5 ms·
Really impressive that they got thru an entire develop, build, approval, and documentation process in just about 2 days. Not that any of those steps are extreme
by etskinner 2y ago
Really impressive that they got thru an entire develop, build, approval, and documentation process in just about 2 days. Not that any of those steps are extremely hard for this fix, but I'm always impressed when big corporations can move so fast
- phoe-krk 2y ago> an entire develop, build, approval, and documentation process in just about 2 days ...on a weekend.
- ssahoo 2y agoWhen their bottom line and head is at stake, what were they supposed to do?
- Bognar 2y agoThey could say "third party kernel modules are installed at your own risk" and provide the usual level of business hours support. CrowdStrike fucked up and Microsoft is helping its customers recover from CrowdStrike's fuckup.
- ssahoo 2y agoThey recommend crowdstrike to customers. Now they are trying to at least skim some good will. Also bad a kernel module that can ruin the OS is partially their fault.
- tatersolid 2y agoMicrosoft does not “recommend CrowdStrike”. Microsoft actually sells its own competitor to CrowdStrike (Defender XDR).
- concerned_user 2y agoI also think Microsoft should be responsible, they gave the keys to sign the kernel driver so I expect that driver to at least be subject to regular testing and scrutiny not just when initial release was made.
- Kwpolska 2y agoThe issue was caused by a data file, Microsoft is not involved in signing or testing individual data files.
- _flux 2y agoThe actual issue was with the signed code reading the data files that the data file update just brought to surface. But I don't think Microsoft verifies customer code, they might not even have access to it.
- concerned_user 2y agoYou are right Microsoft are not checking the 3rd party code itself they are only running a lot of tests on the compiled code. There is a recent video now from a former Microsoft employee where he explains that those drivers that get WHQL certification are ran on test machines in stress conditions for some time, or at least that is how it used to be when he worked there. Since that process is probably quite slow to be able to push update within a couple hours Crowdstrike just bypassed the QA testing by injecting their own data files into the driver.
- _flux 2y agoI guess Microsoft testing lacks fuzzing, then—as does Crowdstrike's.
- Bognar 2y agoThey didn't "give the keys", they have a signing infrastructure that is meant to be used for validating organizational identity and origins of code. They have a quality checking system, but it's only required for certain levels of Microsoft backing. I think it used to be called the Windows Logo Program or something?
- LASR 2y agoSigning is meant only to verify the identity of the organization producing the signed artifact. It’s not meant to signify that it’s bug-free.
- Plasmoid2000ad 2y agoMicrosoft competes directly CrowdStrike with Defender across multiple areas - I'm not sure they recommend them to customer over their own products at the cost of losing sales. I don't think Microsoft is realistically in a position to forbid other companies from writing kernel level modules, from an antitrust standpoint I would think that would land them under investigation(s)
- SoftTalker 2y agoThat the OS needs a product like Crowdstrike in order to be safely used is also their fault.
- gus_massa 2y agoThey made a special memory allocator for Windows 95 to avoid a crash caused by a bug in SimCity https://www.joelonsoftware.com/2000/05/24/strategy-letter-ii-chicken-and-egg-problems/ https://www.joelonsoftware.com/2000/05/24/strategy-letter-ii... They are not only backward compatible or bug compatible. They are others-person-bug compatible. It's the only way to prevent users thinking about switching to another OS.
- HPsquared 2y agoReminds me of this famous post from Linus about being "bug-compatible". https://lkml.org/lkml/2012/12/23/75 https://lkml.org/lkml/2012/12/23/75
- jorvi 2y agoOne thing I’ve never understood about “kernel never breaks user space”.. doesn’t that completely atrophy the kernel, preventing it from ever having big rewrites or architectural changes? What if an initial implantation was terrible, and there are 100x performance improvements to be had by doing a breaking change?
- capitainenemo 2y agoImplement a new API for the better route, isolate the terrible code as much as possible, notify the users, deprecate it, and remove it or move it to a userspace shim after enough years had past and almost everyone was off it?
- HPsquared 2y agoThat must be a pretty well-worn path by now.
- Arwill 2y agoIf anything, then events like this makes decision makers rethink if they really should run Windows everywhere. Why does a flight schedule display has to run Windows, for example? It might not be their fuckup, but they will lose users too, for sure.
- codebolt 2y agoSame thing already happened on Linux, but it failed to make a big enough splash to make any headlines. Putting Windows at fault here is unfair. https://www.newsbytesapp.com/news/science/before-affecting-windows-crowdstrike-update-crippled-linux-systems/story https://www.newsbytesapp.com/news/science/before-affecting-w...
- nerdjon 2y agoI sympathize with the engineers, QA, and everyone involved in getting this out. I have to imagine it was a lot of long hours, and the testing was insane. The last thing I want to do is put this tool out and it somehow messes things up more. But glad it’s out. Hopefully it helps with the remaining machines and with any that are being problematic.
- ffhhj 2y agoSurveillance software is top priority of BigCo's nowadays. If they prove to be useful for governments they'll get softer antimonopoly measures.
- selykg 2y agoI wrote and maintained a tool that was sent to users when something went wrong. Man was I always afraid and stressed that the tool meant to help users when they were already having a failure was also having a failure.
- xinayder 2y agoThey probably got an exemption to fast track the release because this is a critical issue. I wouldn't expect testing to be so thorough for a release in 2 days. The exemption is more likely.
- switch007 2y ago> develop, build, approval, and documentation process Under the immense pressures, I'm sure one or two of the usual steps were missed or reduced (perhaps this is what you were insinuating?)
- Kwpolska 2y agoTo be fair, there isn't a whole lot of code there. I wouldn't be surprised if Microsoft had the WinPE generator written already for some other project.
- kchr 2y agoYeah, WinPE media tools have been around for years. Here is an article from 2021 (although it has been a thing long before then): https://learn.microsoft.com/en-us/windows-hardware/manufacture/desktop/download-winpe--windows-pe?view=windows-11 https://learn.microsoft.com/en-us/windows-hardware/manufactu... Still, customizing the toolchain to fit this particular scenario and making sure it works, in two days, is commendable effort.
- mkl95 2y agoThey are not claiming they built it themselves. This kind of tool could easily be an offshore job.
- aaomidi 2y agoProbably not doing that with this incident. But FBI/NSA is probably involved.
- beefnugs 2y agoActually they may not have a choice, since they have forced people to install their local windows with a Microsoft login, and tying bitlocker to this login, there is probably many situations out there that requires microsoft login supported winPE just to fix this