5 ms·
The glaring question is how and why it was rolled out everywhere all at once? Many corporations have pretty strict rules on system update scheduling so as to e
by Guthur 2y ago
The glaring question is how and why it was rolled out everywhere all at once?
Many corporations have pretty strict rules on system update scheduling so as to ensure business continuity in case of situations like this but all of those were completely circumvented and we had fully synchronised global failure. It really does not seem like business as usual situation.
- chii 2y ago> strict rules on system update scheduling which crowdstrike gets to bypass because they claime themselves as an antivirus and malware detection platform - at least, this is what the executives they've wined and dined into the purchase contracts have been told. The update schedule is independently controlled by crowdstrike, rather than by a system admin i believe.
- xvector 2y agoCrowdStrike's reasoning is that an instantaneous global rollout helps them protect against rapidly spreading malware. However, I doubt they need an instantaneous rollout for every deployment.
- slenk 2y agoI feel like they need to at least first rollout to themselves
- kijin 2y agoWell, millions of PCs bluescreening at the same time does help stop a rapidly spreading malware. Only this time, crowdstrike itself has become indistinguishable from malware.
- imtringued 2y agoWhe I first saw news about the outage I was wondering what this malware "CrowdStrike" was. I mean, the name kind of sounds hostile.
- TeMPOraL 2y agoThey say that, but all I hear is immune system triggering a cytokine storm and killing you because it was worried you may catch a cold.
- inejge 2y agoThe glaring question is how and why it was rolled out everywhere all at once? Because the point of these updates is to be rolled out quickly and globally. It wasn't a system/driver update, but a data file update: think antivirus signature file. (Yes, I know it can get complicated, and that AV signatures can be dynamic... not the point here.) Why those data updates skipped validity testing at the source is another question, and one that CrowdStrike better be prepared to answer; but the tempo of redistribution can't be changed.
- deleted 2y ago[deleted]
- Brybry 2y agoBut is there a need for quick global releases? Is it realistic that there's a threat actor that will be attacking every computer on the whole planet at once? I can understand that it's most practical to update everyone when pushing an update to protect a few actively under attack but I can also imagine policies where that isn't how it's done, while still getting urgent updates to those under attack.
- padjo 2y agoIs there a need? Maybe, possibly, depends on circumstances. Is this what people are paying CS for? Absolutely.
- RowanH 2y agoAfter this I imagine there will be an option "do you want updates immediately, or updates when released - n, or n+2, n+6, n+24, n+48 hrs?" Given the choice I bet there's going to be surprisingly large number of orgs go "we'll take n+24hrs thanks"
- maeil 2y agoA customer should be able to test an update, whether a signature file or literally any kind of update, before rolling it out to production systems. Anything else is madness. Being "vulnerable" for an extra few hours carries less risk than auto-updates (of any kind) on production systems. As we've seen here. If you can point to hard evidence to the contrary, where many companies were saved just in time because of a signature update and would have been exploited if they'd waited a few hours, I'd love to read about it. It would have to have happened on a rather large scale for all of the instances combined to have had a larger positive impact than this single instance.
- hmottestad 2y agoFrom the article on The Verge it seems that this kind of update is downloaded automatically even if you disable automatic updates. So those users who took this kind of issue seriously would have thought that everything was configured correctly to not automatically update.
- danielPort9 2y ago> The glaring question is how and why it was rolled out everywhere all at once? Because it worked good for them so far? There are plenty of companies that do the same and we don’t hear about them until something goes wrong.