3 ms·
There's also orders of magnitudes more machines today than 20 years ago -- so it should be easier to infect more machines now than before, and yet no one can si
by smartpeoplebelw 2y ago
There's also orders of magnitudes more machines today than 20 years ago -- so it should be easier to infect more machines now than before, and yet no one can sight a virus that was as quickly moving and damaging as what crowdstrike did through gross negligence.
Be better.
- orf 2y agoThis entire thread is stupid. Computer security as a whole has improved, whilst the complexity of interconnected systems has exponentially increased. This has made the barrier to entry for malware higher, and so means we no longer have the same historic examples of large scale worms targeting consumer machines that we used to. At the same time the financial rewards for finding and exploiting a vulnerability within an organisations complex stack have greatly increased. The rewards are coupled to the time it takes to execute on the vulnerability. This leads to what we have today: localised, and often specialised attacks against valuable targets that are executed as fast as possible in order to minimise the chance a target has to respond or the vulnerability they are exploiting to be burned. Of course the “smart people belw” must know this, so it’s unclear why they are pretending to be dumb.
- canureadno 2y ago[flagged]
- orf 2y agoYou’re not displaying a pattern of healthy behavior by creating numerous new accounts to try and provoke an argument on such a stupid point, without contributing anything of substance to the discussion.
- TeMPOraL 2y ago> This leads to what we have today: localised, and often specialised attacks against valuable targets that are executed as fast as possible in order to minimise the chance a target has to respond or the vulnerability they are exploiting to be burned. Yup, exactly that. So what I'm saying it, it's beyond idiotic to combat this with a kernel-level backdoor managed by one entity and deployed across half the Internet. If anyone manages to breach that, they have a way to make their attack much simpler and much less localized (though they're unlikely to be prepared to capitalize on that). A fuckup on the defense side, on the other hand, can kill everything everywhere all at once. Which is what just happened. It's a "cure" for disease that happens to both boost the potency of the disease, and, once in blue moon, randomly kills the patient for no reason.
- orf 2y agoBut now you run into the tragedy of the commons. The fact is that this does help organisations. Definitely not all of the orgs that buy Crowdstrike, but rapid defence against evolving threats is a valuable thing for companies. So, individually it’s good for a company. But as a whole, and as currently implemented, it’s not good for everyone. However that doesn’t matter. Because individually it’s a benefit.
- TeMPOraL 2y agoThat's right. Which is why I'm hoping that this incident will make both security professionals and regulators reconsider the idea of endpoint security as it's currently done, and that there will be some cultural and regulatory pushback. Maybe this will incentivize people to come up with other ideas on how to secure systems and companies, that don't look like a police state on steroids.
- orf 2y agoBut you’re conflating a few different things here. The regulations don’t say “you must use a fragile kernel module that runs the risk of boot-locking” do they? The underlying fault in this drama is Microsoft - third party code shouldn’t be able to have the impact it did, regardless of how it is loaded or what it does. Their commitment to supporting legacy interfaces has shot them in the foot here. If HP pushed a dodgy printer driver (and if those still lived in the kernel) that nuked tens of millions of machines, would you be out here saying “regulators and security professionals need to re-consider printers”? Microsoft will shit bricks, start to do something to isolate kernel modules, Crowdstrike will be the first shining user of this, and life will go on.