at the helpdesk.
- lizknope 2y agoI can't delete a file if the machine doesn't finish booting. Unless you are suggesting removing the drive and putting it in another machine. That requires a screwdriver and 5 minutes vs. the 10 seconds to reboot and pick a different kernel. I'm not talking about the cloud. I am talking about the physical machines sitting in front of me specifically my work laptop. I am an integrated circuit computer chip designer, not a data center IT person. I have seen IPMI on the servers in our office. Do cloud data centers have this available to people? I have a cheap cloud VM that I pay $3.50 a month. I normally just SSH in but if I want to install a new operating system or SSH is not responding then I log in to the web site and get a management console. I can get a terminal window and login, I can force a reboot, or I can upload an ISO image of another operating system and select that as the boot device for the next reboot and install that. Does your cloud service not have something like this? I don't know what our corporate IT dept wants to do. We all work from home on Friday and I can't login to check email so I'll just wait until Monday as there is nothing urgent today anyway.
- pepa65 2y agoIf you ran "only Linux, BSD, or MacOS" on a Microsoft hypervisor, yes. I would never recommend that, and your link exemplifies one reason why.