4 ms·
This shouldn't be an either-or situation; you do all of the above. A simple validating parser in the client would be easy to write and would have easily caught
by marsten 2y ago
This shouldn't be an either-or situation; you do all of the above. A simple validating parser in the client would be easy to write and would have easily caught a null payload.
What looks especially bad for Crowdstrike is how many things (relatively simple things) had to fail in order for this to slip through. It's like walking into Fort Knox, grabbing a gold bar, and walking out unimpeded. A complete systemic failure.