4 ms·
Tech has become such an unbelievable house of cards full of various people covering their asses by offloading these tasks to third party trusted actors. Consid
by thepasswordis 2y ago
Tech has become such an unbelievable house of cards full of various people covering their asses by offloading these tasks to third party trusted actors.
Consider the recent npm supply chain attack a few weeks ago, or the attempted SSH attack before that, or the solar winds attack before that.
This type of thing is institutionally supported, and in some cases when you’re working with with the government, practically required.
We’re going to see more of this.
- fishpen0 2y agoNew laws and regulations make companies more liable for being hacked Companies buy cyber insurance to reduce their risk if they are found liable Cyber insurance companies force tech staff to install garbage software in order to check compliance boxes. Garbage software breaks Turns out everyone used the exact same brand of garbage software to check the same garbage box People in hospitals die When you reduce everything to a checkbox and eliminate critical thinking to apply the need to the exact situation you end up with 90% of companies running zscaler and crowdstrike "This is just how you solve this, everyone does it this way in our industry"
- deleted 2y ago[deleted]
- anal_reactor 2y agoThis is precisely how it happens
- throwitaway1123 2y ago> Consider the recent npm supply chain attack a few weeks ago What supply chain attack are you referring to?
- thepasswordis 2y agoYou know what, I'm sorry, it was polyfill.io, not an NPM package.
- commandlinefan 2y ago> We’re going to see more of this If history is any guide, no legitimate lessons will be learned, but mitigation strategies will be put in place that actually make everything worse and ensure that the next catastrophe will be even more catastrophic.
- commercialnix 2y agoNo, not "tech", just Microsoft Windows. Those of us serving Linux based endpoints (that yes, do also run Windows apps with our endpoint-local VDI stack) have happy customers.
- santoshalper 2y agoCrowdstrike broke Red Hat and Debian earlier this year. There but for the grace of God. If you install software there runs in kernel space, you may have a really bad time when it breaks.
- consteval 2y agoSolution: don't run software that runs in kernel mode. It's wildly unpopular in Linux, rampant on Android, fairly standard in Windows, and impossible on Mac. We've made this too normalized. Such software is inherently risky, and the fact it's a blackbox blob makes it unauditable. Even nvidia is moving away from kernel blobs.
- commercialnix 2y ago> Crowdstrike broke Red Hat and Debian earlier this year. For Crowdstrike customers foolish enough to be Crowdstrike customers, yes. The nature of the software pipelines for Red Hat and Debian are very friendly to continuous integration and testing in a way that Windows can not be, at least not without Microsoft sharing source code, which to be fair Crowdstrke is one of the companies they may actually do that with. Nonetheless, other vendors can choose to do proper cicd with Red Hat and Debian without asking Microsoft.
- commercialnix 2y agoCrowdstrike is not able to break my customers' Linux endpoints. My customers hired my company, not Crowdstrike.
- rustcleaner 2y agoNow imagine the base level of your universal machines is opaque proprietary code, its necessity enforced by cryptographic signature. Imagine that the processes putting that code there, which you can't touch because intellectual property rentier reasons, are varying degrees of what we see here today with Crowdstrike, and suddenly it makes more sense to ensure total and complete owner sovereignty over his universal machines so owners can implement diversification strategies.