5 ms·
Oh, if you are also running Crowdstrike on linux, here are some things we identified that you _can_ do: - Make sure you're running in user mode (eBPF) instead
by JackC 2y ago
Oh, if you are also running Crowdstrike on linux, here are some things we identified that you _can_ do:
- Make sure you're running in user mode (eBPF) instead of kernel mode (kernel module), since it has less ability to crash the kernel. This became the default in the latest versions and they say it now offers equivalent protection.
- If your enterprise allows, you can have a test fleet running version n and the main fleet run n-1.
- Make sure you know in advance who to cc on a support ticket so Crowdstrike pays attention.
I know some of this sounds obvious, but it's easy to screw up organizationally when EDR software is used by centralized CISOs to try to manage distributed enterprise risk -- like, how do you detect intrusions early in a big organization with lots of people running servers for lots of reasons? There's real reasons Crowdstrike is appealing in that situation. But if you're the sysadmin getting "make sure to run this thing on your 10 boxes out of our 10,000" or whatever, then you're the one who cares about uptime and you need to advocate a bit.
- guax 2y agoIm suspicious that turning it off entirely would also provide equivalent protection as kernel and user space mode. If not more more.
- School-Cotton 2y agoJust a nit, I don't think it's correct to call eBPF "user mode". It's just a different, much more sandboxed, way of running kernel-mode code.
- anotherhue 2y agoWe could call it, I don't know, "Protected Mode"?
- yencabulator 2y agoIf you can crash Linux with an eBPF program, many more asses will have fires lit under them than just this one vendor.
- senectus1 2y agoheh.. Linus would have a fit :-D
- boudin 2y agoIt's what crowdstrike call it. To run falcon sensor as ebpf, you need to set it up as "user mode" which, I agree with you, is poorly named.
- ghostpepper 2y agoI would wager that even most software developers who understand the difference between kernel and user mode aren't going to be aware there is a "third" address space, which is essentially a highly-restricted and verified byte code virtual machine that runs with limited read-only access to kernel memory
- School-Cotton 2y agoNot that it changes your point, and I could be wrong, but I'm pretty sure eBPF bytecode is typically compiled to native code by the kernel and runs in kernel mode with full privileges. Its safety properties entirely depend on the verifier not having bugs.
- ghostpepper 2y agoall code is native code eventually (although there are experimental cpus that can execute java byte code directly eg. [0]https://en.wikipedia.org/wiki/Java_processor https://en.wikipedia.org/wiki/Java_processor )
- School-Cotton 2y agoNo, lots of VMs don't have any JIT and just interpret bytecode with a loop around a big switch statement (e.g. Python before 3.13).
- parl_match 2y agofwiw there's like a billion devices out there with cpus that can run java byte code directly - it's hardly experimental. for example, Jazelle for ARM was very widely deployed
- ChainOfFools 2y agoListed in that wiki, along with the much older Picojava
- MrDrMcCoy 2y agoDepending on what kernel I'm running, CrowdStrike Falcon's eBPF will fail to compile and execute, then fail to fall back to their janky kernel driver, then inform IT that I'm out of compliance. Even LTS kernels in their support matrix sometimes do this to me. I'm thoroughly unimpressed with their code quality.
- 1oooqooq 2y agodo you work for them? if not what took you to do free tech support? ... honestly this looks a little insane
- alwa 2y agoJackC mentioned in the parent comment that they work for a civic tech lab, and their profile suggests they’re affiliated with a high-profile academic institution. It’s not my place to link directly, but a quick Google suggests they do some very cool, very pro-social work, the kind of largely thankless work that people don’t get into for the money. Perhaps such organizations attract civic-minded people who, after struggling to figure out how to make the product work in their own ecosystem, generously offer high-level advice to their peers who might be similarly struggling. It feels a little mean-spirited to characterize that well-meaning act of offering advice as “insane.”
- 1oooqooq 2y agoCivic minded people would point how to fully understand the base of your mission critical system. not help a crack addict chose a better toothpaste.