4 ms·
What saved my company from this is the recommended policy I’ve had the last three companies I’ve implemented this in. N -1. The first time I ever rolled out Fa
by someonehere 2y ago
What saved my company from this is the recommended policy I’ve had the last three companies I’ve implemented this in. N -1.
The first time I ever rolled out Falcon, the sales engineer said, “if you want to be on the latest when it releases, choose this policy. Generally customers like to be one release (N -1) behind. This is the safest option in my experience. We rarely have issues but this is the way to prevent issues if we do ship something bad.”
I’ve been telling other admins this is the safest option moving forward. I don’t see a need for my org to run bleeding edge releases of newer products. This also applies to OS updates unless it’s a zero day. Major OS releases I wait for the first .1 update to release. Currently doing this with Ubuntu Desktop 24 LTS as it shipped with missing features from 22 and a broken autosetup functionality. August is the first update to 24 LTS and we’ll test and determine if the bugs have been squashed.
I can’t think of any way to always be on the latest upgrade of anything critical. All of these companies were on the bleeding edge release of CrowdStrike and it brought a lot down globally.
- xyst 2y ago(N-1) release is recommended on any product/software that cannot be independently monitored (ie, proprietary shit).
- cgb_ 2y agoN-1 didn't save you, nor did N-2: https://news.ycombinator.com/item?id=41015038 https://news.ycombinator.com/item?id=41015038 > "b) Since n, n-1 and n-2 versions of the sensor all died equally spectacularly, that bug as been around for at least three versions of csagent.sys." There's so much misinformation around this Crowdstrike issue. The change deployed was in what is referred to as a "channel file" which isn't part of the software update mechancism (what you call N-X) but part of the intra-day frequent signature/channel updates it gets (that we all have no control over). Crowdstrike are calling it an unfortunate "logic error" but they and few others are talking about the how a binary payload could get released to the public without seemingly any pre-release testing of the payload. If the content that was made available to the public had ran on a test endpoint, they would have discovered this "logic error" before taking down a high number of the world's systems simultaneously.